Opti'
🛡️ Reference guide

SAFE AI, the framework for humanitarian AI

SAFE AI is the governance framework the humanitarian sector has given itself to use AI responsibly. Its principles, its three risk tiers, its four-stage method and its tools, explained simply.

Up to date as of 21 September 2026. This page is not legal advice.

📄 Download the summary guide (PDF, in French)

SAFE AI, in one sentence

SAFE AI, short for Standards and Assurance Framework for Ethical Artificial Intelligence, is the AI governance framework designed for humanitarian action. It was published in May 2026, as version 1.1, by CDAC Network, The Alan Turing Institute and Humanitarian AI Advisory, with funding from the UK Foreign, Commonwealth and Development Office (FCDO). Its authors: Helen McElhinney, Anjali Mazumder, Michael Tjalve, Suzy Madigan and Sarah Spencer.

It presents itself as the operational layer of humanitarian AI assurance: it does not replace data protection policy, safeguarding or security risk management. It connects them to the risks specific to AI, building on the structures organisations already have.

Why this framework exists

The starting point is a risk the authors name plainly: an underfunded, overstretched sector could accelerate towards unsafe use of AI to cut costs, with serious consequences for vulnerable populations. Their March 2026 report, The Governance Gap in Humanitarian AI, finds that AI is already deployed in contexts of vulnerability and power asymmetry, without an operational framework shared across the sector.

Field data point the same way. According to the January 2026 survey by the Humanitarian Leadership Academy and Data Friendly Space, 75% of humanitarians use AI daily or weekly, but only 23% work in an organisation with a formal AI policy, and 19% in Sub-Saharan Africa.

The right to know

The whole framework is organised around one principle. People affected by decisions influenced by AI have the right to:

  1. know that automation is in play;
  2. understand how it shapes the decisions that concern them;
  3. contest those decisions.

This right also applies collectively: when several organisations use AI in the same area, communities have the right to know whether they are all held to the same standard.

What SAFE AI is not: a data governance framework, an AI literacy course, an ethical self-assessment, a one-size-fits-all compliance checklist or a menu of optional tools. Its evidence is designed to be inspected by someone other than the organisation that produces it.

Humanitarian principles, applied to AI

SAFE AI turns humanitarian principles into concrete decision criteria.

PrincipleWhat AI can undermineWhat SAFE AI asks
HumanityA system can cause harm while improving efficiency.Look at the cost of error, exposure to harmful content and the minimum human oversight required.
ImpartialityAI can exclude through language, data gaps, connectivity or proxy variables.Check whether the use creates unequal access, and whether that effect can be detected and corrected.
NeutralityData, infrastructure and partnerships can create alignment with a party to a conflict.Recognise these trade-offs, justify them, mitigate them.
IndependenceRelying on a supplier can shift control away from the organisation.Keep the authority to pause, modify or decommission the system.

The second pillar is keeping communities in the loop. Communities are domain experts: they see the language errors and exclusions that no internal test reveals. The framework distinguishes designing for people, where you consult and then decide alone, and designing with them, where they have real influence. It names participation washing as the dominant failure mode.

The three risk tiers

SAFE AI classifies each use case, not each tool. The tier determines which tools to use.

TierType of useTools required
1 · BaselineAdvisory and easily reversible. Does not directly influence decisions about people. Mostly internal. One to two days of work.Impact assessment (first part), lean transparency card.
2 · EnhancedInfluences prioritisation, targeting or operational decisions. Humans stay in control, but AI shapes the choices. Uses community data. One to two weeks.Full impact assessment, full card, technical assurance, targeted co-design.
3 · High riskDirectly affects access to assistance, protection or information. Community-facing or automated at scale. High cost of error.All tools, full co-design mandatory, independent support likely.

Two rules to remember: internal use does not guarantee tier 1, and when in doubt, apply the higher tier.

The method: a four-stage journey

Each stage closes with a decision gate: proceed, redesign, pause or stop.

StageWhat happens
1 · Problem definitionState the problem in plain language, without mentioning AI; ask whether AI is really the solution; check organisational and data readiness; first impact assessment.
2 · DesignIdentify risks and the cost of error; involve communities; choose the architecture deliberately; second impact assessment.
3 · DevelopmentProcure with the right clauses (right to audit, exit, change notification); test in real conditions and in the languages people speak; sign off before deployment, with a named owner.
4 · Deployment and monitoringPublish the transparency card before go-live; open feedback channels from day one; reassess regularly; handle incidents; know how to decommission the system.

Responsible refusal

Not using AI is a valid outcome, and indeed a SAFE AI outcome in its own right. If one of these conditions applies and cannot be mitigated, the organisation pauses, redesigns or stops:

  • no meaningful path to redress for the people concerned;
  • accountability cannot be clearly assigned;
  • data is reused beyond what people could reasonably expect;
  • people who cannot opt out would be disproportionately affected;
  • automation would replace essential human judgement;
  • adoption is driven by urgency, cost or donor pressure, without a demonstrated improvement for affected people.

Tools and resources

The framework comes with ready-to-use tools, published and kept up to date online:

  • the onboarding readiness checklist, in five sections: taking stock, accountability, rules, costs, team;
  • the use case readiness checklist, with its decision matrix;
  • the impact assessment, in two rounds, with four red lines;
  • the risk mitigation strategies, by tier and by type of risk;
  • the co-design guidance with communities;
  • the architecture and tech stack decision guide;
  • the procurement guide, with the minimum clauses of a contract;
  • technical assurance, on seven trustworthiness characteristics;
  • the transparency card, in a lean or full version.

The transparency card is the central document: it is filled in along the journey and published before deployment. The framework is unambiguous: “if it's not captured in the Transparency Card, it is not considered governed by SAFE AI”.

The framework also gives donors a basis for requesting evidence proportionate to the risk of the use, not to the size of the grant. The texts and tools are published at cdacnetwork.org/safe-ai.

SAFE AI and the AI Act

The two do not play the same role. The AI Act is a law, binding on organisations established in the Union or whose outputs are used there. SAFE AI is a voluntary sector standard, which goes further on humanitarian principles and communities. SAFE AI itself lists the AI Act among its references. For the details of the law: the EU AI Act explained for humanitarian organisations.

Train in SAFE AI, for free

Opti Academy offers a complete course on SAFE AI, written from the text of the framework: the right to know, the principles, the three tiers, the four-stage journey, responsible refusal, the tools, then an exercise to classify your own uses. Nine steps, about an hour. It is free on every plan, including the free account, and uses no tokens. The course is currently in French.

Frequently asked questions

Is SAFE AI mandatory?

No. SAFE AI is a voluntary framework, which creates no legal obligation and grants no certification. It provides a defensible basis for decisions, and donors can use it to set their expectations.

Can a small organisation apply it?

Yes. The framework is proportionate to risk, not to the size of the organisation. A tier 1 use case can be documented in one to two days, with a lean transparency card.

Do you need to be an AI specialist to use SAFE AI?

No, as the framework itself says. It does however require a multidisciplinary team: technology, procurement, programmes, compliance, protection and community engagement.

What is the difference between the impact assessment and the transparency card?

The impact assessment is the analytical exercise carried out at each decision gate. The transparency card is the record that keeps track of it, with every decision taken along the journey.

Where can I find the official texts?

At cdacnetwork.org/safe-ai, where the framework, the tools and the glossary are published and kept up to date. The version described on this page is 1.1, from May 2026.

Take the free SAFE AI course

Nine steps, about an hour, a summary to keep. On every plan, including the free account, with no tokens used. The course is currently in French.