September 30, 2026

Navigating AI Risks in the Charity Space: Legal Essentials for Responsible Persons

‍Why AI Governance Matters

Artificial intelligence (AI) is changing the way charities work. Used well, it can help organisations improve efficiency, reduce administrative burden and make better use of limited resources.

However, charities also need to be aware of whether they are using AI lawfully, responsibly, and consistently with the organisation’s charitable purposes, legal obligations, and duties to the people it serves. For charitable entities registered with the Australian Charities and Not-for-profits Commission (ACNC), this responsibility falls to its Responsible People.

The legal risk for responsible people arises not from using AI itself, but from the organisation's failure to comply with existing statutory obligations.

Key Takeaways for Responsible People

  • ‍Existing duties still apply. Responsible People remain accountable for ensuring AI is used lawfully, carefully and consistently with the organisation’s charitable purposes.‍
  • Risk depends on how AI is used. Uses involving personal information, vulnerable beneficiaries or significant decisions require greater scrutiny and stronger safeguards.‍
  • Human accountability must be retained. AI may support decisions and communications, but appropriately authorised people must remain responsible for outcomes.‍
  • Effective governance is essential. Boards should understand material AI risks and ensure they are managed through proportionate oversight, controls and reporting.

Leadership Duties Still Apply

Responsible People must act in accordance with ACNC Governance Standard 5, which imposes duties on them to act with reasonable care and diligence, in good faith, and for proper purposes.

These duties are technology-neutral and continue to apply when organisations adopt and manage AI tools.

A board does not need to become experts in the technical operation of every AI model used by its organisation. However, Responsible People should be sufficiently informed to:

  • Understand the material risks associated with significant uses of AI; and
  • Independently assess the information and adviceprovided to them.

What is my legal exposure?

The legal issue is not the use of AI itself. Rather, it is that Responsible People remain subject to the duties imposed by ACNC Governance Standard 5 and, where applicable, the governing rules of the organisation. If the use of AI contributes to poor decision-making, unmanaged risk, or a failure to exercise appropriate oversight, Responsible People may still be accountable for those outcomes.

Example Risk: A board that approves the widespread use of AI without understanding how it is being used, what data is being entered into it, or what controls are in place may have difficulty demonstrating appropriate oversight if issues later arise.

Privacy and Data Protection

AI tools do not create a separate privacy regime. Instead, existing privacy obligations continue to apply to the collection, use, disclosure and storage of personal information. Charities subject to the Privacy Act 1988 (Cth) must ensure that any use of AI, including in the collection, storage, or generation of material, complies with the Australian Privacy Principles (APPs). The ACNC has expressly recognised that the responsible management of information, data and cybersecurity fall squarely within the duties of Responsible Persons.

The Office of the Australian Information Commissioner (OAIC), the privacy regulator, provides guidance on commercially available AI products and confirms that privacy obligations may apply to both personal information entered into an AI system and AI-generated outputs containing personal information. Before adopting an AI product, organisations should conduct appropriate due diligence and, as a matter of best practice, should not enter personal information, particularly sensitive information, into publicly available generative AI tools.

Before using an AI tool, charities should consider:

  • What information is being entered into an AI tool or system?
  • Where will that information be stored and processed?
  • Does the AI provider use information for training or other purposes?
  • Does your privacy policy adequately describe the relevant practices?
  • What are the risks if the AI tool is the subject of a data breach?

Example Risk: A staff member uploads client case notes, counselling records or beneficiary information into a publicly available AI tool to assist with drafting reports or correspondence. If that information contains personal or sensitive information, the organisation may expose itself to privacy, confidentiality and cybersecurity risks.

Upcoming Reforms – Automated Decision Making

The Federal Government has introduced changes to the Privacy Act 1988 (Cth) that will increase transparency about how organisations use AI and other automated systems to make decisions about people. These changes will take effect from 10 December 2026 and will be implemented by the following new APPs:

  • ‍APP 1.7 – If an organisation uses a computer program to make, or significantly help make, a decision about a person using their personal information, and that decision could significantly affect the person’s rights or interests, the organisation will need to provide information about the use of that program in its privacy policy.‍
  • APP 1.8 – Where this requirement applies, the organisation's privacy policy will need to explain:
    • what types of personal information the computer program uses;
    • what types of decisions the program makes on its own; and
    • what types of decisions are significantly influenced by the program's output.
  • ‍APP 1.9 – This provision explains what is meant by a "decision" and when a decision is considered likely to significantly affect a person's rights or interests.

Importantly, these reforms do not prohibit the use of AI or automated decision-making. Rather, they impose transparency obligations on organisations that use these systems in ways that can significantly affect individuals. Responsible People should therefore ensure their organisation understands when these disclosure requirements may apply.

Example Risk: The charity uses AI to prioritise applications for emergency relief or housing assistance. If the system substantially influences decisions that affect an individual's access to services, the organisation may need to disclose that use of automated decision-making under the new requirements.

Intellectual Property

Existing intellectual property laws continue to apply to the use of AI systems. Charities should ensure they have the necessary rights and permissions to use any material uploaded to, generated by, or incorporated into an AI tool, as the use of copyright-protected material without appropriate authorisation may expose the organisation to infringement claims.

Example risk: AI may be used to generate marketing materials, website content or fundraising campaigns. Before publishing that material, organisations should consider whether the content may reproduce or closely resemble copyright-protected works and whether they have the necessary rights to use it.

Consumer Law

Charities fall under the Australian Consumer Law if they provide goods or services for a fee. If AI-driven communications, including chatbots, automated emails, and promotional material, are inaccurate, misleading or incapable of being substantiated, a charity may be exposed to liability under the Australian Consumer Law in the same way as if those statements had been created by a person.

Example Risk: An AI tool may generate fundraising content that exaggerates the impact of a program, inflates statistics or makes claims that cannot be substantiated. If those representations are misleading, the charity may be exposed to liability under the Australian Consumer Law.

Workplace and Employment

Charities increasingly use AI tools to support workforce planning, recruitment and rostering. Employers remain responsible for employment decisions, regardless of whether those decisions are informed by AI. Reliance on an AI tool does not remove obligations under workplace, discrimination and adverse action laws, particularly where automated processes influence recruitment, promotion, rostering or performance management decisions

Example Risk: A charity may use AI to screen resumes, rank candidates for interview or recommend employee rostering arrangements. If the system disadvantages particular groups or contributes to unfair decision-making, the organisation may face employment or discrimination-related risks.

Contracts and Funding Arrangements

Government funding agreements, service contracts, insurance policies and arrangements with third-party providers may contain confidentiality, privacy, data security or subcontracting requirements that affect whether and how AI can be used. Charitable organisations must ensure that AI tool use aligns with their contractual obligations.

Example Risk: Staff may upload funding agreements, service contracts or confidential client information into an AI platform to obtain drafting assistance or summaries. Doing so could potentially breach confidentiality obligations if the information is disclosed or stored inconsistently with contractual requirements.

Equality and Non-Discrimination

AI systems can produce biased or discriminatory outcomes, particularly where the data used to develop or operate the system reflects existing biases. Anti-discrimination laws apply regardless of whether a decision is made by a person, an algorithm or a combination of both. If an AI-assisted decision results in unlawful discrimination, the organisation may remain legally responsible for the outcome.

Responsible Persons should therefore:

  • Take reasonable steps to identify and test for potential bias in AI systems; and
  • Ensure that decisions affecting individuals aresubject to appropriate human review.

This is especially important for charities serving vulnerable or high-risk groups, as an unfair or inaccurate AI-assisted decision may significantly harm the very people the charity exists to support.

Example Risk: A charity delivering financial hardship assistance may use AI to prioritise applications for support. If the system produces outcomes that unfairly disadvantage particular groups, the organisation may face both legal and reputational consequences.

What should NFP boards do now?

The issue for boards is not whether AI should be used, but whether its use is appropriately governed. While there is currently no comprehensive AI-specific regulatory framework for charities in Australia, existing governance, privacy, employment, consumer protection, anti-discrimination and contractual obligations continue to apply.

Responsible People are not expected to understand the technical workings of every AI system used by their organisation. However, they should ensure that appropriate governance frameworks are in place to identify, assess and manage AI-related risks.

As a starting point, the board should consider the following:

  • Establishing an AI governance framework. Treat AI as an organisational governance issue rather than solely an IT or operational matter. Boards should ensure a clear framework for assessing, approving, and monitoring AI use across the organisation, and assign responsibility for staff training.‍
  • Determining the organisation's risk appetite. Not all AI uses present the same level of risk. Boards should consider where AI may affect personal information, vulnerable beneficiaries, employment decisions, financial outcomes or regulatory compliance, and ensure higher-risk uses receive appropriate scrutiny.‍
  • Approving policies and accountability mechanisms. Organisations should have clear policies governing AI use, including appropriate controls for privacy, confidentiality, data security, decision-making, and human oversight. Clearly allocate responsibility for implementation and ongoing monitoring.‍
  • Maintaining oversight of material AI risks. Boards should receive regular reporting on significant AI initiatives, emerging risks, incidents and compliance issues, in the same way they oversee other strategic and operational risks.‍
  • Allocate responsibility. AI should not replace appropriate human accountability. People with the right authority and expertise should remain responsible for important decisions and communications.‍
  • Monitoring legal and regulatory developments. The legal framework governing AI is continuing to evolve. Boards should ensure the organisation remains informed about relevant legislative, regulatory and sector-specific developments that may affect its operations.‍
  • Documenting significant decisions. Where AI is used in higher-risk contexts, boards should ensure that key decisions, identified risks and mitigation measures are appropriately documented.

No items found.
Need help navigating NFP or charity law?

We exclusively support charities and NFPs, so we have a specialised and in-depth knowledge of the practical legal, regulatory, and governance needs of these organisations.

Contact us today to review your compliance and ensure you are up to date.

Call us on 07 3160 0010, email reception@nfplawyers.com.au, or submit a contact form to arrange a consultation.

Disclaimer – Reliance on Content

The material distributed is general information only. The information supplied is not and is not intended to be, legal or other professional advice, nor should it be relied upon as such. You should seek legal or professional advice in relation to your specific situation.

Share the news

Link copied to clipboard!

To discuss your project or legal needs please get in touch.