AI detection of fake charity sites carries legal exposure for platforms
- Authority
- California Attorney General
- Rule type
- statute
- Jurisdiction scope
- US state
- Effective date
- Jul 1, 2026
- Source text
- Read primary rule text ↗
Obtain written authorization from named charity before solicitation
By Q3 2026, the legal question around AI detection of fake charity websites is no longer whether platforms should screen donation pages. They should. The harder question is whether screening changes the platform’s legal posture when the page never should have existed without the named charity’s consent.
The current enforcement signal is unusually concrete. On March 3, 2026, a bipartisan group of 23 state attorneys general and charity regulators sent GoFundMe a letter pressing the company to prove that it had removed 1.4 million unauthorized donation pages within 14 days.[1] That is not a complaint about a handful of obviously fake appeals slipping past a filter. It is a demand that a platform account for unauthorized listings at scale.
The same pattern appeared again in the Donate.gg controversy. In July 2026, Whiteford reported that the crypto donation platform had created nearly 10,000 unauthorized nonprofit donation pages, with more than $2 million in undistributed funds connected to those pages.[2] The numbers matter because they describe the operational problem regulators are now seeing: a fundraising interface can look orderly, automated, and donor-friendly while the underlying consent record is missing.

That distinction is the center of the legal exposure. An AI system may identify suspicious donation pages faster than a manual review team can. It may spot repeated text, inconsistent domains, unusual payment flows, or clustered behavior. Those controls are useful. They do not answer whether the charity agreed to be listed, whether donor money is being held correctly, whether the solicitation disclosures are adequate, or whether the platform has registered where registration is required.
The enforcement pattern is about authorization, not just fraud
Many platform fraud programs are built around detection: find the suspicious page, score it, route it, suspend it, or release it. That architecture works best when the legal problem is deception visible on the page or in the transaction pattern. Unauthorized charity solicitations are different. A page can be cleanly written, use the correct charity name, route money through a real payment system, and still be legally defective if the charity did not consent to the listing.
The GoFundMe letter is important for that reason. The demand described by Crowell & Moring was not limited to pages that had already been proven fraudulent. It focused on unauthorized donation pages and required GoFundMe to show removal at a scale of 1.4 million pages.[1] A platform response built only around the sophistication of its anti-fraud model would leave the regulator’s main question unanswered: who authorized these pages to solicit in the charity’s name?
Donate.gg sharpened the same point in a different setting. The reported issue was not simply that crypto donations are risky, or that AI verification may be imperfect. The issue was that thousands of nonprofit pages allegedly existed without direct nonprofit authorization, and funds associated with those pages had not been distributed.[2] For the named nonprofit, that is not an abstract platform-risk problem. It can become a donor-relations problem, a state-registration problem, and a cleanup project imposed on an organization that did not choose the campaign.
| Platform control | What it can address | What it does not prove |
|---|---|---|
| AI fraud detection | Suspicious language, repeated campaigns, abnormal payment or account behavior | That the named charity consented to the solicitation |
| Takedown workflow | How fast a platform removes or disables a reported page | That the page was lawful when it first went live |
| Donation routing controls | Whether funds are held, released, refunded, or redirected under platform rules | That the platform satisfied state fundraising platform obligations |
| Charity verification | Whether the organization exists and can be matched to an external record | That the organization authorized this platform, this page, and this fundraising use |
This is where legal and technical vocabulary often slide past each other. A verified charity is not necessarily a consenting charity. A low-risk page is not necessarily an authorized page. A model that detects most fraud does not create legal permission for the platform to host solicitations that state law requires the charity to approve.
California AB-488 makes consent architecture visible
California’s AB-488 is the leading statutory model in the current materials because it regulates charitable fundraising platforms as platforms, not merely as passive websites that may encounter fraud. The California Attorney General’s charitable fundraising platform materials describe obligations including registration, written consent in relevant circumstances, handling of funds, and donor-facing disclosures.[3] Those duties took effect in the regulatory environment beginning in 2024.[3]
The practical consequence is straightforward. If a platform allows a donor-facing page to solicit for a charity before the required consent is obtained and preserved, the platform has a compliance problem even if the page contains no obvious scam signal. The problem is not that the AI model failed to see fraud. The problem is that the platform treated absence of detected fraud as a substitute for affirmative authorization.
AB-488 also matters because it links consent to other platform duties. Written authorization is not an isolated checkbox. It sits next to registration obligations, rules for segregating or handling donated funds, and donor disclosures.[3] A platform that cannot identify which charity authorized which page, under which terms, and when, will struggle to prove the rest of the chain. The fund-holding issue in the Donate.gg matter shows why that chain matters: once money has been collected, the compliance question is no longer only whether a page should come down, but what happens to donor funds that were collected through an unauthorized destination.[2]

The false comfort comes from dashboards that report takedown speed, fraud scores, or model confidence. Those metrics can be meaningful controls, but they measure the review system. They do not measure legal authorization unless the platform has deliberately built consent capture into the same operating record.
Hawaii confirms this is becoming a patchwork
Hawaii’s Act 108, effective July 1, 2026, follows the California model and extends the platform-specific regulatory approach beyond a single large state.[4] Verrill’s November 2025 alert framed the law as Hawaii following California with a new charitable fundraising platform law.[4] For national platforms, that development matters less as a one-off Hawaii issue than as evidence that consent-based platform regulation is spreading through state law rather than waiting for a uniform federal rule.
That does not mean California and Hawaii supply a 50-state answer. They do not. State charitable solicitation laws vary, and the current research record does not support treating AB-488 or Act 108 as a comprehensive map of every jurisdiction. The safer operational assumption is narrower and more useful: if a platform operates nationally, its charity-page workflow needs a state-law layer that can identify where direct consent, registration, disclosure, and fund-handling duties apply.
AI screening does not remove that layer. If anything, it can hide the missing state-law analysis when the product team describes the tool as if it were the compliance program. A risk score may decide which pages receive extra scrutiny. It should not decide whether the platform is legally allowed to create or display a donation page in the first place.
The two exposures should be kept separate
For platform counsel, the cleanest way to analyze AI detection of fake charity websites is to separate two exposures that often get bundled together.
| Exposure | Trigger | Why AI matters | Why AI is not enough |
|---|---|---|---|
| Failure-to-detect exposure | A fraudulent or unauthorized page remains live and donors are misled or funds are mishandled | AI monitoring can reduce review time and identify patterns humans may miss | A missed page may still create regulatory, consumer-protection, donor, and charity-facing consequences |
| Regulatory non-compliance exposure | A platform hosts or facilitates a charity solicitation without satisfying state platform duties | AI may help triage pages and identify suspicious anomalies | Consent, registration, disclosure, and fund-handling duties require affirmative compliance records |
The first exposure is the familiar one. A model misses a fake or abusive page. Donors give. The named charity may have to explain that it did not sponsor the appeal. Regulators may ask what the platform knew, what it should have known, how quickly it responded, and whether its controls were adequate. The January 2026 Charity Lawyer Blog discussion of fake charity appeals places these problems within the broader set of platform and charity duties arising around online donation scams.[5]
There is not, on the materials available here, a settled line of case law holding that an AI detection failure by itself constitutes a statutory violation under state charitable solicitation laws. That gap matters. A plaintiff, regulator, or attorney general may argue from existing duties, consumer-protection principles, and platform-specific fundraising statutes, but the AI-failure theory should be described as an enforcement and litigation risk, not as adjudicated doctrine.
The second exposure is less familiar to product teams and more dangerous in a consent-based statute. The platform can accurately detect and remove many scams while still violating a rule that requires charity consent before, or as a condition of, listing. In that posture, the platform’s problem is not model performance. It is legal architecture.
Donate.gg is a useful example because the reported problem involved shadow donation pages and undistributed funds, not merely pages that looked suspicious to a fraud classifier.[2] A shadow page can be ordinary in every way a model knows how to measure. It may use a real charity name, a plausible description, and a functional payment flow. The missing element is a signature, authorization record, onboarding approval, or other consent artifact tied to that charity and that use.
Where AI systems fail legally
The usual AI discussion spends too much time on accuracy as if liability rises or falls with the model’s F1 score. Accuracy matters, but it is not the only legal variable. In the charity-platform setting, the legally relevant failure modes are more specific.
- False negative: the system fails to flag a fraudulent or unauthorized appeal, allowing donors to give through a page that should have been stopped or reviewed.
- False positive: the system blocks, delays, or escalates a legitimate campaign, potentially disrupting an authorized fundraising activity and creating evidence that the platform’s controls are blunt or poorly governed.
- Consent-blind approval: the system correctly determines that a page does not look fraudulent, but the platform has no direct charity consent for the solicitation.
- Recordkeeping failure: the system makes or supports a decision, but the platform cannot later reconstruct what consent existed, what disclosure was shown, what funds were held, or why the page remained live.
- Jurisdictional mismatch: the system applies one national workflow while state-specific platform registration, consent, disclosure, or fund-handling rules require different treatment.
The consent-blind approval is the failure mode most likely to be underestimated. A model trained to identify scams will not necessarily ask whether a nonprofit authorized the platform to raise money in its name. That is not a fraud signal unless the platform defines it as one and connects the model to a consent database. Even then, the consent database—not the model—is the source of legal proof.
Recordkeeping deserves the same attention. A platform that removes a page quickly may still need to explain when it went live, how many donors gave, what disclosures appeared, where the funds sat, whether the charity was contacted, and what authority existed for the page. California’s platform materials make those surrounding duties part of the compliance environment, not optional back-office details.[3]
The nonprofit bears costs the platform may not see
Unauthorized donation pages do not only create donor-confusion risk. They can also put nonprofits in a compliance trap. Charity Lawyer Blog described the problem in April 2026: nonprofits attempting to withdraw state registrations may face regulators pointing to unauthorized third-party donation pages as evidence of continued fundraising activity.[6] That is a useful reminder of who absorbs the mess after a platform treats charity identity as available infrastructure.
From the nonprofit’s perspective, the page may have generated no useful funds, no usable donor relationship, and no intentional campaign. Yet the organization may have to contact the platform, explain the issue to donors, correct regulator assumptions, and preserve its own registration posture. That burden is not solved by a platform saying its fraud model did not identify the page as malicious.
The same April 2026 discussion identified AI monitoring and prompt takedown as part of the documented defense posture for dealing with unauthorized pages.[6] That point should not be ignored. Monitoring and takedown matter, especially where unauthorized appeals can multiply faster than a human review queue. But they are remedial controls. They do not retroactively supply the charity’s consent.
Section 230 is a question, not a compliance program
Platform counsel will ask about Section 230 quickly, and they should. A platform facing state-law claims over user-generated donation pages may consider whether federal immunity applies to particular theories of liability. The harder question is how Section 230 interacts with state statutes that impose direct obligations on charitable fundraising platforms themselves—registration, consent, disclosure, and fund-handling duties tied to the platform’s own role.
The materials here do not support a definitive answer to that immunity question. They do support a more modest conclusion: Section 230 should not be treated as permission to skip the consent workflow. A defense to certain publisher-liability theories is not the same thing as evidence that the platform registered where required, obtained written consent where required, segregated or handled funds properly, or gave donors the required disclosures.
What a defensible platform architecture needs to prove
A serious AI deployment for charity-page risk should be attached to a consent and funds-control architecture. Otherwise the platform is automating only one part of the problem. The more useful design question is not “How accurate is the fake-site detector?” but “What can the platform prove about this page before, during, and after solicitation?”
- Charity identity: the platform should distinguish between verifying that an organization exists and verifying that the organization authorized this platform use.
- Consent record: the system should preserve the authorization source, date, scope, renewal or expiration terms, and the person or account that granted approval.
- Listing gate: pages that require consent should not go live merely because no fraud signal appears.
- Fund status: the platform should be able to show where donor funds are held, whether they are segregated, when they are released, and what happens if consent is disputed.
- Disclosure versioning: donor-facing disclosures should be tied to the transaction record, not left as generic site copy that cannot be reconstructed later.
- Escalation evidence: AI alerts, human review notes, takedown timing, charity notices, and donor remediation steps should be retained in a form usable by compliance and legal teams.
- State-law routing: the workflow should identify which state platform laws apply and should not assume California and Hawaii exhaust the field.
The AI system can support several of those controls. It can flag inconsistent pages, compare campaign language across accounts, surface unusual donor flows, or prioritize review when a high-volume page lacks a consent record. It can also help identify unauthorized copies after the fact. Those are valuable uses. The legal proof still comes from the platform’s ability to show authorization, disclosures, fund handling, and response history.
This distinction also changes procurement. A vendor promise to detect fake charity websites is not enough for a regulated fundraising platform. The platform needs to know whether the tool integrates with charity onboarding, consent storage, page-publication gates, fund-hold rules, and audit logs. If it does not, it may be a useful fraud layer, but it is not a compliance layer for AB-488-style obligations.
The current legal implication is exposure, not settled AI doctrine
It would overstate the law to say that courts have already created a specific doctrine of platform liability for failed AI detection of fake charity websites. The present record is more practical and less tidy: state regulators are challenging unauthorized charity-page models, demanding proof of removal, and focusing on whether platforms had authority to solicit in the first place.
That is enough to affect legal posture now. A platform that deploys AI screening but permits unauthorized charity pages to go live faces failure-to-detect risk if the page is fraudulent or harmful. It also faces regulatory non-compliance risk if state fundraising platform laws require consent, registration, disclosures, or fund controls that the platform did not satisfy. The second risk remains even when the AI works as designed.
The defensible answer is therefore not to abandon AI detection. It is to stop asking AI to do the work of consent law. Monitoring, fraud scoring, and prompt takedown are important controls. They should sit on top of, or alongside, a system that verifies charity consent before listing where required, preserves evidence of that consent, controls donor funds, and treats state charitable fundraising platform laws as direct obligations. This article is a regulatory risk analysis, not legal advice; the jurisdiction-specific answer still requires a live review of the platform’s donation flow and applicable state law.
References
- Bipartisan Group of State Attorneys General Send Letter to GoFundMe — Crowell & Moring, March 11, 2026.
- Donate.gg's Unauthorized Nonprofit Donation Pages — Whiteford, July 17, 2026.
- Charitable Fundraising Platforms — California Attorney General.
- Mahalo Hawaii – Hawaii Follows California with a New Charitable Fundraising Platform Law — Verrill, November 2025.
- Donation Scams: Identifying Fake Charity Appeals – Legal Duties of Platforms and Charities in 2026 — Charity Lawyer Blog, January 26, 2026.
- Why Unauthorized Donation Pages Are a Real Problem for Nonprofits — Charity Lawyer Blog, April 13, 2026.
Operationalizing workflow
No workflow has been explicitly linked to this obligation yet. See Workflows generally.
Illustrative cases
No illustrative case is currently tracked for this obligation. See Risk Digest for documented incidents generally.
← Back to RegulationReport a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this regulation entry should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →