UK regulators and cybersecurity bodies increasingly warn that AI is lowering the barrier for producing deceptive content that appears credible. For organizations built on trust, this introduces significant risks to safeguarding, reputation, and financial integrity.
As the National Cyber Security Centre notes: “Adversaries can use emerging technologies to make their content more believable and easier to distribute at scale.”
As AI-generated content becomes increasingly difficult to distinguish from reality, this article examines what CSOs need to know to recognize misleading information, respond effectively, and safeguard the people and communities they serve.
Misleading AI content is now embedded in the digital environment in which CSOs operate. Unlike traditional misinformation, AI-generated content can be produced quickly, cheaply, and at scale, often without obvious indicators of falsity.
In the UK, cybercrime and fraud affecting charities is increasing. Government data shows that around 14% of charities experience cybercrime annually, while phishing remains the most common attack method. Broader sector analysis suggests that over a third of charities experience fraud or attempted fraud in some form.
Charity Digital highlights the reputational risks of AI misuse: “If a charity accidentally shows support for misleading information, it could have serious reputational repercussions.”
This risk is particularly acute for CSOs due to their reliance on emotional storytelling, public trust, and beneficiary-focused narratives. AI-generated misinformation can distort all three.
Types of Misleading AI Content
Misleading AI content is not a single phenomenon but a spectrum of risks.
AI-generated misinformation refers to content that is incorrect but not necessarily malicious. AI-driven disinformation is deliberately deceptive, often designed to manipulate perception or behavior. Synthetic media, including deepfakes, can realistically depict people saying or doing things they never did.
The National Cyber Security Centre warns that such content is increasingly difficult to distinguish from legitimate material, particularly as AI tools become more advanced.
Deepfake and synthetic content are especially concerning in crisis or humanitarian contexts, where urgency reduces verification time.
For example, in March 2022, during the early stages of Russia’s invasion of Ukraine, a manipulated video appeared to show Ukrainian President Volodymyr Zelenskyy telling Ukrainian soldiers to lay down their weapons and surrender. The video was fake, but it was designed to appear credible by using synthetic video and audio. The incident demonstrated how deepfakes can be used during a crisis to spread false information rapidly and potentially influence people's behavior at a moment when they are under significant pressure. For charities and humanitarian organizations operating during emergencies, a similar fake video, image or statement could potentially undermine public confidence, create confusion among beneficiaries or volunteers, or falsely attribute statements to an organization or its leadership
Additionally, AI has significantly increased the sophistication of phishing attacks. Emails that once contained obvious errors can now closely mimic internal communication styles and organizational tone.
The Charities Aid Foundation highlights: "Fraudsters may impersonate “a member of the charity’s executive team” to request urgent payments or sensitive information." UK government data shows that 95% of charities experiencing cyber incidents identify phishing as the primary attack method, and fraud cases across the UK number in the hundreds of thousands annually.
AI enhances these threats by enabling personalization at scale, making scams more convincing and harder to detect.
Identifying Misleading AI Content
Identifying AI-generated content requires layered verification rather than reliance on visual cues alone. AI-generated text may appear fluent but often lacks depth, specificity, or verifiable sources. AI-generated images may include subtle inconsistencies, such as distorted anatomy or unnatural lighting. However, these indicators are becoming less reliable as models improve.
The Charity Digital notes: "AI-generated content may appear “repetitive, wordy, and lack depth.”
Example 1: “We are delighted to announce that our organization has been selected as a leading recipient of the Government’s new £2.5 million Community Resilience Fund. This transformative funding will enable us to expand our services and create meaningful change across communities.” The language sounds professional and plausible, but it is vague. There is no specific government department, funding programme webpage, application reference, date or named spokesperson. A quick search of the relevant government website or Charity Commission records could establish whether the claim is genuine.
Example 2: “Applications are now open for the UK Community Impact Grant 2026, offering charities up to £50,000 to support vulnerable communities. Successful organizations will be selected based on innovation, sustainability and measurable social impact.” This sounds like a genuine grant announcement, but provides no identifiable funder, eligibility criteria, application deadline or official application page. An organization should avoid sharing it until the funding opportunity has been independently verified.
Context is equally important. Content designed to provoke urgency, emotional reaction, or rapid sharing should be treated cautiously. Source verification remains critical, particularly checking against official registers such as the Charity Commission for England and Wales.
Safeguarding Beneficiaries in an AI Context
Misleading AI content poses direct safeguarding risks to beneficiaries, particularly through fabricated stories, manipulated images, or impersonation of individuals.
AI-generated content can distort lived experiences or create entirely fictional beneficiaries. This can lead to emotional harm, misrepresentation, and reputation loss.
Safeguarding also extends to digital environments where beneficiaries may be directly targeted by scams or fraudulent services.
The National Cyber Security Centre emphasises the importance of verification and caution when interacting with unverified digital content. In CSOs, safeguarding must now include digital authenticity checks as standard practice.
Real-World Case Studies and UK Context
Deepfake Crisis Misinformation
A deepfake video of Volodymyr Zelenskyy during the Russian invasion of Ukraine urging Ukrainian troops to surrender posted in 2022 demonstrated how synthetic media can be used in real-time crisis manipulation.
This example demonstrated how a convincing AI-generated video can be used in crisis situations and highlights the risks of misinformation spreading rapidly during humanitarian emergencies.
The key risks for CSO’s the potential to share unverified content, amplifying propaganda unintentionally and can potentially mislead donors.
It is essential to verify media through trusted resources and avoid resharing ‘breaking’ content without confirmation.
AI-Generated images in Fundraising appeals
Multiple viral social media posts have used AI-generated images of children, disaster victims, or animals to drive emotional engagement and donations. In many cases, the stories and individuals depicted were entirely fictional. Multiple viral social media posts have used AI-generated images of children, disaster victims, or animals to drive emotional engagement and donations. In many cases, the stories and individuals depicted were entirely fictional. For example, animal welfare organizations have highlighted the growing use of AI-generated images and videos depicting apparently injured or distressed animals in rescue situations. These posts can be highly convincing and are designed to trigger emotions such as “shock, anger or compassion”, encouraging people to share the content or donate before checking whether the story is genuine. Four Paws provides a useful guide to spotting AI images and videos on social media.
Misleading images can exploit empathy and compassion, which are the core drivers of charitable giving. Trust in legitimate fundraising campaigns can also be undermined.
Fake identities can exploit perceptions of vulnerable groups, and real beneficiaries could be overshadowed or disbelieved.
It’s important to verify images before using them or sharing. Best practice would be to use original, consented photography or images and also be transparent about how images are sourced.
UK Fraud and Phishing Trends
UK government data shows that fraud is one of the most common forms of crime, with hundreds of thousands of cases recorded each year. For charities, this creates significant risks because organizations manage donations, grants, payments and sensitive beneficiary information, often with limited staff and resources. Cybersecurity data shows that 14% of charities experience cybercrime each year, with phishing accounting for the vast majority of reported incidents. AI can make these attacks more convincing by producing professional-looking emails, tailoring messages to individuals and organizations, and potentially imitating the language or communication style of trusted people.
The impact can go beyond financial loss. A successful phishing or impersonation attack could expose donor or beneficiary information, redirect payments, compromise organizational accounts or allow criminals to impersonate the charity online. For example, a finance officer might receive a convincing AI-generated email appearing to come from their CEO requesting an urgent payment to a new bank account. If the request is not independently verified, the charity could lose money within minutes. For charities, AI-related fraud should therefore be considered alongside existing cybersecurity, safeguarding and financial risks, with clear processes for verifying unusual requests before taking action.
Building Organizational Resilience
Resilience requires structured governance, not ad-hoc awareness. The Fundraising Regulator stresses the importance of transparency and human oversight in fundraising communications involving AI.
Organizations should implement clear policies covering AI use, verification standards, and incident response procedures. Staff training is essential, particularly around phishing recognition and content verification.
Operational safeguards such as dual approval processes, multi-factor authentication, and monitoring for impersonation significantly reduce risk.
For more information, make sure to read this article, titled "Organizational Skills and AI in the Third Sector" by Riccardo Naidi.
Conclusion: Trust as the Core Asset
Artificial intelligence is fundamentally changing how information is created, shared and consumed. While these technologies present exciting opportunities for civil society organizations, from improving efficiency to enhancing service delivery. They also introduce new risks that cannot be ignored. The ability to generate realistic images, convincing emails, cloned voices and fabricated stories in seconds means that misinformation, fraud and impersonation are becoming increasingly difficult to detect.
For CSOs, the challenge extends far beyond cybersecurity. Misleading AI content has the potential to damage every aspect of an organization's work. It can erode public confidence, undermine fundraising campaigns, compromise safeguarding, and weaken the trust that beneficiaries, volunteers, partners and donors place in an organization. Once trust is lost, it can take years to rebuild.
The UK's charity sector has always depended on authenticity. Whether telling the story of a beneficiary, launching an emergency appeal, or advocating for policy change, organizations rely on the public believing that what they see and hear is accurate. As AI-generated content becomes more sophisticated, that authenticity can no longer be assumed, but must be actively demonstrated.
This means developing a culture where verification becomes routine rather than exceptional. The staff of CSOs should feel confident questioning unusual requests, communications teams should routinely verify images and stories before publication, and trustees should recognise AI-related misinformation as an organizational risk alongside financial management, safeguarding and data protection.
Importantly, responding to misleading AI content should not be viewed as a barrier to innovation. AI has enormous potential to help charities analyse data, draft communications, improve accessibility and increase operational efficiency. The objective is not to discourage its use, but to ensure it is adopted responsibly, transparently and with appropriate human oversight. Organizations that establish clear governance, provide staff training and embed verification processes will be far better positioned to benefit from AI while minimising its risks.
The responsibility of CSOs also extends beyond their own organizations. As trusted voices within communities, charities are uniquely placed to help improve digital literacy. By educating beneficiaries, volunteers and supporters about AI-generated misinformation, phishing attempts and online scams, organizations can strengthen community resilience and help protect those who may be most vulnerable to digital deception.
Ultimately, the rise of misleading AI content is not simply a technology issue, but a challenge to trust itself. In a world where almost anyone can create convincing but false content, credibility will become one of the most valuable assets a civil society organization possesses. Those organizations that invest in transparency, verification and responsible AI governance will not only reduce their exposure to risk but will also reinforce the confidence that communities place in them.
Perhaps the most important lesson is that AI does not remove the need for human judgement, it makes it more important than ever. Technology can generate content in seconds, but it cannot replace the experience, empathy, and ethical decision-making that underpin the work of the civil society sector.
As AI continues to evolve, so must the organizations that serve our communities. By embedding robust governance, strengthening safeguarding practices, and fostering a culture of critical thinking, CSOs can embrace the benefits of AI while protecting the people, causes and communities that depend on them.
Key Takeaways
Trust remains the charity sector's greatest asset, and protecting it should underpin every AI-related decision.
Misleading AI content is now an operational risk, affecting communications, fundraising, safeguarding, governance and cybersecurity.
Verification should become standard practice, particularly when sharing stories, images, videos or responding to urgent requests.
Trustees and senior leaders should include AI risks within organizational risk registers and ensure appropriate policies and staff training are in place.
Digital safeguarding is becoming as important as physical safeguarding, particularly for organizations supporting vulnerable people.
Responsible AI adoption is not about avoiding technology, it is about using it ethically, transparently and with human oversight.
CSOs have an important role in improving digital literacy, helping beneficiaries, supporters and communities recognise misleading AI content and online scams.
The organizations that prepare now will be best placed to maintain public confidence and maximise the opportunities AI can bring.
Your Feedback Matters
What did you think of this text? Take 30 seconds to share your feedback and help us create meaningful content for civil society!
Disclaimers
This piece of resources has been created as part of the AI for Social Change project within TechSoup's Digital Activism Program, with support from Google.org.
AI tools are evolving rapidly, and while we do our best to ensure the validity of the content we provide, sometimes some elements may no longer be up to date. If you notice that a piece of information is outdated, please let us know at content@techsoup.org.
This content was created with AI assistance and has been reviewed and edited by Travis Giblen Bagby.
