Back to Blog
AI and Ministry Security6 min read

Your Pastor’s Voice Is Already Public

Churches publish hours of their most trusted voice online every week. Here is what AI changes about the scams aimed at ministries, and the verification habits that still work.

Most of the AI conversation in ministry right now is about sermon prep and social media captions. That's fine, and it's not what this is about.

There's a quieter change worth understanding, and it has less to do with what AI can write than with what it can imitate.

Churches and Christian nonprofits are in an unusual position here. Not a worse one. Just an unusual one, and it's worth seeing clearly.

What Actually Changed

AI didn't invent any of these scams. The gift card request, the fake invoice, the email asking a donor to update their giving details — all of that predates any of this.

What changed is the friction.

Writing a convincing email in someone else's voice used to take effort, and it often showed. The odd phrasing, the grammar that didn't sit right, the greeting nobody on staff would actually use. Most of us were trained to look for exactly those tells.

Those tells are mostly gone now. The FBI's own guidance on this says generative AI lets criminals produce believable content at a scale they couldn't manage before, and specifically calls out audio clips that mimic a familiar voice.

For a sense of scale: in its 2025 annual report, the FBI's Internet Crime Complaint Center broke out AI-related complaints for the first time in the report's twenty-five year history — 22,364 complaints, about $893 million in reported losses. Worth reading that number carefully, though. It only counts cases where the victim recognized AI was involved and said so. It's a floor, not a measurement.

Why Churches Are an Unusual Case

Here's the part I think most ministries haven't sat with.

Voice cloning needs a sample of someone talking. For most organizations, getting a clean recording of the person everyone trusts takes some work.

Churches publish it. Every week, on purpose, in good audio.

The sermon livestream. The podcast archive going back four years. The YouTube channel. The staff introduction video on the website. If someone wanted a high-quality sample of your senior pastor speaking naturally for an hour, you have already done that work for them, and you did it for entirely good reasons.

I want to be careful here, because this is not an argument for taking your sermons offline. Publishing them is the point of publishing them.

It just means the one voice on staff that nobody questions is also the one voice that's easiest to reproduce. And a request that arrives in that voice tends to skip the part of someone's brain that would normally slow down.

The Requests That Should Always Slow Down

The useful move isn't learning to detect a fake voice. People are bad at that, and getting worse as the tools improve.

The useful move is deciding, ahead of time, which requests never move on a message alone — no matter whose voice or name is attached.

In most churches that short list looks something like this: moving money or changing where it goes, changing a vendor's or employee's payment details, resetting a password or adding someone to an account, and sending out anything containing member or giving data.

None of those should ever complete on the strength of a phone call, a text, or an email. Not because you distrust your pastor. Because the request might not be from your pastor.

The control isn't suspicion of people. It's a procedure that doesn't depend on recognizing a voice.

A Codeword Costs Nothing

The FBI's recommendation on this is refreshingly unglamorous. Create a secret word or phrase, agreed in advance, used to confirm identity when a request feels urgent.

It was written with families in mind, and it works just as well for a church staff. A word that four or five people know, that lives nowhere digital, and that gets asked for whenever money or access is involved.

The second recommendation is even simpler: hang up and call back on a number you already have. Not the number that called you, and not a number in the message. One you look up yourself.

Both of these are free. Neither requires new software, a consultant, or a line item. They mostly require deciding as a staff that using them isn't rude.

That last part is the actual obstacle, in my experience. Nobody wants to ask the person who hired them for a codeword. Which is exactly why it has to be a policy rather than a judgment call — so the person asking isn't being suspicious, they're following the rule everyone agreed to.

The Other Direction: What Your Staff Puts Into AI

There's a second AI risk that has nothing to do with attackers, and it's the one I'd actually look at first, because it's already happening.

Staff and volunteers are using these tools to get work done. Summarizing a long email thread. Cleaning up a newsletter. Rewriting a difficult message to a family. Making sense of a spreadsheet.

All reasonable. The question is what goes into the box.

A counseling note pasted in to help word a follow-up. A membership export uploaded so it can be summarized. Giving records, a background check result, a list of families in a hard season. Once that's submitted to a consumer AI account, it has left your control, and depending on the account it may be retained or used to improve the service.

Nobody does this maliciously. They do it because it's genuinely useful and because no one ever told them where the line was.

So tell them. One page is enough: here are the tools we use, here's the account to use them under, and here's what never goes in — anything about a specific person's health, finances, family situation, or counseling, and anything exported from the church management system.

Where to Start This Week

None of this needs a project plan. Four things, and the first two take one meeting:

Agree the short list of requests that require verification, and write it down where staff can see it. Pick a codeword and a callback rule, and tell everyone that using them is expected rather than insulting.

Then write the one-page AI note about what can and can't go into a chatbot, and ask your bookkeeper or treasurer how a change to payment details is currently confirmed. That last question tends to be revealing.

What I like about this set is that none of it depends on spotting anything. It doesn't ask a receptionist to detect a synthetic voice or a volunteer to catch a well-written phishing email. It just makes the outcome not depend on catching it.

Which is roughly where security works best anyway — not in noticing the one bad message, but in making sure noticing wasn't the only thing standing between you and a bad afternoon.

Sources

Need Clarity on Your Church's Security?

An assessment gets everything into one document you can hand to your board.

Schedule a Security Conversation