Your church needs an AI policy: a practical guide for 2026 (with free template)

91% of church leaders support AI use, but only 5% have a policy. A practical guide to writing one for your church, with a free template you can adapt.
The numbers tell a story most churches haven't quite caught up with yet. 91 per cent of church leaders surveyed in 2025 said they support staff using AI tools for ministry. 45 per cent are actively using them. 5 per cent have a written policy that says how.
That's the gap we want to talk about. Not 'should churches use AI?' That horse has bolted. The real question is: how do you let your team use these tools without ending up on the wrong side of a privacy breach, a copyright issue, or a Sunday morning where the sermon AI hallucinated half a Bible verse?
The answer is a policy. Not a 50-page legal document. A two-page document that sets expectations, lists what's in bounds and out of bounds, and gives your team confidence to use the tools without paralysing them with caution. There's a free template at the bottom of this article.
Why this matters now
Three things have changed in the last two years that make a policy genuinely necessary.
First, ChatGPT and similar tools are now so good at tasks like rewriting emails, summarising meetings, and drafting communications that staff use them without thinking. The 'should we?' moment passed. The 'what should we be careful about?' moment is here.
Second, the data churches handle is unusually sensitive. Pastoral conversations. Mental health disclosures. Family situations. Children's records. Giving data. Most consumer AI tools (including the free tier of ChatGPT) train on user inputs unless you actively turn that off. Your pastor pasting a counselling note into a free AI tool is, technically, training a public model on a confidential conversation.
Third, the legal landscape is moving. Australia's Privacy Act review is producing recommendations that affect how charitable organisations handle personal data, including AI processing. Even if your church is small, the tools you use are shaped by these regulations, and your policy should reflect that.
What an AI policy is for
Three things a good AI policy does:
- Defines what kinds of data may and may not be put into AI tools, by category.
- Lists the tools that are approved for the church, the tools that are explicitly banned, and the process for adding new ones.
- Sets expectations for human oversight, attribution, and the church's voice.
Three things a good AI policy avoids:
- Prescribing specific AI tools by name in long lists. Tools change too fast. Policies should describe categories.
- Banning AI use entirely. Your staff are using it whether the policy says they can or not. Better to set boundaries than to push it underground.
- Reading like an HR document. The audience is your kids leader and your worship pastor. Plain English, please.
The five sections every church policy needs
1. Data classification
Three buckets:
Public data is fine to use freely with AI tools. This includes published sermons, public-facing newsletter copy, published event details, anything already on your website. Drafting a social media post about Sunday's sermon using ChatGPT is fine because the source material is public anyway.
Internal data requires care. This includes meeting agendas that aren't confidential, draft policies, internal communications, anonymised statistics. These can go into approved AI tools (the ones your church has vetted), but not into random consumer AI tools where the inputs might train public models.
Confidential data does not go into AI tools at all. This includes pastoral conversation notes, counselling records, anything related to a minor that identifies them, giving data tied to named individuals, personal information about staff or volunteers, anything covered by the seal of the confessional or its denominational equivalent.
If a staff member can't tell which bucket something falls in, the policy says: assume confidential, ask the senior pastor or church manager.
2. Approved and banned tools
Approved tools list: the AI tools your church has vetted. For a typical Australian church, this might include ChatGPT (paid Team or Enterprise tier where data isn't used for training), Microsoft 365 Copilot if you're already on Microsoft, and the AI features built into your church management software where you've reviewed the privacy posture.
On that last point: Floways AI is included in the Core and Complete plans. Our AI inference runs server-side through Anthropic's API. Your church's data is never used to train external AI models, full stop. That's not marketing language, it's a design choice. You can verify the details at floways.co/security.
Banned tools list: anything where the data privacy is unclear or actively bad. Most free consumer AI tools sit here unless you've actively configured them to not train on inputs.
New tool process: a one-paragraph statement of who reviews and approves new AI tools. Usually the church manager or operations lead. The criteria: where is the data stored, does the vendor train on inputs, what's the privacy commitment, is it AU-based or international?
3. Human oversight
Three categories of AI output that need different oversight:
Output for internal use (drafting an internal email, summarising a meeting): light human review. The user reads it, edits if needed, sends. The user is responsible for accuracy.
Output for external use (newsletter copy, social media, website content): formal review. Two pairs of eyes. The user creates, someone else proofreads. Both have authority to publish.
Output that represents the church's spiritual or pastoral voice (sermon notes, devotional content, prayer responses, pastoral communications): pastor or designated leader review. AI is a starting point, not a finishing point. The church's voice belongs to the people called to it, not to the model.
4. Attribution and transparency
Do you tell the congregation when content is AI-assisted? The honest answer for most churches: only when it would matter to them. AI-assisted social media post? No attribution needed. AI-generated devotional published as if from the senior pastor? Yes, this needs disclosure. The principle is: if a member would feel deceived to learn how the content was made, disclose it.
Do you allow AI-generated images? Stock photo replacement is generally fine. Photorealistic images that imply specific people exist or specific events happened is a no. The line is about whether the image misrepresents reality.
5. Children and youth
AI tools and minors require their own short section. Three rules:
- No information identifying a minor goes into any AI tool, ever. Not their name, not their photo, not pastoral notes about them. Even in approved tools.
- Any AI use in kids or youth ministry programmes must be supervised by an adult who has reviewed the AI tool's outputs in advance.
- AI-generated content used in kids ministry is treated like any other ministry resource. It's reviewed for theological accuracy, age-appropriateness, and alignment with your church's child safety standards.
Common questions when you start writing yours
Should the policy be public?
The summary version, yes. A two-paragraph statement on your website saying 'here's how our church thinks about AI' demonstrates that you've thought about it. The full policy stays internal, like most operational documents.
Who signs it?
All paid staff and any volunteer who handles confidential data (kids ministry leaders, pastoral team, finance volunteers). One-time signature, with annual reminder of any updates.
How often do we update it?
Annually at minimum, with the option to update sooner if a major tool change happens. Tool list refresh quarterly. Section structure usually doesn't need to change for a few years.
Who owns the policy?
The board approves it. The church manager or operations lead maintains it. The senior pastor is the final arbiter for spiritual or pastoral edge cases.
What good looks like in practice
Three small examples from churches we've worked with. Composite to protect privacy.
A 200-person Anglican parish put their policy in their staff handbook. Two pages. New staff sign during onboarding. The youth pastor uses ChatGPT Team to brainstorm small group questions, with the rector reviewing before the programme runs. Nobody hides their AI use, nobody panics about it. It's just a tool, used within bounds.
A 600-person multi-site Pentecostal church wrote a more detailed policy because their data exposure is larger. They explicitly ban any AI-generated photorealistic imagery of children, after a near-miss where a volunteer used a stock-photo replacement tool that produced an unsettling result.
A small Baptist church plant of 40 people decided their policy was too short to need its own document. They added one paragraph to their existing communications policy: 'AI tools may be used to draft public-facing content with appropriate review. They may not be used with member-identifying or pastoral information.' For their size, it's enough.
Frequently asked questions
Do we really need a written policy if we're a small church?
Yes, even if it's one paragraph. A written policy gives staff a clear answer when they encounter a new tool or a new use case. Verbal understandings drift. Written policies don't.
What if our denomination has its own AI guidance?
Use it as the foundation. Your church's policy can be a one-page addendum that lists your specific approved tools and any local context. Don't write from scratch if your denomination has done the heavy lifting.
Can volunteers use ChatGPT for their roles?
Yes, within the same boundaries as paid staff. The data classification rules are the most important piece. A volunteer drafting a one-off birthday message using a free AI tool is probably fine. A volunteer pasting member contact lists into the same tool is not.
What about AI for sermon writing?
The policy can say 'AI may be used as a research and brainstorming tool, but the sermon is the work of the preacher and reflects their voice and theology.' The deeper question of how much AI assistance is appropriate in sermon preparation is one for your pastoral leadership and theological framework, not your IT policy.
Are there free AI tools we can use safely?
Some, with care. Microsoft 365 Copilot is bundled into many church Microsoft 365 subscriptions and has reasonable privacy posture for paid tiers. Free ChatGPT can be used safely for public-data tasks if you've turned off training on inputs in your settings. The principle: 'free' often means the tool is paid for with your data. For confidential data, paid tiers with explicit privacy commitments are worth the small cost.
Where to from here
Download the free policy template at the link below. It covers all five sections with prompts for the church-specific details.
Have a 90-minute conversation with your senior pastor, church manager, and one board member with operational expertise. Walk through the template, fill in your specifics.
Take the draft to your full board for approval, then publish to staff and have them sign at your next staff meeting.
If you'd like to see how Floways handles AI within our platform, and what privacy commitments we make about your church's data, you can read the details at floways.co/security or book a 20-minute demo at floways.co.
We'll show you how the modules in this article come together for a church your size — no slide deck, no commitment.