For UK charities · Read from the vendors' own documents

AI Exposure

What the AI in your tools actually does with your data.

AI didn't arrive at your charity as a decision. It arrived as features, switched on quietly inside the tools you already use. Copilot appeared in your Office suite. Your accounts package grew an assistant. A notetaker started turning up to meetings. Nobody chose any of it, and nobody read the small print, because it is scattered across a dozen vendor documents written for lawyers.

So I'm reading it for you. Every entry below comes from the vendor's own published documents, with the date I last checked. And the AI Exposure Report Generator turns what I've found into a report about your charity's own toolkit, free, in your browser.

The AI Exposure Report Generator

Tick the tools your charity uses. Get one report showing what the AI inside each of them actually does with your data, which of the records you hold it can reach, and what to check this week. Download it as a Word document and table it at your next team or board meeting. Nothing you tick leaves your browser.

The Report Generator, start to finish: tick your tools, read your exposure, download the report.

Generate your charity's AI exposure report →

Four things that keep turning up

I have now read the small print behind 17 tools, and the same few things come up every time. They matter more than any single vendor's documents, because they tell you what to look for in the tools I haven't covered yet.

1. The training answer is usually reassuring. Reach is the problem.

Most vendors say plainly that your data does not train their models, and I believe them. Far fewer limit what the AI can see. An assistant inside your office suite reaches whatever the signed in person reaches, so a decade of loose sharing becomes searchable by anyone who asks the right question.

Seen in Microsoft 365 Copilot, Google Workspace and Teams.

2. Whose account it is matters more than which tool it is.

The same tool, the same question typed into the same box, is covered either by an agreement your organisation holds or by nothing at all, depending on whether somebody signed in with a work account. On a personal account there is no admin, no visibility and no contract, and the training default often runs the other way too.

Seen in ChatGPT, Google Gemini, Claude, Canva and Fathom.

3. The off switches mostly exist. Almost nobody has looked.

Reading these documents, the surprise was not how few controls there are. It was how many go unused. Some are a single account wide toggle, some are off until an administrator turns them on, and some are two separate settings where finding only the first leaves the interesting one on.

Seen in Beacon, Zoom and Salesforce.

4. It arrived without a purchase, so nobody assessed it.

Normally a new system means a decision: someone compares options, asks about data protection, signs something. Most of this AI skipped that entirely. It appeared in a product you already paid for, or on a free plan one member of staff installed, which means there was never a moment when anyone was supposed to check.

Seen in Copilot Chat, Google Workspace, Beacon and Fathom.

Read tool by tool

Every entry answers the same questions. What AI is in it? Does your data train AI models? Where is your data processed? What changes between free and paid? Can your organisation turn it off? What does it mean for the people you support? And what should you check this week?

Two rules keep this honest. Everything is descriptive, not a score: I tell you what the vendor says and what it means for a charity, and you decide what to do about it. And every entry carries a verification date, because vendors change these documents quietly and a stale answer is worse than no answer.

Your office suite

AI chatbots

Meeting notetakers

Charity CRMs

Accounts

Marketing and design

17 of 17 entries are verified against the vendor's own documents, and new tools are added as I verify them. Is a tool missing? Tell me which one.

What to do with what you find

If these pages tell you what the AI in your building does, the next step is agreeing what your team is allowed to do with it. My free Charity AI Policy Generator writes that agreement with you in a few minutes, in your browser, and nothing you answer leaves your device.

And if you'd like someone to look properly at how AI is actually being used across your organisation, including the uses nobody ticks on a form, that's what a short discovery is for. peter@peterbrady.co.uk


Start with a discovery

The first step is always the same, and it's a small one: a short, fixed-price discovery. Over a couple of weeks I work out what your team is already doing with AI, where your data actually lives, and the one thing worth building first. You get a written report and a call to talk it through, with no obligation to go further. It's genuinely useful on its own, whether or not we end up building anything.

Here's a sample, laid out exactly as the real one is delivered.

Cover of a sample Private AI Discovery report, prepared for a UK charity
See the sample report → PDF, opens in a new tab

For context: I work mainly with UK charities and non profits, with chief executives, operations and finance directors, programme leads, and the people who look after data and IT. Respectfully, I don't work with recruitment or development agencies.

Not sure it's time for that yet? Just email me, tell me who you are and what your organisation does: peter@peterbrady.co.uk