← Field notes
AIMinistryNonprofitsPolicy

AI Policy Template for Churches and Nonprofits (Free, Board-Ready)

Karl Kenneth AlibuasSeptember 15, 2026 · 7 min read

Most churches and nonprofits don't have an AI policy. They have staff and volunteers using AI tools anyway, each with their own private sense of what's appropriate. That is worse than a short policy, because the person most likely to paste something sensitive into a free chatbot is the one who never had the conversation with you.

This post is an AI policy template for churches and nonprofits you can adapt in an afternoon. It's the one-page version, with a sample clause for every section, written to be read by an elder board or a nonprofit board rather than by a lawyer. If you'd rather start from the document itself, the free download is here.

Why one page beats no page

A policy that exists only in the pastor's head protects nobody. A 20-page policy that nobody reads protects nobody either. What works is a single page that answers the four questions staff actually have: which tools may I use, what may I put in them, who checks the output, and who do I ask when I'm not sure.

The template below is built around those questions. Everything else is detail you can add later, once the first version has been in use for 90 days and you've learned where it's unclear.

The eight sections every church AI policy and nonprofit AI policy needs

Each section has a short explanation and a sample clause. Copy the clause, change the names, and move on.

1. Purpose and scope

Say what the policy is for and who it covers. Cover volunteers explicitly; in most churches the person doing the bulletin, and in many nonprofits the person doing intake, is not on payroll.

This policy governs the use of AI tools, including chatbots, writing assistants, transcription, and image or voice generation, by all staff, volunteers, contractors, and leaders acting on behalf of [Organization]. Its purpose is to let us use these tools well without compromising the trust of the people we serve.

2. Approved tools

List the tools you've actually evaluated, the tier the organization is on, and who approves additions. Vagueness here is how a personal free account becomes the de facto organizational tool.

Approved tools are listed in Appendix A with the account tier we use for each. Staff may not enter organizational information into an AI tool that is not on the list. Requests to add a tool go to [Owner], who confirms the tool's current data terms before approving it.

3. Data classification

This is the section that matters most, because it's the one most likely to be broken tonight. Use three tiers and give examples people will recognize.

Green, any approved tool: sermon outlines before personal study, generic bulletin and event copy, public program descriptions, general research questions, published reports with no individual data.

Yellow, enterprise-grade tools only, with review: de-identified attendance or program trends, budget summaries with no names, scheduling, first drafts of communications that don't name individuals, translations of internal handbooks.

Red, no AI tool ever: prayer requests, counseling notes, beneficiary case notes, member or client records, giving or donor data tied to a name, safeguarding and background-check records, HR and medical matters, anything shared with "please don't tell anyone" attached.

No sensitive pastoral or client information — counseling matters, member or beneficiary records, private prayer requests, or giving and donor data — is ever entered into a third-party AI tool, free or paid, without a signed enterprise agreement confirming the data is not used for model training and is handled under appropriate retention controls. If a name, a situation, and a struggle appear in the same sentence, it does not go into an AI tool.

4. Human review rules

AI drafts; people decide. State it plainly, and name the places where AI never carries the first draft at all.

Every AI-assisted draft, summary, or translation is reviewed by an accountable person before it reaches a member, client, donor, funder, or the public. AI never produces the first draft of pastoral counsel, a response to a person in crisis, or a communication about an individual's private situation.

5. Disclosure

Decide in advance when you tell people that AI was involved. The bar is simple: if the use touches something personal, or if someone would feel misled to learn about it later, disclose it.

We disclose meaningful AI use to leadership. We disclose it to members, clients, or donors when AI has been used in a way that touches their personal information or that they could reasonably feel misled by. Sermons and teaching content are the responsibility of the person delivering them, and AI assistance in preparation does not change that.

6. Ownership and review date

A policy with no owner is a poster. Name one person and put a date on it.

[Owner, title] is responsible for this policy, for maintaining the approved tools list, and for answering questions about cases this policy does not clearly cover. This policy will be reviewed 90 days after adoption and annually after that.

7. Training

Nobody follows a policy they've never been walked through. Thirty minutes is enough for the first version.

All staff and regular volunteers who use AI tools on behalf of [Organization] will complete a short orientation on this policy within 30 days of adoption, and new staff and volunteers will complete it during onboarding. The orientation covers the approved tools, the three data tiers, and the review rules.

8. Incident handling

Someone will paste the wrong thing. Make it safe to say so, and be clear about what happens next.

If sensitive information is entered into an AI tool contrary to this policy, the person who discovers it reports it to [Owner] the same day. We treat prompt reporting as the right thing to do, not as a disciplinary matter. [Owner] assesses what was shared, deletes the conversation where the tool allows it, and decides with leadership whether the affected person should be informed.

The red lines most churches land on

Every congregation I've worked with defines its own red lines, and they converge on the same short list. AI never replaces:

  • Pastoral counseling. A person in a hard moment gets their pastor, not a paraphrased chatbot.
  • Prayer. Nobody needs an AI to pray for them, and nobody's prayer request belongs in a tool's logs.
  • Preaching. AI may help with research and structure; the sermon is the preacher's, and the preacher owns every claim in it, which means checking every citation. I learned that one the hard way when an AI invented a scholar for me.

Nonprofits usually add one more: decisions about an individual's eligibility, care, or case are made by a person, with AI at most summarizing material the person then reads in full.

Write your red lines into the policy as a named list. They are the part your board will remember.

A four-step rollout

  1. Draft. Take the template, fill in the tools you actually use, your owner, and your red lines. One afternoon.
  2. Elder or board review. Bring it to the next meeting with the data classification section flagged. That's the part they'll have questions about, and the questions are good ones.
  3. Staff and volunteer training. One 30-minute session. Walk through the three tiers with real examples from your own week. Print the red list and put it where the shared laptop lives.
  4. 90-day review. Ask two questions: what came up that the policy didn't cover, and what did people find unclear? Fix those, and set the next review for a year out.

Get the template

The full one-page policy, with all eight sections and the sample clauses above ready to edit, is free: download the church and nonprofit AI policy template.

If you'd like help auditing what your staff are already pasting into AI tools, adapting the policy to your denomination or funder requirements, and getting it approved by your board this month, that's the work I do through the AI guidance track. The policy is the floor. The audit is how you find out what's already in the building.

Karl Kenneth Alibuas

Written by

Karl Kenneth Alibuas

Senior full-stack engineer shaped by ministry. Eight years in ministry, now building AI agents and teaching ministries to navigate AI. Creator of OpenLumin and AI Fluency Ministry.

[ Newsletter ]

Enjoyed this?

Field notes on AI, ministry, and building with purpose. No noise.