Illustration of an AI voice cloning scam targeting a church member with a fake pastor phone call.

AI and the Future Church: 3 Ways to Stop AI Voice Cloning Scams

July 09, 20269 min read

by Erin Ward, ChurchReady Co-Founder

Trust is the real currency inside a church. It matters more than the budget, more than the building, more than the size of the crowd on a Sunday morning. When someone in your congregation gets a call from a number they don't recognize and hears a voice they do, they don't stop to run it through a verification process. They act, because for their entire life in that congregation, a familiar voice has always been proof enough.

AI and the future church are now colliding at exactly that point of trust, and the collision is moving faster than most churches have built a defense for. The 2026 State of AI in the Church Survey, reported through ChurchTechToday.com, found that six in ten church leaders are already concerned about someone using an AI-cloned voice to defraud a member of their congregation. One in four say it has already happened somewhere in their community. This risk has already arrived, wearing the voice of someone the congregation loves.

AI and the Future Church: How an AI Voice Cloning Scam Reaches Your Congregation

Here's the question worth asking before anything else: what would it actually take for someone to sound exactly like your pastor on a phone call?

Not much. A few seconds of audio, pulled from a sermon recording, a livestream, or a podcast clip, is enough for current voice-cloning tools to produce a convincing match. The scammer doesn't need your pastor's real voice. They need a sample of it, and most churches have posted hundreds of hours of that sample online for good reasons: to reach people, to archive teaching, to serve the homebound. The same audio that extends a church's ministry is the raw material for what people are now calling a pastor deepfake scam.

Carey Nieuwhof names this shift clearly in his book AI and the Future Church: the tools reshaping how churches teach and communicate are the same tools now capable of standing in for the people who lead them. That reality makes a verification habit that doesn't depend on how convincing a voice sounds essential for every church, whether or not it publishes sermons online.

This sits inside a larger question we've mapped out at length in AI and the Future Church: What Every Pastor Needs to Know, the question of whether the trust your congregation places in your church, financial, relational, and spiritual, is protected by something more durable than good intentions. An AI fraud impersonation church leaders now have to plan for is one specific, urgent expression of that larger question. Here are three concrete ways to answer it.

How to Verify a Request Is Really From Your Church Leadership

Paul wrote to the Corinthian church that every matter should be established by the testimony of two or three witnesses. He was writing about resolving disputes and confirming the truth of a claim inside the community, not about twenty-first century fraud. But the underlying principle transfers directly. A single, uncorroborated claim, even one that sounds exactly right, isn't enough to act on when something significant is at stake.

A verification standard gives your staff and your congregation a way to confirm that a request for money, sensitive information, or urgent action actually came from who it claims to have come from, independent of how the voice or the message sounds.

Voice cloning defeats the test most people have relied on their whole lives: does this sound like the person I know? Once that test stops working, the church needs a second, independent channel of confirmation. That's the two-or-three-witnesses principle in practical form.

A workable standard is simple enough that staff will actually use it under pressure. For any request involving money, gift cards, wire transfers, or sensitive personal or financial information, the person receiving the request calls back on a number already on file, not a number provided in the message itself, before taking any action. For requests coming through email or text, a second staff member confirms verbally before anything moves. Write this down as an actual policy, not an assumption everyone shares. Circulate it to staff, elders, and anyone with access to church funds or member data.

Don't build a verification standard so cumbersome that people route around it. Don't treat urgency as proof; a scammer creates urgency on purpose, because urgency is what makes people skip verification. And don't limit the policy to the finance team. The person a scammer is most likely to target is whoever is easiest to reach and most inclined to help quickly, which in most churches is a volunteer or an administrative assistant, not the senior pastor.

If your church hasn't sat down and asked whether a verification standard like this exists in writing anywhere, that's usually the first gap the Church Readiness Assessment surfaces. It takes about ten minutes and shows you exactly where your church stands on this, and on the broader questions of readiness sitting alongside it. You can take it at the Church Readiness Assessment.

What Your Church Will Never Ask for by Phone or Text

A verification policy protects the institution. It does almost nothing for the widow who answers her phone at home, hears a voice she trusts, and is asked to buy gift cards before she has any reason to call anyone back. She was never part of the staff meeting where the policy got written. If the only place that policy lives is inside a binder in the church office, it hasn't actually protected the person most likely to be targeted.

Congregants need to hear, directly and repeatedly, what your church will and will not ask them for by phone or text, so an unusual request registers as unusual the moment it arrives.

Scammers are counting on the fact that most congregants have never heard their church say, out loud, "we will never ask you for this." Silence on the subject reads as neutral. It isn't. Silence leaves the door open for a scammer's voice to be the first voice a congregant hears making that claim.

Say it plainly, in language your congregation will actually remember. A bulletin insert or a platform announcement might read: "Our church will never call or text you asking for gift cards, wire transfers, or immediate payment of any kind. If you receive a request like this claiming to be from our staff, hang up and call the church office directly." New-member materials can carry the same line, framed as part of how the church cares for its people, not as an alarm. Repeat it at least once a year, the same way you'd repeat any safety announcement, because a message given once is a message most people forget by the time they need it.

Don't bury this in fine print or a single email most people won't read. Don't assume that because staff know the policy, the congregation does too; those are two different audiences carrying two different levels of exposure. And don't frame the message around fear. Frame it as the same kind of practical care your church already offers in a dozen other forms.

Protecting Your Church's Name Online From Impersonation

A verification standard protects your church from the inside. Reputation monitoring protects your church's name from being used against people who have never set foot in your building.

Church-security and nonprofit reputation-management research tracking ministry impersonation has found a pattern worth taking seriously: small and mid-size churches are targeted more often than large, well-known ones. A message that appears to come from a pastor whose name most people outside the congregation wouldn't recognize reads as more plausible to a stranger than one impersonating a national figure. Your church doesn't need a large public profile to become someone's raw material. This is the quieter side of church AI safety, the side that has nothing to do with what happens inside your building.

Monitoring doesn't require a security budget most churches don't have. It requires a short, recurring habit. Set up a free alert for your pastor's name and your church's name, so new mentions surface as they appear. Check the social platforms your church actually uses for accounts impersonating your staff or your church page, and report them the moment you find them. Then check the platforms your church doesn't use at all; a fake account on a platform your church has never touched is often the easiest one for a scammer to run undetected, because no one on staff is watching it. Assign this to a real person on staff or a trusted volunteer, with a specific cadence. Monthly is reasonable for most congregations, rather than leaving it as a task everyone assumes someone else is handling.

Don't assume a small platform footprint means low risk; it's often the opposite. Don't wait for a congregant to report an impersonation before you look for one yourself. And don't treat this as a one-time setup. Impersonation accounts get created after the initial check, not only before it.

Verification, congregant communication, and reputation monitoring work together. A church with one of the three and not the other two still has a real gap. Most churches we talk with have none of the three written down anywhere.

Character and integrity are what make any of this worth building in the first place. A pastor who would never dream of actually asking a widow for gift cards over the phone isn't the problem this post is solving. Good character in a pastor's own heart doesn't verify anything for the congregant on the other end of an AI voice cloning pastor call, because the voice on that call was never actually the pastor's character speaking. It was a convincing forgery of the sound that character usually comes wrapped in.

That's the gap these three practices exist to close: whether your systems can prove what your leadership already is, when it matters most. Building a verification standard, communicating it plainly to your congregation, and watching for impersonation of your church's name are three specific, buildable answers to a question every church is already exposed to, whether or not anyone has named it out loud yet.

Start with whichever of the three your church doesn't currently have in writing anywhere. Then take the Church Readiness Assessment to see where the other gaps are sitting, so you're building from a complete picture instead of guessing.

Church Readiness Assessment promotional graphic showing a pastor using a smartphone to assess church AI readiness, leadership, and ministry planning.


Erin L. Ward

Erin L. Ward

I help pastors build the resilience their churches will need as AI reshapes church giving and the faith and lives of believers in the pews. Erin Ward Co-founder of ChurchReady.

Youtube logo icon
LinkedIn logo icon
Back to Blog