The Weekly Scan for week of 17 August ’26: Responsible AI has to make value and control work together
This week’s strongest developments begin inside the charity and nonprofit sector itself. The Charity Commission places AI-enabled fraud within the sector’s wider risk landscape, while new research examines the benefits nonprofits report from AI and the importance of involving the people affected by its use.
Together with practical developments in writing, agent design and frontier-model assurance, they show that responsible AI is not a choice between pursuing value and managing risk. It is the operating discipline that allows organisations to do both.
SECTOR RISK
United Kingdom
Charity Commission for England and Wales · UK · 18 August 2026
AI-enabled fraud enters the charity sector risk landscape
The Charity Commission’s second annual Charity Sector Risk Assessment identifies financial resilience, abuse of charitable status for private benefit and gaps between regulatory responsibilities among the significant risks facing charities.
It reports a further 29 per cent increase in concerns involving potential private benefit, to 374 cases in 2025–26. The Commission says this upward trend may be fuelled in part by bad actors using AI in charity registration applications as they seek to exploit charitable status for private benefit. It also warns that AI can facilitate fraudulent grant applications, while increasingly complex cases require work across different regulators and public bodies.
Why it caught our eye: This is not primarily an AI report, which is precisely why its inclusion of AI matters. The technology is beginning to appear within the ordinary risk environment that trustees and leaders are already responsible for managing.
For charities and funders, that raises practical questions about identity and applicant verification, financial controls, cyber resilience, due diligence and how suspicious patterns are escalated. The answer is not to treat every application or interaction as fraudulent because AI may have been involved. It is to consider where existing controls rely too heavily on plausible documents, polished language or information that is difficult to verify.
The report does not quantify how many confirmed cases involved AI, so it should not be read as evidence of widespread AI-enabled charity fraud. It is an early regulatory signal that the methods available to bad actors are becoming more capable, while responsibility for protecting charitable assets and public trust remains with trustees.
SECTOR CAPABILITY
Global
Google for Nonprofits · Global · 28 July 2026
New nonprofit research puts numbers behind the capability gap
Google has published findings from an annual global survey, conducted by Qualtrics, of 6,461 organisations using Google for Nonprofits.
Eighty-six per cent of respondents believed AI could make their work more effective, but organisations reported that only 49 per cent of their workforce used it regularly. Among staff using AI, reported time spent on administration fell from 18.8 to 10 hours a week. Seventy-nine per cent expressed an interest in AI training, while 65 per cent had fewer than three hours a month available for professional development.
Why it caught our eye: The findings support the economic case for responsible adoption, but they also show why access to tools is not enough.
If AI releases time from administration, the organisational benefit depends on what happens to that capacity. It can be redeployed into direct services, relationships, analysis, quality assurance and other work that advances the mission. It may also need to support new or expanded responsibilities such as workflow design, agent management, outcome evaluation and exception handling. That does not automatically mean adding headcount. It means redesigning work so the effort required to manage AI is part of the value model rather than an unfunded layer added afterwards.
The evidence needs careful handling. The time saving is self-reported rather than a measured causal result. Respondents are drawn from the Google for Nonprofits community, and the published report does not provide the fieldwork dates, geographical composition, response rate, weighting or detailed question wording needed to judge representativeness. Google also presents the findings alongside its own products and training.
The report is therefore useful evidence of perceived benefits and capability constraints, not proof that every charity should expect to save 8.8 hours per person each week. Its stronger message is that benefits depend on people having the time, skills and organisational support to turn experimentation into repeatable practice.
HUMAN ACCOUNTABILITY
North America
Clay · North America · 19 August 2026
An AI writing policy that keeps responsibility with the writer
Software company Clay has introduced an AI writing policy across its organisation after finding that some AI-assisted documents and presentations were becoming longer, less coherent and harder for colleagues to review.
The policy does not ban AI. It permits its use for brainstorming, drafting and proofreading, but requires employees to stand behind every idea and sentence, treat writing as part of thinking, respect the reader’s time and avoid assuming that greater length means greater value.
Why it caught our eye: The interesting part of this policy is what it does not do. It does not attempt to govern writing simply by telling people which technology they may or may not use.
Instead, it keeps responsibility with the person communicating. They must understand the argument, check that the words express what they mean and be prepared to defend the result.
That is a useful principle for charities producing board papers, funding proposals, policy submissions, impact reports and supporter communications. AI can help people express and test their thinking, including people for whom writing is not their strongest form of communication. The risk arises when polished language conceals work that nobody has properly considered or owns.
Clay’s approach is not a complete responsible AI policy. Organisations still need clear rules for confidential information, appropriate tools, factual verification, copyright and higher-risk uses. But it demonstrates that effective policy can enable useful adoption while preserving human judgement and accountability.
AGENTIC GOVERNANCE
North America
Urban Institute · North America · 19 August 2026
A practical playbook brings governance into the design of AI agents
The Urban Institute has published a Responsible Agentic AI Playbook for teams building agents that non-experts may use in public services such as health, housing, workforce support and access to benefits.
It organises responsible development around a clear purpose and measures of success, ownership and oversight, reducing known risks and creating an accessible audit trail. It also provides separate guidance for internal and external agents, alongside a governance process for reviewing different kinds of change.
Why it caught our eye: Agentic AI makes familiar governance questions more immediate because the technology can do more than generate an answer. It may navigate a process, use connected tools or help someone take an action with real consequences.
The playbook is useful because it takes responsible AI down to the level where governance has to operate: what the agent is for, who owns it, how it will be tested, what evidence will be retained and what happens when it changes.
Its scope is deliberately narrower than an organisation-wide approach to responsible AI. It is aimed at people building particular agents, not organisations purchasing general AI tools for their workforce or deciding which opportunities to pursue across a wider portfolio.
That boundary is instructive. Application-level controls are an important part of responsible adoption, but they depend on an organisation having clear principles, accountable people and the capability to apply those controls consistently. A good playbook can guide a particular build. It cannot establish the surrounding operating model on its own.
EQUITY & PARTICIPATION
North America
Bellwether · North America · 19 August 2026
People affected by AI should help shape how it is used
Education nonprofit Bellwether has examined how schools and advocacy organisations can involve parents in decisions about AI. Drawing on interviews conducted between April and June with researchers, parent advocates and current and former school-district leaders, it identifies early principles for engagement rather than claiming an established set of best practices.
The report recommends beginning with the outcomes and values families want for children, involving people before tools or policies are finalised, and matching their role to the stakes of the particular use. Some decisions may require transparency, while others justify consultation, consent or shared decision-making.
It also points to an emerging divide in who is being equipped to use and understand AI. Citing RAND data for autumn 2024, Bellwether reports that 67 per cent of low-poverty school districts had trained teachers in generative AI, compared with only 39 per cent of high-poverty districts.
Why it caught our eye: Responsible AI discussions often concentrate on what leaders, technical teams and governance specialists need to decide. Bellwether asks an equally important question: where are the people who will experience the consequences?
For charities, the relevant stakeholders may be beneficiaries, service users, supporters, volunteers, staff or communities. Engagement should not mean asking people to approve a technical proposal they had no role in shaping. It should begin with the need, the outcome people value, what they would want protected and the circumstances in which AI would or would not feel appropriate.
Meaningful participation also depends on people having enough shared knowledge and practical experience to contribute confidently. If AI literacy and access to good training remain concentrated among better-resourced organisations and communities, the people already most likely to be excluded may have the least influence over how the technology affects them and the fewest opportunities to benefit from it. Building common knowledge and widening responsible use are therefore questions of equity as well as organisational capability.
The degree of involvement should remain proportionate. People do not need to participate in every low-risk internal decision. But when AI influences access to a service, affects children or vulnerable people, uses sensitive information or changes an important human relationship, consultation after deployment is unlikely to be enough.
Bellwether’s evidence is qualitative and specific to US education. Its principles should therefore be tested in other settings rather than treated as a universal model. The wider lesson is nevertheless strong: trust is more likely to survive change when the people affected have meaningful agency before important decisions become difficult to reverse.
ASSURANCE & OVERSIGHT
Global
OpenAI · North America / Global · 18 August 2026
The Astra follow-up shows what a pause looks like in practice
Last week’s Scan covered OpenAI’s decision to slow development of its forthcoming Astra model after preliminary evidence suggested it might meet the company’s threshold for critical cybersecurity capability.
OpenAI has now described more of the operational response. It says reinforcement-learning training was paused for two weeks, its largest planned frontier training run remains on hold, and some workloads will not resume until they meet a stronger security standard.
The controls include greater isolation for workloads executing untrusted code, tighter separation from the internet and internal networks, continuous security testing and expanded monitoring. OpenAI says its current monitoring system aims to escalate concerning activity within 30 minutes and adds roughly 20 per cent to the inference compute being monitored.
Why it caught our eye: The new information is not simply that a pause happened. It is what an organisation needs in place for a pause to be meaningful.
OpenAI describes monitoring able to identify concerning behaviour, people with the authority to investigate and stop activity, technical environments that can isolate access, and sufficient operational capacity to accommodate the trade-offs and delay created by stronger safeguards.
The specific controls reflect frontier-model risks and would be disproportionate for most charities. The operating principle is much more widely relevant. Human oversight only works when people can see enough to intervene, understand the threshold for doing so and have both the authority and practical means to stop or contain the system.
Responsible AI is therefore part of the economic model for adoption, not an optional overhead. Monitoring, evaluation and clear ownership require real effort, but new responsibilities do not automatically require new headcount. As AI changes or removes parts of existing work, organisations should redeploy some of the capacity released into agent management, quality assurance, exception handling and governance.
Without that redesign, promised efficiencies may be misleading: work is automated while necessary human responsibilities remain unfunded or unowned. The aim is not to add a parallel compliance function, but to shift existing labour towards the judgement and control that make AI dependable at scale.
A CURIA AI PERSPECTIVE
Responsible AI has to make value and control work together
The developments in this week’s Scan operate at very different levels, but they expose the same organisational challenge.
The Charity Commission shows how AI is changing the environment around charities, including the methods available to people attempting to exploit trust, registration and funding processes. Google’s research looks in the other direction, towards the time and capability charities believe AI can release.
Those two stories should not be separated into a debate between risk and opportunity. If AI is to create sustainable economic and organisational value, charities need to pursue worthwhile uses while adapting the controls, skills and responsibilities that make those uses dependable.
Clay’s writing policy demonstrates this at the level of an individual output. People can use AI, but they cannot hand over ownership of what they communicate. The Urban Institute playbook moves the same principle into agent design, where purpose, testing, accountability and an audit trail have to be built into a particular application.
Bellwether extends responsibility beyond the organisation. A system may be internally well governed and still undermine trust if the people affected had no meaningful opportunity to shape its purpose, boundaries or use. Its evidence of unequal access to teacher training also shows that participation depends on capability. Proportionate engagement must therefore sit alongside wider AI literacy and access to responsible use, as well as proportionate technical and organisational controls.
The Astra response illustrates what happens when evidence suggests those controls are not ready. A principle such as human oversight only affects outcomes if people have the information, authority and practical means to pause or contain a system.
This is why responsible AI needs Principles, People and Capability to develop together.
Principles establish what the organisation is trying to achieve, what it will protect and where its boundaries sit. They should support valuable uses while remaining clear enough to guide decisions when the evidence is uncertain or pressures conflict.
People exercise judgement, remain accountable and bring different forms of knowledge into the process. That includes leaders and staff, but also the beneficiaries, communities and other stakeholders who understand how a service works in people’s lives.
Capability turns those intentions into repeatable practice. It includes the data, processes, technology, skills, monitoring and organisational habits needed to identify opportunities, test them safely, learn from evidence and intervene when something changes.
The Google findings suggest that AI may release meaningful staff time, but time saved is not the same as organisational value created. Benefits appear when capacity is deliberately redeployed into better services, stronger relationships, deeper analysis or other mission-led work.
Some of that capacity will also need to support work that becomes more important as AI scales: designing workflows, managing agents, reviewing exceptions, evaluating outcomes and governing change. These are new or expanded responsibilities, but not necessarily new posts. In many organisations, the stronger economic model will be to shift existing labour towards the human judgement and control that AI cannot safely replace.
The objective is not maximum automation or maximum governance. It is a proportionate operating model in which the value released by AI exceeds the effort required to manage it, while preserving the quality, trust and control on which that value depends.
That is when responsible AI stops being a policy position and becomes the way an organisation works.