Governing AI Faithfully
Building an AI Policy for Churches and Mission Organizations
~3 min read
By 2026, Christian organizations were publishing real AI policies. They did not all draw the same boundaries.
That is healthy evidence of prudential governance. The Church of God of Prophecy permits a range of assistive uses while setting controls around confidentiality, verification, public translation, theological responsibility, and approved providers.1
The Missouri Baptist Convention takes a more restrictive authorial approach in several areas, permitting limited assistance while retaining stronger human-authorship boundaries for sermons, Bible lessons, and journalism. Faithful organizations can share principles and reach different operational conclusions.
Policy Starts With Real Work
• A policy written for imaginary use will fail.
• Ask what staff already do.
• Which systems?
• Which accounts?
• Which data?
• Which public outputs?
Shadow AI often emerges when policy denies obvious useful workflows without providing safe alternatives.
A minimal policy should answer: 1. Which low-risk uses are permitted?
1. Which uses require review?
2. Which require specialist or leadership approval?
3. Which are prohibited?
4. Which tools and accounts are approved?
5. Which data classes apply?
6. Which verification level is required?
7. When should AI involvement be disclosed?
8. How are incidents reported?
9. Who owns and updates the policy? A small church may need only a few pages.
Table 32.1. Minimum AI Policy Components
| Component | Minimum question |
|---|---|
| Allowed uses | Which tasks are permitted, restricted, or prohibited? |
| Approved tools | Which providers/accounts may staff use? |
| Data | What classifications may enter which systems? |
| Verification | Who checks consequential outputs and how? |
| Disclosure | When must AI assistance be disclosed? |
| Incidents | How are failures, leaks, or harmful outputs reported? |
| Ownership | Who owns workflows, accounts, prompts, and outputs? |
Tools, Accounts, and Data Boundaries
Provider approval should consider account terms, data handling, retention, administrative controls, access, and organizational need.
An approved provider does not make every data type appropriate to upload. Organizations should distinguish public consumer accounts from managed organizational accounts where provider controls differ.
Staff should know which account is approved for internal information and which data categories remain prohibited even there.
AI procurement should involve more than price and benchmark capability. Review data terms, administrative controls, export, audit logs, regional availability, accessibility, contractual commitments, and provider stability. The strongest model may not be the best organizational system.
Verification and Incident Response
• V0 — ordinary judgment.
• V1 — surface review.
• V2 — factual verification.
• V3 — qualified domain review.
• V4 — independent or dual review.
• V5 — formal approval.
• Required verification depends on consequence, not how convincing the output sounds.
A generated citation slips through. A confidential file is uploaded. A synthetic image is published unclearly. An automated message goes to the wrong recipient.
Workers need a simple route to report incidents without fear that every mistake becomes disciplinary evidence. Governance improves when failures become visible.
Policy as a Living Practice
A perfect document cannot compensate for leadership that rewards speed over truth or hides errors.
• Staff should be able to say:
• This workflow is unsafe
• We need review
• The system made a mistake
• We should not automate this.
• Governance is a process, not a PDF.
The contrast among Christian policies should reassure leaders who fear one perfect AI policy exists.
An organization can reasonably choose stronger authorship boundaries because authenticity is central to its public identity. Another can permit extensive drafting under review.
The common questions matter more than identical answers. A policy without training becomes a document employees violate unknowingly. Short scenario-based training is more useful than long abstract warnings: Can I upload this meeting note? May the agent send this? What review does this translation need?
Policy should have an owner and scheduled review. Rapid AI change does not require rewriting every month, but major shifts in agentic capability, law, or provider terms may require targeted updates. Governance should evolve without becoming permanently provisional.
Footnotes
-
Church of God of Prophecy International Offices, Artificial Intelligence (AI) Policy for the International Offices ↩