Here's a fact worth sitting with: whether or not your church has an AI policy, your church already has AI use. Your youth pastor drafted an email with ChatGPT this week. A volunteer made the sermon slides with an AI image tool. Somebody summarized the board minutes. The only question is whether any of it has guardrails.

I've started collecting the AI policies churches are writing, and they fall into two camps. Some ban almost everything — usually written from fear, by leaders who haven't actually used the tools. Others are so narrow they only answer one question ("don't write your sermon with ChatGPT") and miss everything else that matters. A good policy is neither. Here's what I'd put in one.

The dos

Do name what's encouraged, not just what's banned. A policy that's all prohibitions teaches staff to hide their AI use — and hidden use is where the real risk lives. Spell out the green lights: drafting emails and social posts, summarizing meetings, brainstorming, transcription, research, graphics. Give your team permission to save time on busywork.

Do protect people's information — this is the big one. The most important line in any church AI policy has nothing to do with sermons: never put a congregant's personal information into a public AI tool. Prayer requests, counseling notes, giving records, kids' information — treat them with the same care as a confidential pastoral conversation, because that's what they are. If a tool will touch sensitive data, it needs to be one with a real data agreement, not a free chatbot.

Do draw the pastoral-care line clearly. AI can draft an announcement. It cannot sit with the grieving, counsel the struggling, or know your people. No AI-generated care responses, no counseling chatbots, no outsourcing presence. Write that down — not because your staff wants to do it, but because vendors will pitch it.

Do set an honesty norm. Congregations run on trust. If AI played a significant role in something public-facing — teaching content, a testimony-style story, an image of something that never happened — people should be able to find that out without feeling deceived. A simple integrity test for preaching works well: did I study this text myself, do I own this theology, could I have written this without the tool?

Do give the policy an owner and a review date. AI changes monthly. A policy written once and filed away is a policy about last year's tools. Name one person who owns it and revisit it a couple of times a year.

Do distinguish AI that builds your tools from AI inside your tools. If AI helps write a dashboard that connects to your church database, and the finished tool never sends data to an AI model when it runs, no data has been shared with AI at all — that's just software development, and it's welcome. But if a tool sends real records through an AI model to summarize or interpret them — or a person loads real data into an AI session to analyze it — that is sharing data with AI, even though nobody pasted anything. Those cases need the approved-tools rules: commercial terms with no-training assurance in writing, and only the minimum data the task needs. The rule of thumb that keeps this simple: follow the data, not the developer.

Do train people, not just restrict them. A one-page policy plus one lunch-hour walkthrough of "here's how to use this well" beats ten pages of rules. People follow policies they understand.

The don'ts

Don't ban AI outright. It doesn't work — it just moves the use to personal phones and personal accounts, where your data protections don't exist. And it costs you the genuinely good stuff: hours back every week for the people doing ministry.

Don't write the policy before you've used the tools. This is the most common failure I see. A policy written from headlines reads like it: vague fears, wrong emphases, rules for things that aren't the actual risks. Have the writers spend two weeks actually using AI for admin work first (here's the safest place to start). The policy that comes out will be twice as useful and half as long.

Don't only regulate the chatbot. AI isn't one app you can name — it's now inside the tools your church already pays for: your church software, your design tool, your email platform, your accounting system. A policy that only mentions ChatGPT misses most of the surface area. Write rules by activity (what data, what output, what disclosure) rather than by product.

Don't fake a human. No deepfakes, no synthetic voices of real people, no AI-written "personal" stories presented as lived experience. This should be the easiest paragraph to write and the least controversial.

Don't make it a legal document. If your policy needs a lawyer to read it, your volunteers won't. One or two pages: what we encourage, what we never do, how we protect people's information, who to ask about gray areas.

A starting outline you can steal

  1. Why we're writing this (stewardship, not fear)
  2. Encouraged uses — admin, drafts, research, graphics
  3. Never — congregant data in public tools, AI pastoral care, synthetic people, unreviewed public content
  4. Ask first — new tools, anything congregant-facing, significant teaching assistance
  5. Data rules — what counts as sensitive, which tools are approved
  6. Honesty norms — disclosure and the preaching integrity test
  7. Owner + review cadence

I built a free AI Policy Generator — answer 15 questions and it assembles a board-ready policy plus the adoption kit. And if your church wants help past the policy — training the team, picking the first workflows, keeping the guardrails real — that's what my church AI consulting work covers. A good policy isn't a fence to keep AI out. It's a set of lanes so your team can drive.