T. Gschwender & Associates Is Now The Bonadio Group LEARN MORE.

Practical Applications of AI in Financial Institutions Part 3: Information Technology & Information Security

By Christopher Salone, on September 3rd, 2026

Artificial intelligence is quietly reshaping the back office of every community bank and credit union. In the first two installments of this series, we looked at how AI is transforming lending and customer service. This third installment examines how small to midsize financial institutions are actually implementing AI within their Information Technology (IT) and Information Security (IS) departments, the two functions most directly responsible for keeping the institution operational and resilient.

In 2025, financial services firms were the most-targeted sector for AI-powered cyberattacks, more than any other industry, according to Deep Instinct, and roughly two-thirds of credit unions now say that they plan to use AI for underwriting, decision-making, and other core activities. At the same time, the National Credit Union Administration (NCUA) launched a dedicated Artificial Intelligence resource webpage in August 2025 and published its own AI Compliance Plan in September 2025, signaling that examiners will evaluate AI within the existing supervisory framework rather than through a bolt-on regime. For community banks, the Independent Community Bankers of America (ICBA) followed with its Community Bank AI Security Readiness Guide in June 2026, aimed squarely at the vendor-heavy operating model most community institutions rely on.

For IT and IS leaders at institutions with lean teams and modest budgets, the question remains how to deploy AI safely, prove value to the board, and document controls that stand up to an NCUA, FDIC, OCC, or state examination.

Where AI Is Making an Impact

1. Security Operations, Threat Detection & Alert Triage

Community banks and credit unions rarely operate a 24/7 in-house Security Operations Center (SOC). Most rely on a managed security service provider (MSSP), a managed detection and response (MDR) partner, or a small internal team paired with a virtual Chief Information Security Officer (vCISO). AI is now embedded in nearly every one of those service tiers.

Examples of Tools in Action:

  • CrowdStrike Charlotte AI: CrowdStrike’s agentic analyst triages detections with more than 98% accuracy and is being marketed as “the brain of the agentic SOC,” designed to accelerate analyst outcomes across endpoint, identity, and cloud workloads that community institutions increasingly rely on.
  • SentinelOne Purple AI and Microsoft Security Copilot: These platforms use natural-language threat hunting, one-click remediation, and autonomous alert triage. Microsoft’s Security Alert Triage Agent is designed to autonomously triage phishing, identity, and other detections so analysts can focus on real attacks, a capability Microsoft says can make phishing triage roughly 6.5 times faster.
  • Managed Detection and Response (MDR) Partners: In the community-financial-institution market, MDR and MSSP providers are combining AI-driven analytics with 24/7 SOC monitoring, identity security, and threat intelligence to deliver layered defense that most institutions could not build in-house.

Why It Works: Small SOC teams (or virtual ones delivered by an MSSP) simply cannot read every alert. AI compresses alert volume, correlates events across endpoints and identity, and surfaces the handful of incidents that actually warrant analyst attention. That is a genuine capacity multiplier for an institution with two or three security staff.

2. Email Security, Phishing Defense & Deepfake Detection

Email remains the single most common attack vector for community financial institutions, and AI is now on both sides of the fight. The same generative models that help employees draft emails also help attackers craft flawless phishing lures at scale.

Examples of Tools in Action:

  • Abnormal AI, IRONSCALES & Tessian: These behavioral-AI email security platforms model normal communication patterns for each user, then flag anomalies indicative of business email compromise (BEC), vendor impersonation, or account takeover. In one publicly documented case study, a credit union displaced its incumbent Avanan deployment for Abnormal to stop advanced spear-phishing and BEC attacks and automate remediation.
  • Microsoft Security Copilot Phishing Triage / Security Alert Triage Agent: Now in public preview and generally available in Defender XDR, this agent autonomously reviews user-reported phishing emails, classifies them, and gives analysts natural-language explanations of its verdicts, dramatically reducing the manual backlog of “Is this real?” reviews.
  • KnowBe4 with AI-Focused Modules: Security awareness platforms are integrating AI-specific content, including modules on Deepfakes, Scams, and Disinformation, so employees are trained on the exact threats attackers are now delivering.

Why It Works: Traditional secure email gateways use signatures and rules. Behavioral AI learns what “normal” looks like at the individual user level, who a loan officer typically emails, when, and about what, so it can flag the CEO-impersonation wire request that a rule-based system would miss.

Deepfake and Voice-Clone Fraud is Now Real for Community Institutions. FinCEN’s alert on Fraud Schemes Involving Deepfake Media Targeting Financial Institutions provides red-flag indicators community banks and credit unions can operationalize. Documented incidents include a $25 million deepfake video-call fraud at a multinational and a wave of voice-clone attacks specifically targeting credit unions, which has forced institutions to re-examine callback verification, wire-approval workflows, and member authentication scripts.

3. IT Operations, Help Desk & Employee Productivity

For institutions with two-to-ten-person IT teams, the highest-ROI AI use cases are often the least glamorous: deflecting password resets, summarizing tickets, drafting runbooks, and answering “where is that policy?” questions.

Examples of Tools in Action:

  • Microsoft 365 Copilot & Copilot Studio IT Helpdesk Agents: Institutions can build a Copilot Studio agent that deflects tier-1 IT queries (password resets, VPN, software how-tos) with instant knowledge-base answers, then automatically opens tickets in ServiceNow, Jira, or a custom helpdesk system via Power Automate. Microsoft cites internal data that roughly 70% of Level-1 IT tickets have a documented solution somewhere in the knowledge base.
  • Internal “Closed-Loop” AI Knowledge Bases: A number of credit unions have deployed internal, walled-garden AI assistants that reference only the institution’s own policies, procedures, and training content, ensuring that no member data is exposed to public models.
  • Glia CoPilot: Launched in March 2026, Glia CoPilot is an agentic knowledge partner marketed to banks and credit unions that surfaces answers from institutional knowledge for every role, including front-line, back-office, and IT, reducing the “swivel-chair” research that eats employee time.

Why It Works: A well-scoped Copilot agent removes the most repetitive work from a small IT team, password resets, “is the core system down?” questions, new-hire access requests, and does it inside Microsoft Teams, where employees already work. The IT team keeps the escalation and P1 incident paths for humans.

From the Field: One credit union we work with has formally approved AI tools within tightly scoped, closed-loop use cases: an internal AI knowledge base (“Ask Sam”), an internal coaching assistant (“CoachApply”), image generation for the marketing team, and exploratory use by the technology and senior-leadership teams. Critically, none of those approvals allow member information or nonpublic credit union data to be entered into any AI platform without explicit prior approval from the SVP of Information Technology & Project Management. That model, narrow scope, explicit data-handling rules, and a single accountable executive, is emerging as a template for community institutions.

4. Governance, Risk, Compliance & Audit Readiness

The compliance and audit functions inside community institutions are typically staffed for last year’s workload, not this year’s regulatory expectations. AI is helping close that gap.

Examples of Tools in Action:

  • Abrigo BAM+ & the Abrigo AI Suite: End-to-end AML and fraud-prevention software built for banks and credit unions, enhanced with AI-powered alert capabilities that improve detection, reduce noise, and help analysts resolve genuinely suspicious activity faster. Documented outcomes for credit unions using AI-enabled compliance workflows include roughly 95% faster audit examination preparation, 85% fewer false positives, and 70% faster suspicious activity report filing.
  • AI-Assisted Policy & Documentation Drafting: Institutions are using generative AI to draft first cuts of information security policies, incident response playbooks, and board memos, then routing them through the human review and approval process. Community banks report using AI tools to review documents, checks, receipts, and loan materials for signs of fraud, synthetic content, or AI-generated forgery.
  • AI Vendor Due-Diligence Questionnaires: Institutions and their auditors are now issuing structured questionnaires that ask vendors specifically about model risk, training data, bias, explainability, incident notification, and AI-specific breach response, mapped to GLBA Safeguards Rule, the FFIEC IT Examination Handbook, and the NIST AI Risk Management Framework.

Why It Works: The compliance workload for a community bank or credit union has grown, but the tools finally allow productivity gains. AI does not replace the BSA officer, the ISO, or the internal auditor, it drafts, summarizes, extracts, and triages so those specialists spend their time on judgment rather than paperwork.

Challenges & Risks: What Small & Midsize Institutions Must Navigate

Regulatory Expectations Are Real, even Without AI-Specific Rules

Neither the NCUA nor the federal banking agencies have issued AI-specific rules. Instead, both have made clear that existing regulations are technology-neutral and apply to AI use, information security standards, fair lending, model risk, and third-party risk management all continue to apply regardless of whether the tool is an AI system, a spreadsheet, or a legacy application. NCUA’s September 2025 AI Compliance Plan reinforces that examiners will evaluate safety and soundness, compliance, internal controls, ongoing monitoring, and third-party due diligence, not the AI tool itself.

Institutions should also plan for life after the FFIEC Cybersecurity Assessment Tool (CAT), which was formally sunset on August 31, 2025. Federal Reserve SR 24-7 and companion FDIC/OCC guidance direct institutions to transition to alternatives such as the NIST Cybersecurity Framework 2.0, the CISA Cross-Sector Cybersecurity Performance Goals, and the Cyber Risk Institute (CRI) Profile. AI risk is increasingly a first-class control area within each of those frameworks.

Vendor-Embedded AI & “Shadow AI”

The ICBA guide identifies problems community banks may not see coming, such as shadow AI, vendor-embedded AI, wearable devices, and fourth-party risk. Because community institutions typically rely on a core processor, a digital-banking provider, and a stack of fintech partners, a feature activated by a vendor can put AI inside the institution before anyone at the bank has approved it. ICBA recommends that community bankers ask each critical vendor three questions:

  1. Do you already have AI features active in our environment?
  2. Will you notify us before activating additional AI features?
  3. How are you responding to AI-driven cyber capabilities from Microsoft, Anthropic, and OpenAI?

Data Governance, Model Risk & Explainability

Even a well-scoped internal AI assistant needs disciplined data governance. The Treasury Department’s report Managing Artificial Intelligence-Specific Cybersecurity Risks in the Financial Services Sector, the FS-ISAC AI guidance released in early 2024 and updated in 2025, and CISA’s Cybersecurity Information Sheet on AI Data Security and Deploying AI Systems Securely all point to the same core discipline: know what data trains and prompts your models, protect model weights and APIs, monitor for drift, and enforce human oversight for consequential decisions.

Workforce Readiness & Board Oversight

Boards at community institutions are being asked to hold off on AI without the technical vocabulary to do so responsibly. The ICBA guide places AI readiness explicitly at the board level, arguing it “touches risk, technology, vendors, customers, and long-term planning,” and encourages institutions to document the conversation, participate in tabletop exercises, and update incident response plans. Structured curricula, such as six-month, monthly, 30-minute board sessions that build fluency and generate defensible governance artifacts, are becoming a practical answer for institutions that need to prove oversight to examiners.

Practical Guidance: Implementing AI in IT & Information Security

For institutions considering or expanding AI adoption in IT and IS, the pattern that consistently works looks like this:

1. Start with High-ROI, Lower-Risk Use Cases

The best first pilots are the ones where errors are recoverable and value is measurable:

  • Phishing triage inside an existing email security platform
  • A Copilot Studio helpdesk agent scoped to password resets, VPN, and software how-tos
  • An internal, closed-loop knowledge base grounded only in your policies and procedures
  • AI-assisted first drafts of policy updates, board memos, and audit responses

Each of these captures productivity without exposing member data to a public model.

2. Put Governance in Place Before You Scale

A defensible AI program at a community institution typically includes:

  • A board-approved AI policy that names an accountable executive (often the CIO, CISO, or SVP of IT) and specifies approved and prohibited uses.
  • A formal AI risk assessment aligned with the NIST AI Risk Management Framework, GLBA Safeguards, and model-risk principles, refreshed at least annually.
  • Integration with your existing third-party risk management program, using an AI-specific vendor questionnaire that asks about training data, bias testing, explainability, incident notification, and SOC 2 / ISO 42001 evidence.

3. Address Shadow AI Explicitly

Block public generative AI by default. Sanction a small number of enterprise-grade tools (for many institutions, that is Microsoft 365 Copilot with tenant-level guardrails configured by the core provider). Communicate the policy, then reinforce it in security awareness training with AI-specific modules on deepfakes, prompt injection, and data-handling.

4. Build the AI Discussion into Board Reporting

Boards should see, at a minimum:

  • Which AI tools are approved, in pilot, or in production
  • Which vendors have AI features embedded in their products
  • Metrics on AI-related incidents, phishing simulation results, and Copilot license utilization
  • Progress against the AI risk assessment and the next planned refresh

5. Choose Partners Who Know the Community-Institution Market

Community banks and credit unions rarely need enterprise-scale AI platforms. They need partners—MSSPs, MDR providers, MSPs, core-adjacent AI providers, and vCISO/vCIO advisors—who understand FFIEC, NCUA, GLBA, and state cyber rules and can deliver AI-enabled capabilities inside a governance envelope the board and examiners can defend.

6. Measure, Refine & Report

Successful institutions treat AI adoption in IT and IS the way they treat any other control: pilot, measure, refine, and report. Track ticket-deflection rates, mean time to triage phishing reports, false-positive reduction in AML alerts, and audit-preparation hours saved. Feed those results into the next board update and the next risk assessment refresh.

Next Steps

For institutions just beginning, the message is the same as it was in customer service and lending: start now, start small, but start with governance. Deploy an internal, closed-loop assistant. Turn on the phishing-triage agent inside your existing email security platform. Ask your MSSP or MDR provider what AI is already in their playbook. Update your board reporting to include AI. And treat every implementation as an opportunity to build the evidence your next examination will require.

If you have any questions or are interested in learning more, we are here to help. Please do not hesitate to reach out to discuss your specific situation.

This material has been prepared for general, informational purposes only and is not intended to provide, and should not be relied on for, tax, legal or accounting advice. Should you require any such advice, please contact us directly. The information contained herein does not create, and your review or use of the information does not constitute, an accountant-client relationship.

Share on LinkedIn
Share on Facebook
Share on X

Written By

Related Industries

Insights

Related Articles

Jamie Card
Jamie Card
Industry Leader, Financial Services
MicrosoftTeams image
Timothy Pike
Regional Managing Partner, Dallas Region