Somewhere in your credit union today, a member service rep pasted a member's complaint email into a free AI chatbot to draft a nicer reply. A lending analyst uploaded a delinquency spreadsheet and asked for a trend summary. Someone in marketing fed it a segment of the member newsletter list to "personalize the tone." An admin pasted an error log full of internal hostnames to ask what it meant.
None of them were being careless in their own eyes. All of them were being helpful, faster, better at their jobs. There was no project, no vendor review, no board discussion, no line item. Your institution adopted AI one browser tab at a time, and if you are the CTO, there is a fair chance nobody told you.
The perimeter is intact. The data left anyway.
Credit unions run some of the most locked-down environments in financial services relative to their size: segmented networks, hardened cores, examined vendor lists. Shadow AI walks past all of it, because nothing is breached. The data leaves through an approved browser, over standard encrypted traffic, typed voluntarily by your most trusted people into a website that is not blocked because it is not malware. Every control worked exactly as designed. The design just never imagined that exfiltration would look like an employee asking for help with an email.
If you think this is a big-company problem, consider that it happened at Samsung. In 2023, after engineers pasted sensitive internal code into ChatGPT, Samsung banned staff use of generative AI tools entirely, and that was an organization with world-class security engineering. A forty-person credit union with no sanctioned AI tool and no policy is not more protected than Samsung was. It is simply less able to see it happening.
Why credit unions are especially exposed
Three structural reasons, none of them anyone's fault. First, small teams and tight budgets mean almost no credit union has bought enterprise AI licenses, so staff use the free consumer tiers, and consumer tiers are exactly where the data handling terms are weakest and where prompts may be retained or used for training depending on settings nobody at your institution has reviewed. Second, the absence of a sanctioned tool does not reduce demand; it guarantees the demand is met invisibly. Third, and most seriously, the data your staff handle all day is member nonpublic personal information, the specific class of data your institution is obligated to safeguard.
Frame it the way an examiner eventually will. A consumer AI chatbot receiving member data is a third-party service provider processing nonpublic personal information. Where is the due diligence file? Where is the agreement? Who reviewed its data handling? For sanctioned vendors you have answers. For the AI tools your staff actually use most, the honest answer is that the vendor was onboarded by a browser bookmark. And under the NCUA's incident reporting expectations, with reportable cyber incidents due within 72 hours, there is a harder question underneath: if member data leaked through a personal chatbot account, would you find out in time to report it? Would you find out at all?
The ban reflex, and why it fails
The instinctive response is prohibition: block the domains, update the acceptable use policy, send the memo. Three things happen next. Usage moves to personal phones, where you have even less visibility than before. Your best people quietly keep the productivity gain and stop telling you how they work. And the institution forfeits the upside entirely while retaining most of the risk. A ban does not end shadow AI. It ends your ability to observe it.
The uncomfortable truth is that your staff have run a more successful pilot than most funded IT projects. Adoption is total, satisfaction is high, and training took zero hours. The problem is not the enthusiasm. It is that the institution has not caught up to it with governance.
The 90-day path from shadow to governed
Discover without punishing. Pull DNS and proxy logs for the major AI domains and measure actual usage. Announce an amnesty at the same time: no consequences for past use, because the goal is a map, not a purge. Punish discovery and you will never get honest data again.
Write the data rule in plain language. Not a fifteen-page policy; one memorable line, on the order of: member names, account data, credentials, and unreleased financials never go into any AI tool we have not issued you. Specific enough to follow at the moment of temptation.
Give them a sanctioned door. Stand up an enterprise tier of one of the major assistants, with contractual no-training commitments, single sign-on, and logging. The single most effective control against shadow AI is a sanctioned tool that is actually good, because people do not route around a door that opens.
Train with your own examples. Not abstract slides; the four vignettes at the top of this article, replayed with your systems' names, and what to do instead in each case.
Monitor as an ongoing control. Data loss prevention on prompts where feasible, periodic log review, and a standing agenda item where staff can propose new AI uses openly, because the pipeline of shadow use never stops, it only changes tools.
The real risk is not AI
It is unmanaged AI, adopted at full speed with zero governance, inside institutions whose entire brand is member trust. Credit unions have survived every technology wave by being deliberate. This wave did not wait for deliberation, which means the deliberate move now is not to slow the adoption down. It is to catch up to it, see it, and put a frame around it before an examiner, or a breach notification letter, does it for you.
I help credit unions and banks make exactly this move, from shadow AI to governed AI, and then onward to the AI systems worth building on purpose. If you want the discovery step done right, my messages are open.
And a challenge for the credit union leaders reading: ask your team this week, anonymously, one question. Have you used a public AI tool for work in the last month? Come back and tell me, no names and no institutions, what percentage said yes. I have a prediction, and I do not think I am wrong.