AI Exposure · Charity CRM

What CiviCRM actually does with your data

The open source CRM ships no AI of its own. What that is worth to you depends on which CiviCRM you are running: one your organisation hosts, or a hosted product somebody sells you. Everything below splits along that line.

Trains on your data
Nothing there to train
Processed
Wherever you host it
Can you turn it off
Yes, if you know what's installed
Verified
20 July 2026, against CiviCRM's published documents

What AI is in it?

  • No AI in the product itself. I read every monthly release of CiviCRM from May 2025 to July 2026 and found no AI features in the core software. Nothing arrives quietly with an update the way it does in commercial tools, because there is no vendor pushing features at you.
  • DocBot, which reads the manual and not your data. An optional extension that answers questions about how to use CiviCRM. It is trained on the public documentation and community forums, not on anything in your database. It has not been updated since March 2024.
  • If you host it yourself, AI arrives only when someone installs it. On a CiviCRM your organisation or your agency runs, nothing AI shaped appears unless a person puts it there, usually by wiring the CRM to an outside AI service through an automation platform. That is a decision with a date and a name attached to it, which is a different situation from every hosted product here.
  • If someone hosts it for you, they decide what gets added. On a hosted CiviCRM you are back to having a vendor, and the usual questions come back with it. There are several to choose from, including one run by the CiviCRM project itself and a number of UK agencies. The one with published AI plans so far is CiviPlus, run by Compuco, which is openly building an assistant called CiviAI into it.

Does your data train AI models?

Nothing there to train.

CiviCRM is software you run, not a service someone runs for you, so there is no company receiving your data and no training clause to read. Worth being precise about what that means: it is an absence, not a promise.

Nobody is undertaking not to train on your data; there is simply nothing for such an undertaking to be about. The moment someone connects an AI extension, an automation platform or a hosted add on, that provider's small print applies instead, and the three questions travel with it. Does our data train your AI, where is it processed, and can we turn it off?

Where is your data processed?

Wherever you host it.

CiviCRM lives wherever your installation lives: a server your organisation controls, or more commonly a hosting partner or agency's cloud. The where question therefore has a genuinely knowable answer, but only your host can give it to you. Many charities inherited a CiviCRM set up by an agency years ago and have never asked.

If you are on CiviPlus it is already answered. Compuco says CiviPlus data is hosted on Amazon Web Services, by default on their UK servers. Its G Cloud listing declares data storage and processing locations as the United Kingdom, and the agreement that governs your CRM data limits transfers to the UK and the European Economic Area.

One wrinkle if you go reading for yourself. The general privacy policy on Compuco's websites, last updated in 2021, still says you consent to storage in the United States. That page covers website visitors rather than your CRM, and the documents above are the ones that govern your data, but it is the kind of thing that stops you mid read.

Free versus paid: No tiers, no rollout. The software itself has no plans, no paid AI add on, and no feature arriving one morning because a vendor shipped it. If you are on a hosted product that changes: your provider decides what gets added and when, on their schedule rather than yours. CiviAI, the furthest along of the hosted assistants, is described by its own makers as far from production ready, so for most charities this is a question to ask before it arrives rather than after.

Can your organisation turn it off?

Yes, if you know what's installed.

Nothing connects to a CiviCRM unless someone installs or configures it, so your organisation has, in principle, total control. In practice that control is only as good as your knowledge of what is already there. The job here is an inventory, not a settings hunt.

What does this mean for the people you support?

Start by working out which CiviCRM you have, because the two are genuinely different positions.

If your organisation or your agency hosts it, full control means full responsibility: there is no vendor promise to lean on and no vendor to blame, and the whole story is your host, your extensions and your integrations. If you buy a hosted product instead, you have a vendor again, and the fact that CiviCRM underneath is open source does not change what that vendor may add on top.

Either way this is a CRM full of donors, beneficiaries and case detail, so it is worth the half hour it takes to find out.

What to check this week

  1. Work out which CiviCRM you have. Ask whoever looks after it whether your organisation or an agency runs the server for you, or whether you pay for a hosted CiviCRM product. Everything else on this page depends on the answer, and plenty of charities inherited a set up nobody has looked at in years.
  2. Get the inventory, and ask where it lives. Ask for a list of installed extensions and any external connections, automation platforms included, plus which country the server is in and who can reach the database. On a self hosted CiviCRM there is a person who knows, which is not true of most systems here.
  3. If someone hosts it for you, ask what AI they are adding. Hosted CiviCRM providers are building AI features now, and the data terms are not always published yet. Ask in writing: what is coming, what will it be able to read, does our data train it, where is it processed, and can we decline it?

Sources

Everything above is my plain English reading of what CiviCRM publishes. The originals:

Vendors change these documents quietly and often. If you spot something out of date, email me and I'll re-verify the entry.

What if the AI reading your CRM was yours?

This is not a hypothetical for CiviCRM. I have already built it: a private assistant running in an AWS account that reads a charity's live CiviCRM through its API, alongside three other systems, with every figure linking back to the real record. You keep CiviCRM, and no outside AI company sees the question or the answer.

Here it is, asked for a full update on an appeal. The answer draws on live CiviCRM records and the other three systems at once. The full demonstration is at chat across your systems.

The Fenmere Trust is a fictional charity and all data shown is invented for demo purposes.

See your whole toolkit at once

This page covers one tool. The AI Exposure Report Generator covers your toolkit: tick the tools your charity uses and get one report showing what the AI inside each of them does with your data, as a Word document you can table at your next meeting. Free, and nothing you tick leaves your browser.

The Report Generator, start to finish: tick your tools, read your exposure, download the report.

Generate your charity's AI exposure report →

Read the other tools

The same questions, answered for every tool in the directory.

Your office suite

AI chatbots

Meeting notetakers

Charity CRMs

Accounts

Marketing and design


Start with a discovery

The first step is always the same, and it's a small one: a short, fixed-price discovery. Over a couple of weeks I work out what your team is already doing with AI, where your data actually lives, and the one thing worth building first. You get a written report and a call to talk it through, with no obligation to go further. It's genuinely useful on its own, whether or not we end up building anything.

Here's a sample, laid out exactly as the real one is delivered.

Cover of a sample Private AI Discovery report, prepared for a UK charity
See the sample report → PDF, opens in a new tab

For context: I work mainly with UK charities and non profits, with chief executives, operations and finance directors, programme leads, and the people who look after data and IT. Respectfully, I don't work with recruitment or development agencies.

Not sure it's time for that yet? Just email me, tell me who you are and what your organisation does: peter@peterbrady.co.uk