AI’s Promise — And Its Peril: What Credit Unions Need To Know About Securing The Next Frontier

By Ray Birch

TAMPA—As credit unions accelerate their adoption of artificial intelligence, many are discovering that innovation is moving faster than internal controls.

According to Shane Butcher, executive director of Optiri, a division of Trellance, the industry is experiencing what he describes as a “Wild West” moment with AI. Institutions know they need it. Employees are already using it. But many aren’t confident they know how to secure it.

“The reality is people are going to use AI whether we want them to or not,” Butcher said. “The question is whether we put the right guardrails around it.”

From Butcher’s vantage point working with credit unions, the first issue isn’t sophisticated cyberattacks or rogue algorithms. It’s employees with good intentions.

He points to what he calls “shadow AI” — staff using public tools such as ChatGPT or Claude outside formal IT oversight. A member service representative trying to respond more clearly to a complaint. A loan officer drafting a denial letter. An employee polishing internal communications. In the process, they may paste account numbers, loan data or even Social Security numbers into a public AI interface.

“They’re trying to be more efficient. They’re trying to serve members better,” Butcher said. “But now that data has left the credit union. You don’t control it. You don’t necessarily have an audit trail.”

Industry surveys underscore the scale of the issue. Roughly 70% of employees report using AI tools whether their employer has approved them or not, and nearly half say they would continue even if banned. Even among organizations with AI policies, fewer than one in five employees say they understand those policies. To Butcher, that makes one thing clear: ignoring AI use is not realistic.

Fortunately, he said, most of what credit unions need to do isn’t revolutionary.

“We’ve done this before,” he said. “With networks. With servers. With cloud. AI is another technology layer. If you don’t put the right guardrails around it, you’re going to have issues.”

Where Is AI In Play?

That starts with understanding where AI is already in play. Butcher advises credit unions to inventory usage, looking at web filtering logs to see whether employees are visiting AI sites, reviewing browser plug-ins and evaluating what AI features may already be embedded in existing platforms. In many cases, tools that institutions already rely on now have AI capabilities switched on by default.

Embedded AI, he noted, can feel safer because it operates inside the credit union’s own environment. But that security depends on the fundamentals. If file permissions aren’t properly segmented — if, for example, HR folders aren’t fully walled off — AI can surface information that employees technically have access to but would never normally seek out.

“You can get some surprising results,” Butcher warned. “If the underlying environment isn’t prepared, AI will expose that very quickly.”

The newest concern, he added, is agentic AI — systems that don’t just generate content but take actions. When AI begins initiating workflows, interacting with systems or moving data on a user’s behalf, the control requirements expand significantly. Institutions must rethink authentication, authorization and monitoring to ensure accountability remains clear.

Shane Butcher

For Butcher, the solution isn’t for IT to clamp down unilaterally. AI governance must be cross-functional. IT and information security teams need to build the technical controls, but risk management must update risk profiles, legal must review vendor contracts and business units must define the legitimate use cases that align with strategy and compliance obligations.

“If you don’t give employees approved alternatives, they’re going to find their own,” he said. “So, create the policies, communicate them, train on them — and provide tools that operate within your controls.”

Close Calls

So far, Butcher said, he has not seen a catastrophic AI-driven breach at a credit union. But he has heard of multiple instances where not having the right controls led to close calls with potentially sensitive information. In those cases, nothing immediately “bit” the institution. But the exposure risk was real.

At the same time, he cautions strongly against abandoning AI out of fear. Banks are investing heavily here. AI is improving operational efficiency, enhancing fraud detection and accelerating cybersecurity response times. Even in security operations, AI-driven tools can identify adversaries faster than traditional methods and automate defensive actions before human teams are aware of a threat.

“If we decide we’re not going to use AI at all, we’re putting ourselves behind,” Butcher said. “It can make credit unions more efficient, more nimble, more competitive. We just have to do it the right way.”

In his view, that means treating AI not as an experiment but as infrastructure — subject to the same disciplined governance credit unions apply to every other critical system. The technology itself is powerful, he said. The difference between risk and resilience will come down to how seriously institutions take the fundamentals.

“The technology isn’t the problem,” Butcher said. “It’s whether we put the right guardrails around it.”

Section: Standard
Word Count: 952
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/AI-s-Promise-And-Its-Peril-What-Credit-Unions-Need-To-Know-About-Securing-The-Next-Frontier