PART 1 OF 5
The Peace That Surpasses Understanding — Even With AI
A practical guide for pastors and church admins who don't need to master the technology to steward it well.
Most AI-and-church content answers one question: should we use AI? This piece focuses on a more operational question instead: what exactly do I check before I turn this on? — the same instinct a legal or governance function would bring to any new tool at work, applied here to a church setting.
This matters because churches are already using AI — quietly, tool by tool, often without anyone deciding to. A worship leader tries an AI setlist tool. A volunteer coordinator turns on a “smart list” feature in the church management system. A staff member starts using ChatGPT to draft newsletters. None of this went through a board vote. All of it touches your congregation's data in some way.
Recent survey data on AI in the church backs this up: a large majority of church leaders now report using AI weekly or monthly, but only a small fraction of churches have any formal AI policy in place. The tools are already here. The governance isn't.
A real example, not a hypothetical.
Church management platforms are beginning to ship AI features that connect directly to your database — letting staff ask plain-English questions like “who's been stuck in our visitor follow-up process for two weeks?” That's genuinely useful. It's also a new data pathway, and at least one major provider has been transparent that, by default, some AI assistants may use those conversations to train their own models unless a setting is changed — meaning fragments of your congregation's information could, in theory, become part of a third party's training data.
Five questions, not five hundred.
A formal AI policy is genuinely the best practice here, and worth building toward. But a comprehensive policy nobody reads is worth less than a short list of questions people actually use — so if a 40-page manual and an AI task force feel out of reach right now, start with a short list of questions any staff member or volunteer can ask before adopting a new tool, and one person accountable for asking them.
- 1. Where does this data go, and does the vendor train on it by default? Look for a setting to disable model training, and turn it off unless you've decided otherwise on purpose.
- 2. Who needs to catch and fix it if the AI gets something wrong? A specific staff member who reviews AI output before it reaches pastoral care notes, safeguarding records, counseling, or doctrine.
- 3. How long is sensitive data kept, and can it be deleted? “Retention policy” sounds abstract until it governs how long a prayer request sits on someone else's servers.
- 4. Who pays if the AI gets something wrong? Ask the vendor plainly, and call your insurance broker to ask whether your policy covers anything AI-related.
- 5. Who is the one person responsible for approving new AI tools going forward? Not a committee. One name. Diffuse responsibility is how gaps happen.
The fine print: a four-step gut check for any AI tool.
Strip away the church-specific parts above, and there's a simpler framework underneath — the same instinct a legal or compliance function brings to evaluating any AI tool, at any organization. Run every tool through these four questions:
What goes in? What data are you feeding it, where did that data come from, and do you actually have the right to put it there?
What comes out? Raw data, a derivative analysis, a summary, a rearrangement of existing content? Is it in a usable format, and does it carry someone else's copyright or license terms?
What can you do with it? Are there IP, copyright, or confidentiality restrictions on how you can use what came out — restrictions that mean you shouldn't use it for this purpose at all?
Who's the human in the loop? Not just “someone reviews it” — someone who knows the subject well enough to catch a wrong answer, not just glance and say “looks fine.”
One more thing: this is a young, fast-moving industry full of startups. Before building a workflow around a specific tool, ask what happens if the vendor isn't around in six months — is there a notice commitment, can you export your data, and are you prepared to rebuild if you have to replace them?
The simplest shortcut: pay for it, and turn off training.
If reading a privacy policy or asking a vendor pointed questions still feels out of reach, there's one habit that does most of the work for you: if you aren't paying for the product, then YOU are the product. Free AI tools often make their money by using your conversations and data to improve their own models — a very different arrangement than a paid tier, where the vendor's business model is your subscription, not your data.
It's worth saying plainly: if you already pay $10–20 a month for Netflix and another $10–15 for Spotify without a second thought, a paid AI subscription in that same range isn't a splurge — it's the same category of expense, and it typically buys meaningfully better terms, stronger privacy protections, and a training-data toggle the free version doesn't offer.
So a simple, sleep-well-at-night rule of thumb: default to paid tiers for anything touching real church or congregant information, and turn off model training the day you sign up. It won't answer every question above, but it closes the biggest gap with the least effort.
Turning this into an actual policy.
A workable church AI policy fits on one page and does four things:
- 1. Names who decides. One staff member owns AI tool approval. Everyone knows who that is.
- 2. Sets a default posture for sensitive data. “No AI tool touches pastoral care, counseling, or safeguarding records without explicit review.”
- 3. Requires the five questions above for anything new. A five-minute habit before a new tool goes live.
- 4. Defaults to paid tiers with training disabled. The standing rule, not a case-by-case call.
That's it. It's not comprehensive. It's not exhaustive. But it's the difference between hoping you're being careful and knowing you've done the basic due diligence — which is precisely where earned peace lives instead of anxious uncertainty.
Permissions matter more than they used to.
Before AI, information being hard to find was its own kind of quiet protection. A staff member might technically have database access to years of prayer requests or pastoral notes, but actually digging through them took real effort — so in practice, most people only ever saw what they specifically needed. AI removes that friction entirely, and that changes the risk.
If prayer request records, counseling notes, or pastoral care history live anywhere an AI tool can search, a completely innocent request — “help me put together a prayer list for the board meeting” — can surface exactly the specific, sensitive detail behind someone's request, to someone who was never supposed to see it. This isn't a hypothetical edge case. It's the direct, predictable result of making previously buried information instantly searchable.
This matters most in exactly the two places you'd expect: pastoral care records and youth ministry. Before connecting any AI tool to a database that touches either, ask a simple question: does this tool respect the same access permissions the underlying system already has, or does it search across everything regardless of who's asking? If you don't know the answer, treat it as “everyone can see everything” until you've confirmed otherwise.
The peace that isn't naive.
Paul's peace “which transcends all understanding” wasn't a peace that came from having no questions. It came from bringing the questions to God rather than carrying them alone, and then resting in what he'd faithfully done with what he could control.
Pastors and church admins don't need to become AI experts to steward this well. They need five questions, one accountable person, and a simple to follow policy that they can actually implement.