Community Financial Institutions and AI: Confidence Is Rising. Governance Must Catch Up.
By Nicole Volpe, Contributor at The Financial Brand
Simple Subscribe
Subscribe Now!
When it comes to the risks and opportunities of AI adoption, community banks and credit unions find themselves at a pivotal moment. Confidence in the technology is rising, but so is awareness that adopting it safely and effectively will require stronger governance, clearer policies, and a more deliberate approach.
The 2026 Banking Priorities Survey from CSI suggests an industry moving in two directions at once. On one hand, the share of community banking leaders concerned about the potential for AI in banking fell sharply, from 83% in 2024 to 50% in 2025, and 85% said institutions that adopt AI would gain a significant competitive advantage.
On the other hand, nearly 60% said they were highly or very concerned about AI-related governance; 68% expect AI use by fraudsters to significantly increase in the next five years; and respondents overall named AI-enhanced social engineering attacks their top cybersecurity concern at 27%, up 15 points from 2025.
Warnings about AI risk have only grown louder. Federal agencies, including the Government Accountability Office, the OCC, and the NCUA have all highlighted concerns ranging from lending bias and data quality to new cybersecurity threats. Early this month, Anthropic drew headlines when it said it would hold back the general release of its latest model, Mythos, because of its ability to identify software vulnerabilities at scale — a move that precipitated White House action to shore up critical infrastructure including by convening an urgent meeting of the country’s largest banks.
For community financial institutions, however, the most important development may have been the U.S. Treasury Department’s February release of the Financial Services AI Risk Management Framework, the first AI-focused resource designed specifically for the financial industry.
As the need to play both offense and defense gains urgency, the question for small financial institutions is how to strike the right balance.
To better understand what that framework means in practice, and what community banks and credit unions should do next, The Financial Brand spoke with Steve Sanders, Chief Risk Officer at CSI, whose background spans the risk, information security, and audit disciplines.
The Confidence-Defensibility Gap
Institutions can start by keeping the rapid changes of the past three years in proper perspective. Overconfidence and complacency are familiar challenges in cybersecurity, and AI is proving no different, Sanders said. And bank and credit union leaders should be careful not to place too much weight on their own growing sense of confidence.
Sanders suggests understanding this in terms of a “confidence-defensibility gap”: the difference between how confident an institution feels about AI and how well it can actually defend that confidence.
Here is a simple test: If an examiner or board member asks how your institution is governing AI use and controlling for its risks, can you answer with documented policies and procedures?
Part of the challenge is AI’s growing acceptance across the business world and its everyday use by employees in both personal and professional contexts. “Some of what we feel is just because we’ve gotten more comfortable with AI over time,” Sanders said. “It’s become normalized.”
That normalization has also helped fuel shadow AI, in which an organization’s individuals or teams use AI tools outside formal governance channels.
IBM’s 2025 Cost of a Data Breach report found that 63% of organizations lacked AI governance policies to manage AI or prevent shadow AI, while 97% of organizations that experienced an AI-related security incident and lacked proper AI access controls reported that incident involved shadow AI.
Finally, a Framework
Treasury’s new AI Risk Management Framework is the product of a public-private partnership that drew on input from more than 100 financial institutions. Adapted from the NIST AI Risk Management Framework, the new framework is organized around four functions — Govern, Map, Measure, and Manage — and includes 230 control objectives scaled to an institution’s stage of AI adoption, from early development through full production deployment.
Companion tools include an AI Adoption Stage Questionnaire, a Risk and Control Matrix, and an implementation guidebook.
For Sanders, the framework’s most important quality is that it was built to be used. Its scaled approach — providing different entry points to different institutions based on their level of AI maturity and institutional sophistication — is a key advantage, he said. It helps institutions “level set” by asking where they are in the AI journey, where they intend to go, and what controls they need to get there.
The new framework also scales better than the federal cybersecurity framework for banks, known as the Cybersecurity Assessment Tool (or CAT), which was released in 2015. In Sanders’ view, the CAT was too rigid to remain useful over time but the new framework is “more sustainable.”
The new Treasury framework is currently voluntary and creates no new legal obligations. It is, however, the first sector-specific federal AI governance tool for financial institutions, and Sanders, along with many compliance observers, expects it to shape examination standards going forward. Four additional resources are planned, covering identity, fraud, explainability, and data practices.
Getting Started
Assess your exposure to AI. “The best advice I can give to anybody is to know clearly where AI is being used in your institution right now and begin that mapping process today,” Sanders said. The Treasury framework, he said, provides a strong model to map usage.
As part of this, it’s critical to look beyond formal deployments, to evaluate third-party tools and platforms — in which AI might be embedded — and shadow AI projects, which can take hold quickly if your institution has not set clear expectations about what staff may and may not do with public models.
Smaller institutions that lack the internal resources to do that work on their own should look for outside help, Sanders said: “I would highly encourage them to find a third party that comes in and helps them to walk through a framework and determine where they’re at on that maturity scale.”
Adopt an operating discipline. Sanders said the Treasury framework is useful in part because it helps institutions ask better questions: how AI tools are being used, how misuse is documented, what controls are in place, and how vendors are being evaluated. Perhaps even more important, it gives banks a practical structure for board oversight and board communication.
Boards aren’t AI experts so it’s critical to “narrow the scope of what you take to the board to just the things that matter,” Sanders said. The framework provides the talking points and language that enables the institution’s leaders to focus board attention and to do so with confidence.
Keep your eye on the upside. With all of the concern about risk, it’s important to keep practical adoption firmly in your institution’s sights — another reason why it’s so important to communicate clearly on this topic with your board. “The board ultimately owns risk and risk cuts both ways,” Sanders said.
“If you aren’t using AI, you might as well get ready to sell because there’s going to come a point where you can’t keep up because your competitors have synergies you don’t have.”
CSI’s research found that institutions see AI’s highest-potential applications in cybersecurity, advanced data analytics, financial crimes prevention, customer service, customer engagement, and back-office efficiency. Sanders said smaller institutions in particular can “punch way above their weight” by applying AI to fraud detection and “data-heavy boring tasks” such as policy drafting, analysis, and operational review, provided those uses are tightly governed.
“Human in the loop” isn’t just a catchphrase, especially for community institutions. Notably, 78% of the survey’s respondents agree AI should augment rather than replace human judgment. This suggests not only that institutions are keeping their AI ambitions in proper perspective, but also that they’re leaving room for the personal interaction and local touch that distinguish community institutions from fintechs and larger banks.
Sanders pointed to cases in which bankers who knew their customers recognized unusual withdrawals or transfer requests and interrupted likely fraud attempts, an example of human judgment doing what automated systems alone cannot always do. “The debate over whether to use AI is over,” he said. “The question is, how do I do this right?”
