Why banks can’t policy their way out of shadow AI
- Banks are cracking down on "shadow AI" with stricter policies, but experts say that's treating the wrong problem entirely.
- Institutions buy AI tools before mapping the workflows they're meant to support and employees notice when the sanctioned option can't keep up.
Employees at financial institutions are using AI tools their employers never approved for tasks that touch sensitive customer data. This unsanctioned use of AI, often called shadow AI, is not a toothless problem. In May 2026, an employee at Pennsylvania-based CB Financial Services, parent company of Community Bank, uploaded a file containing customer names, Social Security numbers, and dates of birth into an unauthorized AI application while preparing a presentation. The employee bypassed the bank’s approved AI tool for a personal account on a personal device. The bank caught the exposure quickly enough to get the data deleted before it could be used to train the vendor’s model. Notably, the bank already offered a sanctioned AI tool. The employee simply chose not to use it. The instinct inside most banks and credit unions is to treat this as a policy failure and respond with tighter restrictions, more monitoring, and firmer language in the acceptable-use policy. But that response gets the diagnosis wrong, according to Corey Gross, VP and Head of Data & AI at Q2 Holdings. “When employees bypass a sanctioned tool, they’re telling leadership teams that the approved option isn’t getting the job done.” In his view, the root cause sits upstream of governance entirely: institutions are buying AI tools without first understanding the workflows those tools are meant to support. Instead of writing stricter acceptable-use policies, Gross suggests the more useful question is why employees felt they needed to go around the tool they were given in the first place. “It’s rarely a governance or compliance issue,” he said.
The distinction sounds subtle, but it points to a different set of priorities for any bank trying to scale AI responsibly. It suggests that starting with the design of the work itself is more critical than the framing of the rules that surround it.
Workflow redesign has to come before the AI rollout
…
