In brief

  • A church AI policy is short, specific and approved by whoever governs the church — trustees, elders or a church council.
  • It should name permitted, restricted and prohibited uses rather than attempting to list every tool.
  • Personal data and pastoral confidences are the highest-risk areas and need explicit rules.
  • This article is educational and is not legal advice. For UK data-protection duties, work from the Information Commissioner’s Office guidance and take advice where needed.

Why a small church still needs a written policy

Volunteers are already using these tools. Someone has pasted a rota into a chatbot; someone has generated an image for a poster; someone has asked for wording for a difficult email about a real person. Without a policy, each of those decisions is made privately, at speed, by whoever happens to be doing the task.

A written policy does three things. It protects people whose information passes through the church. It protects volunteers, who should not have to guess. And it protects the church’s witness, because the alternative to a stated standard is an implied one that nobody agreed.

Length is not virtue here. One page that people read beats twelve pages that live in a folder.

Scope: who and what the policy covers

State plainly at the top:

  • Who it applies to — staff, elders, trustees, volunteers, and contractors working on church material.
  • What it applies to — any generative tool used for church work, including chatbots, image and video generators, transcription and meeting-notes tools, and AI features built into software you already pay for.
  • Where it applies — church-owned and personal devices alike, when the work is church work.
  • Who owns it — a named role responsible for questions, and a named body that approves changes.

Permitted, restricted and prohibited uses

Three tiers are easier to remember than a long list of rules.

Permitted without approval. Drafting public communications; summarising material the church already owns; producing accessible or plain-English versions; research that will be verified; brainstorming; formatting and proof-reading.

Restricted — approval and a named reviewer required. Anything published in the church’s name that has not been rewritten by a person; images or audio depicting people; translation of material to be used in worship; drafting policies, safeguarding documents or financial communications; any use involving young people’s work.

Prohibited. Entering personal data or pastoral confidences into any tool not approved for it; generating images of identifiable people without written consent; producing prayers or pastoral messages presented as personal; using AI output in safeguarding assessments or decisions about individuals; presenting generated content as someone’s own words.

Personal data and pastoral confidentiality

Most consumer AI tools transmit what you type to a third party, and some use it to improve their systems. That makes the ordinary rule simple: names, contact details, health information, safeguarding matters, giving records, marriage and family circumstances, immigration status and anything shared in pastoral confidence must not be entered.

Where you genuinely need help with a sensitive task, de-identify it. “Draft a gentle letter declining a request to hire the hall” is fine; the applicant’s name and history are not needed for the tool to be useful.

UK churches handling personal data have duties under data-protection law regardless of size. The ICO’s guidance on AI and data protection is the right starting point, and your existing privacy notice should mention AI processing if you introduce it. This article is educational and does not constitute legal advice.

Safeguarding within the policy

Your AI policy should point to your safeguarding policy rather than compete with it. Three additions are usually needed: no images of children or young people may be uploaded to generative tools; no AI tool may be used to assess, triage or record a safeguarding concern; and any disclosure of harm involving AI-generated material — a manipulated image, a threatening deepfake, an exploitative chat — is reported to the safeguarding lead by the normal route, immediately.

Youth workers need this in more detail than a general policy provides; the youth ministry safeguarding article sets out the specifics.

Records, review and accountability

  • Keep a short register of approved tools and who authorised each one — a single shared document is enough.
  • Require a human reviewer named against any published material that began as AI output.
  • Record training: who has read the policy and when. Repeat it annually for anyone handling personal data.
  • Review the policy every twelve months, or sooner if a tool, an incident or the law changes.
  • Provide a no-blame route to report mistakes early. Most harm comes from concealment.

A one-page policy skeleton

  1. Purpose — why we are writing this, in two sentences.
  2. Scope — who and what is covered.
  3. Principles — truthfulness, care for people, confidentiality, human accountability.
  4. Permitted uses.
  5. Restricted uses and the approval route.
  6. Prohibited uses.
  7. Personal data rules and the link to the privacy notice.
  8. Safeguarding rules and the link to the safeguarding policy.
  9. Verification standard — references, quotations and statistics checked before use.
  10. Disclosure — when we tell the congregation that AI was involved.
  11. Training and register of approved tools.
  12. Owner, approval date and review date.

Where to go next

Module 14 of the programme, Data Protection, Governance & Copyright (UK), works through each of these clauses with worked examples and a drafting exercise. If you want the wider theological grounding first, start with AI for pastors.