Corp Moves

Banks struggle with shadow AI risks

By Bunga Sulistio August 5, 2026
Banks struggle with shadow AI risks - shadow ai
Banks struggle with shadow AI risks

Financial institutions are grappling with unauthorized artificial‑intelligence tools to handle sensitive customer data, a practice that has raised alarm after a recent breach at a Pennsylvania‑based bank.

Unauthorized tool exposes personal data

In May 2026, an employee at CB Financial Services, the parent of Community Bank, uploaded a spreadsheet containing customer names, Social Security numbers and dates of birth into an AI application that the firm had not approved.

The employee was preparing a presentation and chose to use a personal device and a personal account rather than the bank’s sanctioned AI platform.

The breach was detected quickly enough for the firm to delete the file before the vendor could incorporate the data into its system.

This incident shows that having an approved tool does not guarantee its use.

Bank responses focus on policy, but experts warn they miss the point

Most banks and credit unions react to such incidents by tightening acceptable‑use policies, increasing monitoring, and issuing stricter language to employees.

According to Corey Gross, vice president and head of Data & AI at Q2 Holdings, this approach addresses the symptom rather than the cause.

Gross notes that when employees bypass a sanctioned tool, they’re telling leadership teams that the approved option isn’t getting the job done.

He argues that institutions often purchase AI solutions without fully mapping the workflows those tools are meant to support, resulting in a mismatch between the technology and the real‑world tasks employees need to perform.

Gross adds that the issue is rarely a matter of governance or compliance, but rather a deeper problem: the design of work processes precedes the rollout of AI, not the other way around.

Related: The Science Behind the Sparkle: Understanding Lab Grown Diamonds in London

This perspective suggests that banks should prioritize core system modernization and workflow redesign before implementing new AI capabilities.

Employees may find that approved tools lack certain features, have cumbersome interfaces, or fail to integrate with existing systems, leading them to seek workarounds.

When the tools do not align with daily operational demands, staff are likely to turn to external applications that appear more convenient, even at the risk of exposing confidential data.

One practical step for banks is to conduct thorough assessments of how AI tools fit into specific job functions.

This includes gathering feedback from front‑line staff, testing prototypes in real environments, and iterating on the solution before full deployment.

By addressing usability and integration early, institutions can reduce the incentive for unauthorized AI use.

Stricter policies might deter some casual misuse, but they do not resolve the underlying friction that drives employees to seek alternatives.

A balanced approach that combines clear guidelines with user‑centered design could prove more effective in safeguarding data.

Banks that fail to align AI tools with actual workflows risk repeated incidents, regulatory scrutiny, and potential fines.

Conversely, those that invest in redesigning processes and ensuring tool relevance may achieve smoother adoption and stronger data protection.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 CBS News. All rights reserved.