← Back to blog

The Weekly Scan: Transparency, trust and organisational readiness

The Weekly Scan for week of 3rd August ’26: Transparency, trust and organisational readiness

This week’s developments bring an important part of responsible technology into focus: transparency matters most when organisations have to explain what has actually happened, who may be affected and what remains uncertain. From a cyberattack on a widely used charity CRM to new European disclosure duties and emerging approaches to AI oversight, the recurring challenge is turning principles into reliable organisational practice.

DATA GOVERNANCE & TRUST

United Kingdom

The Register and Bates Wells · UK · 5 August 2026

The Beacon cyberattack tests charity transparency in practice

Beacon CRM has confirmed that an unauthorised third party made copies of database backups and that activity during the incident indicated data was likely to have left its systems. The company advised customers to assume that everything stored in Beacon, including attachment files, may have been downloaded and could have been readable, while its investigation continued.

The platform is used by more than 1,500 organisations, predominantly in the charity sector. The Register identified charities that had confirmed an impact, others that were still investigating and at least one whose data was not affected, illustrating why each organisation must establish its own position rather than repeat a generic communication.

Bates Wells notes that charities using Beacon are likely to remain the controllers of the personal data they placed on the platform. Its guidance says each organisation should establish what information it held, whether it was likely to have been copied, who may be affected and what harm could follow. It should then document decisions about notifying the Information Commissioner’s Office, communicating with affected people and making a Serious Incident Report to the Charity Commission.

Why it caught our eye: This is a direct test of how charities practise transparency when facts are incomplete and people may be worried. Outsourcing a system does not outsource the charities accountability to supporters, beneficiaries or service users. Good incident communication requires an organisation to understand what it held, who may be affected, what harm could follow and which facts remain provisional.

Read The Register article →   Read the Bates Wells guidance →

REGULATION & TRANSPARENCY

Europe

European Commission · Europe · 31 July 2026

Europe’s AI transparency requirements begin to take effect

From 2 August, Article 50 of the EU AI Act began to apply across the European Union. Its transparency obligations include informing people when they are interacting directly with certain AI systems and identifying particular content that has been generated or altered by AI. Compliance will mainly be enforced by national market-surveillance authorities, with the European AI Office responsible in a more limited set of circumstances.

The detailed obligations depend on the system, role and context. The practical direction is nevertheless clear, organisations need to know where AI is being used, who is responsible for it and when disclosure is necessary.

Why it caught our eye: A transparency statement cannot be added reliably at the end of a project if no one has maintained an inventory of systems, uses and owners. Disclosure depends on operational knowledge. For organisations serving people across Europe, that makes AI inventory and accountability part of day-to-day capability rather than a one-off compliance exercise.

Read the European Commission guidance →

AI SAFETY & POLICY

United Kingdom

ITPro · UK · 4 August 2026

The UK leaves the door open to stronger safeguards

The UK’s AI Minister, Kanishka Narayan, has said the government could consider regulation requiring testing before powerful AI systems are deployed if the existing approach proves insufficient. The comments followed incidents in which cyber-capable AI agents escaped intended testing boundaries and interacted with third-party systems.

The report also says the Information Commissioner’s Office is monitoring developments, while the UK AI Security Institute has access to some frontier models before release. No new regulatory requirement has yet been announced, so the comments indicate a possible direction rather than a settled policy.

Why it caught our eye: Supplier testing and government evaluation do not remove the responsibility of organisations deploying AI. As systems gain access to tools, data and external services, charities will need controls based on what a system can do in their environment, not just assurances about the underlying model.

Read the ITPro report →

PUBLIC ACCOUNTABILITY

North America

arXiv research paper · North America · 31 July 2026

Public AI registers can still leave accountability gaps

Researchers examined three US federal transparency mechanisms covering records, information collection and government AI use. They found that each disclosed different parts of the picture, but none made it straightforward to follow a particular AI system across agencies, documents and time.

The problems included inconsistent levels of detail, the absence of persistent identifiers and reporting cycles that can leave systems in use for months before they appear in a public inventory. The paper is a preprint and focuses on US federal government, but the underlying accountability problem travels well.

Why it caught our eye: Publishing a list of AI systems is useful, but it is not the same as making their use intelligible. Effective oversight requires connections between the system, its purpose, data, owner, risk assessment, changes and effects. A register becomes meaningful when it supports questions and decisions, not when it merely records that technology exists.

Read the research paper →

PRACTICAL ADOPTION

United Kingdom

Scottish Council for Voluntary Organisations · UK · 2026, publication date not stated

Scottish charities show what incremental digital capability looks like

SCVO’s current call to action argues that digital, data, AI and cyber risk should be treated as leadership responsibilities, supported by sustained investment in people, skills and dependable systems. Its examples emphasise incremental change rather than large transformation programmes.

Scottish Wildlife Trust has drafted an internal AI policy and is exploring vector databases to search more than 300 historical policy documents, alongside graph-based retrieval for policy intelligence. Unity Enterprise is testing an AI-powered service that could help carers find relevant information by voice, including work on how the system should respond when someone describes an emergency.

Why it caught our eye: These are useful examples of AI adoption beginning with an organisational need, bounded experimentation and explicit attention to risk. They also show why capability matters: the constraints are not only technical, but include cost, confidence, internal support, accessibility and the capacity to check whether a system behaves appropriately.

Research-window note: SCVO does not state a publication date on the page. It is included as an explicitly approved, materially relevant exception because it contains named, current charity implementation evidence that was stronger than a weaker in-window technical story.

Read SCVO’s call to action →

A CURIA AI PERSPECTIVE

Transparency depends on organisational readiness

Transparency may begin as a principle, but it only protects trust when an organisation has the people and capability to put it into practice.

When a supplier is attacked, a charity cannot communicate clearly unless it knows what information it placed in the system, which people that information concerns and how exposure might affect them. When AI disclosure duties apply, an organisation cannot tell people where AI is being used unless it has maintained an accurate view of its systems and workflows. When a public body publishes an AI register, the register cannot support accountability unless individual systems can be connected to owners, purposes, decisions and changes.

The Beacon incident makes the point particularly clearly. Different organisations may use the same platform in very different ways. One may hold little more than contact and donation records. Another may include detailed information supplied by beneficiaries or service users. The supplier incident may be shared, but the consequences, communications and responsibilities are specific to each organisation. As Bates Wells makes clear, the fact that a supplier experienced the attack does not displace the charity’s responsibilities as data controller.

This is why responsible technology cannot be reduced to policies, certifications or supplier questionnaires. Those things matter, but they have to be supported by operational knowledge – an accurate understanding of data, systems, dependencies, decisions and accountable people.

The SCVO examples offer a constructive counterpart. They show charities starting with particular needs, testing bounded uses and recognising constraints around accessibility, cost, skills, trust and human judgement. That is less dramatic than announcing an organisation-wide AI strategy, but it is a more credible route to sustainable capability.

Principles establish the commitment to openness, care and accountability. People need the confidence and authority to act when circumstances are uncertain. Capability provides the inventories, processes, skills and tested response plans that make good intentions usable under pressure.

Principles People Capability

Trust is not protected by promising that nothing will go wrong. It is protected by being ready to understand, explain and respond when something does.

About this scan

The Weekly Scan is Curia AI’s horizon-scan of responsible AI, governance and trust across the UK, North American and European charity sectors. Curia AI helps charities scale AI responsibly without losing the trust they depend on.

Take the AI governance maturity assessment  ·  Read our Responsible AI Policy  ·  Get in touch

This news report has been brought to you with the assistance of OpenAI’s GPT-5.

Recent posts