Direct Line:

(240) 441-5259

Get your Technology Strategy Audit and secure your church's digital future. Get Started

Technology

The Church Leader's Guide to ChMS AI Governance

  • 18 Jun, 2026
  • 0 Comments
  • By Good Shepherd Insights
The Church Leader's Guide to ChMS AI Governance
The Church Leader's Guide to ChMS AI Governance

Most churches cannot answer one simple question right now: when their church management software vendor’s AI touches congregant data, what exactly is happening to that data? According to the Barna and Pushpay 2026 State of Church Technology report published March 2026, 83 percent of church leaders say data privacy is their top concern about AI, yet only 5 percent have a formal AI policy. The governance gap is not in the church’s intentions. It is in the vendor relationships no one has audited. This guide walks through what is happening inside the major ChMS platforms, what the law now requires, and the specific governance decisions church leaders need to make before the next renewal cycle.

Table of Contents

  • Why ChMS Vendor AI Is Now a Data Stewardship Question

  • What Just Happened: Planning Center, ChatGPT, and the Default Setting Problem

  • The Counter-Model: How ACST Built Ministry Platform AI Differently

  • How Each Major ChMS Vendor Currently Handles Congregant Data in AI

  • The Legal Layer: What the Amended COPPA Rule Now Requires

  • What the Denominations Are Saying, and What They Are Not Saying

  • Why the Cybersecurity Picture Makes This More Urgent

  • The Six Governance Decisions Every Church Leader Needs to Make This Year

  • The Pre-Renewal Audit: A Practical Walkthrough

  • Frequently Asked Questions

  • Key Takeaways

  • Sources and References

  • Where We Go From Here

Why ChMS Vendor AI Is Now a Data Stewardship Question

For most of the past decade, the conversation about church management software focused on features, pricing, and migration friction. We helped churches compare giving platforms, evaluate workflow automation, and avoid the common ChMS selection mistakes covered in our work on how to evaluate ChMS platforms. The vendor relationships were a procurement question. The data inside those vendors was operational background.

That picture has changed. ChMS vendors are now embedding AI features directly into the systems where congregant data lives. Some of those features query third-party large language models. Some surface giving history to AI assistants. Some route household profiles through external chat interfaces. Each one of those design decisions has data governance implications, and almost none of them are visible to the church leader who is using the software.

The 2026 Barna and Pushpay study tells us why this matters. When the report measured what church leaders worry about, data privacy came in first. 83 percent flagged it. The same study found that 64 percent of leaders say it is important for their church to have an established AI policy, and only 5 percent actually have one. The Exponential and AI NEXT 2025 survey published November 2025 reached a similar conclusion from a different angle: 91 percent of church leaders support AI use in ministry, 73 percent have no AI policy of any kind, and 60 percent are very concerned about AI voice cloning being used to defraud congregants. 25 percent say they have already seen voice cloning incidents affect their church community.

We have a category where leaders care deeply about data, want policy, and have not yet translated that concern into specific decisions about the vendor relationships where the data actually lives. That is the gap this guide tries to close.

Key Point: Church leaders’ concern about AI and data privacy is high, but very few churches have made explicit governance decisions about the AI features their existing vendors have already deployed. The governance work happens at the vendor relationship layer.

What Just Happened: Planning Center, ChatGPT, and the Default Setting Problem

On May 28, 2026, Planning Center announced that it is now available in the ChatGPT app store. Users can connect their Planning Center account to ChatGPT directly. Once connected, ChatGPT can search across the People module, which includes profiles, contact information, households, workflows, lists, and form submissions.

What makes this announcement unusual is what Planning Center said in the same document. In their own words: “By default, OpenAI will train their models based on your conversations unless you change your settings. Your conversations could include personal and private information from your Planning Center account.” Planning Center recommends that users disable the “Improve the model for everyone” option inside ChatGPT’s Data Controls settings.

We want to be careful here, because this is not a Planning Center problem in isolation. Planning Center built a useful integration on top of an open standard called the Model Context Protocol, the same protocol other ChMS vendors are now adopting. The issue is the default behavior on the ChatGPT side. By default, when a church administrator queries congregant data through this integration, the conversation, which can contain member profiles, household information, and form submissions, is available to be used in OpenAI’s model training pipeline. The protection requires every individual user to find the right setting and turn it off.

This is the kind of design pattern that looks fine at the feature demo and creates real exposure at the data stewardship layer. The default is the policy. If the church does not explicitly configure every user, the default is what governs the data.

This is also why we wrote our recent supporter on whether your ChMS vendor’s AI uses congregant data to train its models. That piece focused on the single question. This pillar is the broader framework: how to think about the design choices across every vendor, not just one.

Key Point: When a ChMS connects to a third-party AI like ChatGPT through an open protocol, the data governance is controlled by the third-party AI’s default settings, not by the ChMS vendor’s privacy posture. The default is the policy.

The Counter-Model: How ACST Built Ministry Platform AI Differently

Three weeks before Planning Center announced its ChatGPT integration, ACST released Ministry Platform AI on May 7, 2026. Ministry Platform AI is built on the same Model Context Protocol that Planning Center uses. The difference is in the data handling.

ACST’s CEO Joe Koehling described the design intent this way in the announcement: “We built Ministry Platform AI specifically for the realities of ministry, not by retrofitting a consumer AI tool for church use.” According to ACST, congregation data queried through Ministry Platform AI is retrieved live, securely returned, and not stored or used to train AI models. The product includes data response inspection, role-based permissions, audit trails, and table-level controls. ACST opened a Pioneer Program for the first 50 churches and says setup takes under 30 minutes. The company serves nearly 50,000 churches, dioceses, schools, and faith-based organizations.

We want to mark a careful boundary here. The ACST claim that data is not used to train AI models is a vendor statement, not an independently audited fact. The same is true for Pushpay’s similar claim that we discuss below. These claims may be entirely accurate, but they are self-reported, and a responsible church leader treats them as starting points for verification rather than ending points. We come back to verification in the pre-renewal audit section.

What the ACST launch makes visible is the design fork in the ChMS vendor landscape. Two vendors built integrations on the same open protocol, with two different defaults. One routes queries through a third-party consumer AI with model training enabled by default. The other built a church-specific integration with model training disabled by design. Church leaders need to know which fork their vendor took, because the answer changes what governance work is required at their end.

Key Point: Two ChMS vendors built on the same open AI protocol with opposite default behaviors. The vendor’s design choice determines whether data governance happens by default or has to be configured by the church.

How Each Major ChMS Vendor Currently Handles Congregant Data in AI

Based on the public statements, product launches, and changelogs from May 2025 through June 2026, here is what the current landscape looks like across the major ChMS platforms. We are reporting what each vendor has said publicly. We are also marking what is a vendor claim versus what is independently verified.

Pushpay and Church Community Builder. Pushpay launched AI People Search in December 2025 and AI features inside its Giving Insights tools. In their own explanation of AI ethics in ministry, Pushpay states that “church member data processed through Pushpay stays within Pushpay’s secure partner ecosystem. It is not used to train external foundation models.” The company says it has implemented a sequential validation process where AI responses go through safety, accuracy, and transparency checks before reaching the user, and that financial transactions are PCI-DSS certified. Pushpay also published a roadmap on June 16, 2026 outlining the upcoming Staq Transformation, including an AI Involvement Summary feature in August 2026 and a Staq Data Lake in September 2026 that consolidates church data for AI tools to run on top of. This is significant. As more data consolidates into the Staq Data Lake, the governance decisions made now will determine what is permitted to run on that data when the new features land.

Planning Center. ChatGPT store integration live as of May 28, 2026. By default, OpenAI trains models on conversations unless individual users disable the setting. Planning Center says it is working to expand the integration to cover more products beyond the People module.

ACST and Ministry Platform. Ministry Platform AI launched May 7, 2026 on the Model Context Protocol with vendor claims of no model training and built-in role-based permissions. Realm, ACST’s mid-to-large denominational ChMS, falls under the same corporate umbrella.

Subsplash. Trends AI launched in March 2026 as an internal analytics hub with 25-plus chart types and data import from external sources. According to the launch coverage, the product includes privacy and permission controls. Subsplash has not made an explicit public statement on model training of congregant data, so this falls in the category of “verify directly before renewal.”

Tithe.ly and Breeze. As of the research window for this guide, neither vendor has made a significant public AI feature announcement that meaningfully changes the data governance picture. That does not mean there is no AI inside their platforms. It means a church using either platform has fewer publicly stated AI capabilities to govern at this moment, and should still verify directly during their next renewal conversation.

The pattern across the landscape is that AI features are arriving fast, vendor statements are partial and self-reported, and the documentation churches need in order to make informed renewal decisions is uneven across vendors. That makes the verification work at the church level non-optional.

Key Point: Every major ChMS vendor is now shipping or roadmapping AI features, but the public documentation of how those features handle congregant data is uneven and largely self-reported. Verification at the church level is required.

The Legal Layer: What the Amended COPPA Rule Now Requires

There is a regulatory dimension to this that most church leaders have not yet processed. The Federal Trade Commission’s amended Children’s Online Privacy Protection Act rule took full effect April 22, 2026. According to the legal analysis published by Finnegan on May 15, 2026, the amended rule requires operators of online services that collect personal information from children under 13 to obtain separate parental consent before disclosing children’s personal information to third parties for any purpose not “integral to the service.”

The FTC’s commentary on the rule explicitly states that targeted advertising and AI model training fall squarely outside the definition of integral. In other words, a church-facing software platform that routes children’s program data through an AI system that trains on that data is no longer in a gray area. The amended rule makes it specifically non-integral. Penalties are up to $53,088 per violation.

Two further pieces of legal context matter. First, biometric identifiers are now treated as personal information under the amended COPPA rule. Second, several state privacy laws, including those in Colorado, Delaware, New Jersey, and Oregon, do not exempt nonprofits, which means religious nonprofits in those states do not have a categorical opt-out from the broader privacy regime. The European General Data Protection Regulation treats religious affiliation as special-category data under Article 9, which is relevant for any church with international members or a diaspora congregation.

We are not lawyers, and this is not legal advice. We are pointing out that the regulatory floor under church technology has shifted upward in 2026, and the shift is most pronounced in the exact zone where ChMS AI features now operate. As a Progressive Church Media analysis noted in April 2026, churches that operate children’s programs need to be especially careful about which platforms touch children’s data and what those platforms do with it.

Key Point: The amended COPPA rule, fully effective April 22, 2026, explicitly excludes AI model training from the “integral to service” exception. Church technology that routes children’s program data through training-enabled AI is now legally exposed in a way it was not 18 months ago.

What the Denominations Are Saying, and What They Are Not Saying

While vendors are rolling out AI features and the regulators are tightening the rules, denominations are publishing statements. In April 2026, Southern Baptist leaders convened at Lifeway headquarters in Brentwood, Tennessee, and released what is now called The Brentwood Statement on AI and Christian Ministry on June 8, 2026. The statement is built around seven themes including pursuing wisdom, championing human dignity, promoting truth, cultivating trust and integrity, protecting privacy, representing the Kingdom, and modeling faithful leadership.

The Southern Baptist Convention has been working in this space for some time. Its Ethics and Religious Liberty Commission published the first faith-based AI ethics statement in 2019, the convention passed the first denominational AI resolution in 2023, and the Brentwood Statement is the third major document in that arc.

In May 2026, the Tennessee-Western Kentucky Annual Conference of the United Methodist Church released formal AI guidelines that go further than a statement. The guidelines cover tool selection, data handling, transparency, and internal approval processes. They specifically recommend that confidentiality statements be updated to include AI data use disclosures and that policy review happen at least annually, tied to the budgeting process. The TWK document also says that “as tools evolve quickly, churches should avoid locking themselves into single-vendor solutions without due discernment.”

Our recent supporter on what the new wave of denominational AI statements means covers this terrain in more depth. The pattern across denominations is encouraging at the level of principle and uneven at the level of practical guidance. None of the major denominational documents tells a local church exactly which questions to ask Pushpay, Planning Center, ACST, or Subsplash during a renewal conversation. The principles are right. The vendor-level translation is still missing.

That gap is part of why we built this guide.

Key Point: Denominational AI statements are establishing principles and modeling good governance, but they do not yet translate into specific vendor-level questions. Local church leaders still have to do the vendor translation work themselves.

Why the Cybersecurity Picture Makes This More Urgent

If AI integration was the only thing changing in the church technology landscape, this would still be a serious governance question. The cybersecurity picture makes it more urgent.

In March 2026, Chapel Hill Presbyterian Church confirmed a data breach affecting approximately 1,000 individuals, according to UpGuard’s incident report. The breach itself occurred January 30, 2026. In July 2025, First Baptist Church of Hammond, Indiana was hit by the Rhysida ransomware group. Comparitech reported that the attackers demanded $594,000 and that 5,217 individuals had personal information including Social Security numbers, state identification, addresses, and health data compromised. In June 2026, CyberInsider reported that ShinyHunters claimed responsibility for taking 23 GB of data from Moody Bible Institute, including 46 million communication records, 2.2 million enrollment leads, and 108,000-plus biographical records. The systems implicated reportedly included Salesforce, PeopleSoft, and donor databases.

The APS Payroll State of Church Payroll Security 2026 report published June 8, 2026 cited industry data showing that cyberattacks against nonprofits increased 30 percent in 2024 and 241 percent from 2024 to 2025. The report says over 70 percent of churches have been targeted, with average remediation costs of $168 per breached record.

We covered the operational side of this in our earlier piece on the five types of cyberattacks confirmed to target churches. The connection to the AI question is direct. The data categories targeted in these breaches, including giving records, pastoral notes, household information, and member identifiers, are the same data categories that ChMS-connected AI features now query and route through external systems. Every additional integration is an additional surface. Every default-on setting is an additional risk. The cybersecurity baseline and the AI governance question are not separate problems.

Key Point: The data categories most exposed in 2025 and 2026 church breaches are the same categories ChMS AI features now route through. The governance question is not abstract. It is operational.

The Six Governance Decisions Every Church Leader Needs to Make This Year

Putting all of this together, there are six decisions a church leader needs to make explicitly, ideally before the next ChMS renewal cycle. We are presenting them as decisions because they are not optional and because the default outcome, if no decision is made, is whatever the vendor and the third parties choose for you.

Decision one: What categories of congregant data are we willing to allow vendor AI to access? A church may decide that AI may query attendance and event registration data but not pastoral notes. Another church may permit AI to surface giving history to staff with appropriate roles but not to any external chat interface. The categories matter and they should be written down.

Decision two: Are we willing to use vendor AI features that route data through third-party large language models with default training enabled? This is the Planning Center plus ChatGPT question stated cleanly. The answer might be yes with constraints, no, or yes only after every user has confirmed the opt-out. Whatever the answer is, it needs to be a decision, not a default.

Decision three: Who in the church is authorized to enable, configure, or query vendor AI features? AI features inside ChMS platforms are typically permission-gated, but the permission decisions are often made by an administrator without explicit leadership input. Naming who is authorized is governance work.

Decision four: What disclosure are we making to our congregation about vendor AI use of their data? The Lausanne Movement’s analysis on governing AI in God’s house published October 2025 argues that meaningful consent requires “clear disclosure of data collection practices, plain-language explanations, meaningful consent processes, and regular transparent reporting.” Most churches have none of this in place yet. The decision to add it is a decision.

Decision five: How often are we reviewing this? The TWK United Methodist guidelines recommend at least annually, tied to the budgeting process. We agree with that cadence. Annual review at budget time forces the decision to be made in the open with the people who control the contract dollars.

Decision six: What is our exit path? This is the question every church leader hates and every church leader needs. If a vendor changes its data handling in a way the church cannot accept, what is the practical path to migrate? We covered the operational side of this in our earlier work on what ChMS migration actually involves. The point in the governance context is simpler. If there is no exit path, there is no real governance, because the vendor has all the leverage.

Key Point: The six governance decisions are not optional. The default outcome, when no decision is made, is whatever the vendor and the third parties choose for you.

The Pre-Renewal Audit: A Practical Walkthrough

The decisions in the previous section become real when they meet a renewal date. Here is the audit we recommend running at least 90 days before a ChMS renewal. The framework below complements the five-question framework we shared in what to ask your ChMS vendor about AI before you renew, which goes deeper into the vendor conversation itself.

Step one: Inventory every AI feature currently active in the platform. Not features you remember enabling. Features the platform has shipped, whether you flipped a switch or not. Vendor changelogs are the primary source. Look at the changelog for the last 12 months. Note every AI feature.

Step two: Map each AI feature to a data category. For each feature in step one, write down what congregant data the feature can access. This is where the vendor’s own documentation needs to be specific. If the documentation is not specific, that is the first audit finding to bring to the renewal conversation.

Step three: Request a Data Processing Agreement, not just a privacy policy. The privacy policy is the consumer-facing document. The Data Processing Agreement, sometimes called a DPA, is the operational contract that specifies what the vendor does with your data, where it is stored, who it is shared with, and what happens if either party exits the relationship. Ask for the current DPA in writing. If the vendor cannot produce one, that is a finding.

Step four: Verify the model training claims. Both Pushpay and ACST claim, in their public materials, that congregant data is not used to train external models. These are vendor claims. Ask in writing for confirmation in the DPA. Ask whether the vendor has had a third-party audit of its data handling. Ask whether the vendor uses any subprocessors, what those subprocessors do, and what their data handling looks like. The answers might be entirely satisfactory. The point is to get them on paper.

Step five: Test the opt-out and configuration controls. For any AI feature that requires a configuration to protect data, like the ChatGPT integration opt-out that Planning Center recommends, verify that the configuration actually works the way the documentation says it does. Have an administrator enable the feature in a test account with non-real data, run a query, and confirm the configuration behavior in practice.

Step six: Document the audit and the decisions. Whatever the church decides after running this audit becomes the basis of the AI policy that the Barna data says 64 percent of leaders know they need. The audit document becomes living evidence of the governance work and is also exactly the kind of artifact the COPPA and state privacy regulators will look for if there is ever a question. We discussed the policy document itself in our earlier piece on what an AI policy for church staff actually needs to include.

This audit takes time. It is not 30 minutes. For a church with three or four major vendors, two staff people, and an existing board governance rhythm, the realistic time is several weeks of cumulative work across the audit window. That is part of why this guide exists. The work is real. It is also necessary.

Key Point: The pre-renewal audit converts the six governance decisions into a documented, vendor-by-vendor conversation. The output is both a renewal decision and the foundation of the AI policy the church needs.

Frequently Asked Questions

Does Planning Center use congregant data to train AI models?

Planning Center’s own changelog announcement for its ChatGPT store integration states that “by default, OpenAI will train their models based on your conversations unless you change your settings” and that those conversations could include personal and private information from a Planning Center account. The data exposure is on the ChatGPT side, not the Planning Center side, but the route to that exposure is the integration Planning Center built. The protection requires individual user opt-out in ChatGPT’s Data Controls settings.

Does Pushpay use congregant data to train AI models?

According to Pushpay’s public statement on AI ethics, church member data processed through Pushpay stays within the Pushpay secure partner ecosystem and is not used to train external foundation models. This is a vendor claim, not an independently audited fact. Churches that want to verify the claim should request a Data Processing Agreement and ask Pushpay to confirm the data handling in writing.

Does ACST Ministry Platform AI use congregant data to train AI models?

ACST states in its Ministry Platform AI launch announcement that data queried through the platform is retrieved live, securely returned, and not stored or used to train AI models. This is also a vendor claim and should be verified the same way through a Data Processing Agreement.

What is the Model Context Protocol and why does it matter?

The Model Context Protocol, or MCP, is an open standard for connecting AI assistants to data sources. Both Planning Center and ACST built their AI integrations on MCP. The protocol itself is neutral. What matters is which AI assistant the protocol connects to and what that AI assistant does with the data. The same protocol can be used to enable training on conversations or to prevent it. The vendor’s design choice determines the outcome.

Are churches subject to COPPA?

In general, yes, for any church program that collects personal information online from children under 13. As the Finnegan analysis of the amended rule notes, the rule applies regardless of whether the operator is a for-profit, nonprofit, or religious organization, and several state privacy laws do not exempt nonprofits. The amended rule, effective April 22, 2026, explicitly excludes AI model training from the “integral to service” exception, with penalties up to $53,088 per violation.

What is the difference between a privacy policy and a Data Processing Agreement?

The privacy policy is the public document that describes the vendor’s overall approach to user privacy. The Data Processing Agreement is the contractual document, typically between the vendor and the customer organization, that specifies the operational details: what data is processed, where it is stored, which subprocessors handle it, and what happens at the end of the relationship. Privacy policies are easy to find. Data Processing Agreements often require an explicit request. Ask for both.

How often should a church review its ChMS AI governance decisions?

We recommend at least annually, tied to the budget cycle and renewal calendar. The Tennessee-Western Kentucky United Methodist guidelines recommend the same cadence. Vendor AI features are moving fast enough that a governance decision made in early 2025 is probably already out of date.

Where does denominational AI guidance fit into all of this?

Denominational documents like The Brentwood Statement provide a principled framework, but they do not yet translate into vendor-specific questions. They are useful for setting the values that drive the governance work. The vendor translation is the local church’s responsibility, and the pre-renewal audit in this guide is one way to do that translation.

Key Takeaways

  • Vendor AI is now a data stewardship question. ChMS platforms have shipped AI features that query, surface, and route congregant data through external systems, often with default settings that require explicit configuration to constrain. The governance work happens at the vendor relationship layer, not the feature layer.

  • The vendor landscape has a clear design fork. Planning Center’s ChatGPT store integration and ACST’s Ministry Platform AI use the same open Model Context Protocol with opposite default behaviors. One enables third-party model training on conversations by default. The other claims no training of congregant data by design. Church leaders need to know which fork their vendor took.

  • The legal floor has moved. The amended COPPA rule fully effective April 22, 2026 excludes AI model training from the “integral to service” exception, with penalties up to $53,088 per violation. Multiple state privacy laws do not exempt nonprofits. The regulatory environment now expects churches to make these decisions, not assume them.

  • The cybersecurity picture makes the AI question more urgent. Cyberattacks against nonprofits rose 241 percent from 2024 to 2025 according to APS Payroll, and recent breaches at Chapel Hill Presbyterian, First Baptist Hammond, and Moody Bible Institute show the same data categories that ChMS AI features now route through are actively being targeted.

  • Six governance decisions, made once, then reviewed annually. What data is in scope, what vendor AI is permitted, who is authorized, what disclosure to the congregation, what review cadence, and what exit path. The default outcome, when no decision is made, is whatever the vendor and the third parties choose for you.

  • The pre-renewal audit is the operational entry point. A 90-day audit before renewal, including a Data Processing Agreement request and configuration verification, converts the six decisions into a documented, vendor-by-vendor conversation. The output is both a renewal decision and the foundation of the AI policy the Barna data says 95 percent of churches still need.

  • Denominational principles plus local audits, not principles alone. Denominational AI statements are useful for setting values. They do not replace the vendor-by-vendor work each local church has to do to translate those values into specific governance decisions about specific contracts.

Sources and References

  1. Barna Group and Pushpay, “State of Church Technology 2026,” published March 18, 2026. https://www.barna.com/research/church-technology-mission/

  2. Planning Center, “Planning Center is now in the ChatGPT Store,” changelog, May 28, 2026. https://www.planningcenter.com/changelog/picolabs/new-planning-center-is-now-in-the-chatgpt-store

  3. ACST, “ACST Launches Ministry Platform AI, Bringing Secure, Ministry-Aware AI to Churches,” BusinessWire press release, May 7, 2026. https://www.businesswire.com/news/home/20260507886746/en/ACST-Launches-Ministry-Platform-AI-Bringing-Secure-Ministry-Aware-AI-to-Churches

  4. Pushpay, “Why AI Ethics Matter in Ministry,” company blog, December 10, 2025. https://pushpay.com/blog/why-ai-ethics-matter-in-ministry/

  5. Pushpay, “What to Expect From Pushpay’s Staq Transformation,” product blog, June 16, 2026. https://pushpay.com/blog/what-to-expect-from-pushpays-staq-transformation/

  6. Baptist Press, “Lifeway, SBC leaders respond to research findings with AI in Christian Ministry Statement,” June 8, 2026. https://www.baptistpress.com/resource-library/news/lifeway-sbc-leaders-respond-to-research-findings-with-ai-in-christian-ministry-statement/

  7. Exponential and AI NEXT, “AI in Churches 2025: 91 Percent Adoption Rate Reveals Dangerous Policy Gap,” November 24, 2025. https://exponential.org/ai-in-churches-2025-91-adoption-rate-reveals-dangerous-policy-gap/

  8. Finnegan, “COPPA’s Amended Rule Is Now in Full Effect: What Operators Need to Know,” legal analysis, May 15, 2026. https://www.finnegan.com/en/insights/articles/coppas-amended-rule-is-now-in-full-effect-what-operators-need-to-know.html

  9. Progressive Church Media, “Church AI Policy,” April 19, 2026. https://www.progressivechurchmedia.com/church-ai-policy/

  10. Lausanne Movement, “Governing AI in God’s House,” global analysis, October 27, 2025. https://lausanne.org/global-analysis/governing-ai-in-gods-house

  11. UpGuard, “Chapel Hill Church Data Breach 2026,” March 23, 2026. https://www.upguard.com/news/chapel-hill-church-data-breach-2026-03-24

  12. Comparitech, “Cybercriminals Give Indiana Megachurch 7 Days to Pay $600K Ransom After Data Breach,” August 2025. https://www.comparitech.com/news/cybercriminals-give-indiana-megachurch-7-days-to-pay-600k-ransom-after-data-breach/

  13. CyberInsider, “Moody Bible Institute Investigates Potential Data Breach Incident,” June 2026. https://cyberinsider.com/moody-bible-institute-investigates-potential-data-breach-incident/

  14. APS Payroll, “State of Church Payroll Security 2026,” June 8, 2026. https://apspayroll.com/insights/state-church-payroll-security-report/

  15. Tennessee-Western Kentucky United Methodist Conference, “TWK AI Guidelines,” May 2026. https://twkumc.org/wp-content/uploads/2026/05/TWK-AI-Guidelines_May-2026.pdf

Where We Go From Here

The honest summary of this guide is that the AI features inside your church management software are already touching congregant data, and the governance decisions about that data are being made by default settings unless your leadership makes them explicitly. The framework above, the six decisions and the pre-renewal audit, gives you a way to get in front of that.

The next question most church leaders face after reading something like this is whether to take this on internally or bring in someone who lives in this material every day.

If your ministry is working through ChMS AI governance, a renewal that is coming up, or a Data Processing Agreement that needs review before a decision lands on the board’s desk, we would be glad to think it through with you. We offer no-pressure consultations where we listen first, then share what we have learned helping ministries navigate the same questions. Schedule a consultation.

Tags:
  • Strategy
  • Technology
  • Leadership
Background Pattern

Get a Technology Strategy Audit

Wrong tools, underutilized software, vendor overcharges. Get a professional assessment of your current tech stack and a strategic roadmap forward.

Background Pattern
Good Shepherd Insights

Good Shepherd Insights

Fractional CTO

Fractional CTO providing strategic technology leadership for mid-sized churches.

Learn more about Good Shepherd Insights →