For UK charities · Shadow AI, GDPR and the case for private

Shadow AI: why a policy won't fix ChatGPT

Your team is already using it. The answer isn't a stricter rule, it's removing the reason they reach for it.

Most of the AI happening inside UK charities today isn't run by anyone's IT team. It's individual staff, quietly, using the consumer tools. A fundraiser drafting an appeal. A caseworker summarising a referral. Someone in finance asking for help wording a board paper. None of it is reckless. It's productive. That is exactly why it's so hard to stop.

That quiet, unofficial use has a name: shadow AI. This page is the honest version of why it's a problem, why writing a firmer policy doesn't solve it, and what actually does.

For context, this is what I do: I build UK charities a private AI assistant that answers questions across their own systems, their CRM, their finance system, their spreadsheets and their documents, on data that never leaves their control. If you want to see that first, the walkthrough is here. This page is why it matters.

What's actually happening to your data

Because it's happening off the books, nobody sat down and chose any of this. The moment a document is pasted in, the decision has already been made for you. Four things come with it.

1. The data leaves the country, and there's no contract

When someone pastes a case note into ChatGPT, it travels to OpenAI's servers in the United States, gets processed there, and a copy stays in logs you can't see. Unless the right setting is off, it may also feed future training. Copilot and Gemini each have their own version of the same picture.

Under UK GDPR, if you use a third party to process personal data on your behalf, you need a written contract with them covering security, deletion and how they handle it. The free version of ChatGPT gives you no such contract. The Data (Use and Access) Act 2025 didn't change that: the same controller and processor framework still applies. And wherever the document legally belongs, you've now moved it somewhere another country's courts can ask for it.

2. You can't enforce your own rules

A public tool comes with the vendor's policy baked in, and you don't get a vote. Worse, you can't reliably enforce your own charity's rules on top of it. If your position is "we don't rank candidates by anything a person can't change," a public tool won't hold that line for you. Where a decision about someone is made mainly by the machine, UK law gives them rights: to be told, to ask for a human review, to contest it. The Data (Use and Access) Act 2025 tightened this, and being shortlisted for a job almost certainly counts.

3. You can't verify the answer, or defend it later

A general tool answers from a blend of everything it was trained on, which for UK law includes pre Brexit EU rules and US material. It has never read your handbook, your funder agreements or your safeguarding policy. It guesses from patterns, and nothing is cited. "ChatGPT said so" is not an answer you can give a funder, an auditor, the ICO or a tribunal.

4. You're tied to one vendor's decisions

Pricing goes up. Models get retired. Terms on data, retention and training shift, across all the providers. The longer your team leans on one tool, the more your ways of working quietly shape themselves around it, and the harder it becomes to move when you decide you should.

Your safeguarding policy probably says "keep records secure and don't share them outside the organisation." It probably doesn't say "except by pasting them into a US AI service when you're short on time."

And pasting is only half of it. The other half arrived on its own, as AI features switched on inside the tools you already pay for: your office suite, your CRM, your accounts package, the notetaker in your meetings. Nobody pasted anything, and nobody chose it. AI Exposure reads the small print on those tools for you, one entry per tool, from the vendors' own published documents.

Why a policy doesn't fix it

The instinct, once you see all this, is to write a rule. Add a line to the staff handbook. Run a training session. Put AI on the risk register. It feels like doing something, and it's not nothing. But it doesn't hold.

A policy is a rule you are hoping people follow. And they break this one for the least reckless reason there is: the tools genuinely help them get the work done, and the work still has to get done. A rule that makes a good day harder is a rule people quietly route around.

A policy that says "don't paste client documents into ChatGPT" works on the day it's signed, and decays from there.

So you end up policing a temptation you can't take away, auditing something you can't see, and carrying the liability whether or not anyone followed the rule. The processing already happened. Whether your charity ever meant to engage OpenAI is beside the point.

What actually removes the problem

You don't fix this by asking people to want the useful thing less. You fix it by giving them the useful thing in a place your data is allowed to be.

That's the assistant I build. It does the same everyday work your team currently opens ChatGPT for, drafting, summarising, answering questions across your systems, except it runs privately, in an account you own, and reads your systems with its own limited, read only access. Your questions, your records and its answers are never sent to ChatGPT, Gemini, Claude or any other outside service.

Once the private version is genuinely as helpful, there's no reason left to reach for the public one. Safety stops being a rule you enforce and becomes a consequence of where the tool lives: the useful version is the safe version, because it's the same version. And because every answer links back to the real record it came from, it's the defensible version too. Here's how I keep it accurate, and here's the full walkthrough.

You're not banning something useful. You're making the useful thing safe, so the policy has far less to hold back.

Where this leaves your policy

You may still want a short AI policy, and some funders and boards will ask for one. That's fine. The difference is that it stops being the only thing standing between you and a problem, and becomes what it should have been all along: a statement of how you work, not a wall you're hoping holds.

I'll also be honest about which situation you're in. Not every charity needs a private build. Some genuinely just need a clear policy and one sanctioned tool, and if that's you, I'll say so. If a policy is the right first step, I made a free one you can use:

Generate a free charity AI policy →

A note on what this is

This is informational, not legal advice. I'm not a lawyer, I'm an architect. The legal points above are the kinds of issues a DPO or solicitor would normally raise, and for advice about your specific situation you'll want your own counsel. What I can speak to is the technical side: what's actually happening to your data, and what a private alternative looks like in practice.

Common questions

Can charities use ChatGPT?

For work that involves no personal or confidential data, such as rewording public copy, it's usually fine. The problem is the sensitive work: beneficiary records, case notes, financial detail, anything naming a real person. For that, the public version sends the data out of your control, and the safer answer is a private assistant that does the same job without the data ever leaving.

Is ChatGPT GDPR compliant for a UK charity?

The free version, for personal data, almost never is. Using a third-party service to process personal data on your behalf needs a written contract covering security and deletion, and usually a lawful basis and a risk assessment. Pasting a list or a case note into public ChatGPT has none of those. The Data (Use and Access) Act 2025 didn't change the underlying framework.

What is shadow AI?

Shadow AI is the AI use already happening inside your organisation outside any official tool or policy: individual staff using ChatGPT, Copilot or Gemini to get through the day, without IT setting it up or knowing the detail. It's rarely reckless, usually just productive, which is what makes it hard to see and hard to stop.

Do charities need an AI policy?

A short one is worth having, and some funders will ask for it. But a policy is a rule you hope people follow, and they tend to break it because the tools genuinely help. It's a floor, not a solution. The more durable fix is to remove the reason staff reach for the public tools in the first place, by giving them a private one that's just as useful.

Is Microsoft Copilot or Google Gemini safe for sensitive charity data?

They're better than pasting into the free consumer tools, and inside a paid business tenancy the data stays within that vendor's systems. But it's still that vendor's systems, their settings and their logs, rather than something you control, and the office suite versions can surface documents more widely than people expect. For your most sensitive records, "we control it" is a stronger position than "they promised not to look."

Got a question that isn't here? Ask me directly →


Start with a discovery

The first step is always the same, and it's a small one: a short, fixed-price discovery. Over a couple of weeks I work out what your team is already doing with AI, where your data actually lives, and the one thing worth building first. You get a written report and a call to talk it through, with no obligation to go further. It's genuinely useful on its own, whether or not we end up building anything.

Here's a sample, laid out exactly as the real one is delivered.

Cover of a sample Private AI Discovery report, prepared for a UK charity
See the sample report → PDF, opens in a new tab

For context: I work mainly with UK charities and non profits, with chief executives, operations and finance directors, programme leads, and the people who look after data and IT. Respectfully, I don't work with recruitment or development agencies.

Not sure it's time for that yet? Just email me, tell me who you are and what your organisation does: peter@peterbrady.co.uk