Five concerns on every C-suite agenda
Synthesized from NCUA supervisory priorities, Cornerstone Advisors industry research (January 2026), and credit union CEO commentary. These are the questions behind closed-door meetings — not vendor slide decks.
Balance sheet
Earnings under pressure
Loan delinquencies and losses are at a 10+ year high. Higher-cost funding limits margin recovery. CEOs report widening stress in member affordability and portfolio quality — not abstract macro risk.
“Can we grow loans without blowing up credit quality — and still fund it?”
Fraud & payments
Fraud is a balance-sheet line item
Half of credit unions saw higher fraud losses in 2025. First-party fraud now accounts for more than 40% of total fraud losses. NCUA examiners are sharpening focus on payment-system governance and insider controls.
“Are we losing more to fraud than we’re saving with efficiency projects?”
AI governance
AI is deployed — not governed
NCUA has no AI-specific rule, but existing vendor management, security, and fair-lending expectations apply. Use cases are easy to spot; governance and implementation gaps leave institutions over-reliant on vendors.
“We already have AI in our stack — what governs it, and can I explain that to the board?”
Execution
Strategy without operators
Technology budgets are rising, but many institutions still miss planned deployments. 2026 is the year to operationalize GenAI — not experiment indefinitely.
“We bought Copilot — why isn’t anyone using it safely?”
Competition
Digital pressure from every direction
Deposit growth, member experience, and fintech competition remain top strategic priorities. Digital banking vendors are shipping AI features faster than institutions can govern them.
“Our digital vendor is rolling out AI — are we ready to turn it on?”
Exam readiness
NCUA 2026 supervisory lens
Letter 26-CU-01 emphasizes lending quality, liquidity and IRR, earnings and capital, payment-system risk, fraud prevention, and risk-based BSA/AML programs — all while AI use grows inside vendor stacks.
“What will the examiner ask that we can’t answer today?”
Where budget is going in the next six months
Credit unions are not holding cash — they’re allocating it. The gap is sequencing: fraud and vendor AI get funded first; governance and workforce adoption often lag until the board or examiner asks.
| Spend category | Why now | Typical motion |
| Fraud / BSA / AML |
Rising losses; 75% increasing prevention budgets; NCUA BSA emphasis |
Alert triage tools, staffing, sanctions modules, vendor upgrades |
| Cybersecurity & payments |
NCUA payment-systems priority; deepfake and wire-fraud exposure |
MFA, wire controls, vendor security reviews |
| Digital banking & core-adjacent tech |
80%+ raising tech spend; member experience competition |
Mobile features, AI in digital channels, payments modernization |
| GenAI licenses |
59% CU genAI deployment rate |
Microsoft Copilot, contact-center AI, vendor-embedded assistants |
| AI governance |
NCUA vendor diligence expectations; no dedicated AI rule |
Often underfunded until board vote or exam — Seiche’s entry point |
| Automation pilots |
Agentic AI plans in fraud, lending, contact center, finance |
90-day POCs with scale/stop criteria — not enterprise transforms |
The white space: Budget flows to fraud tools and vendor AI features. The direction that governs them — who owns AI, what the guardrails are, how value gets proven — is what usually goes unfunded until the board or an examiner asks. That direction is what the Seiche AI Strategy Assessment establishes.
The risk ledger: every AI investment carries a risk
The investments above each carry a primary risk your board — and your examiner — will ask about. NCUA now reviews AI inside existing frameworks (BSA/AML, fair lending, vendor management, ERM): the use cases don’t change, the controls around them do. This is the layer Seiche makes examiner-ready.
| The AI move | Primary risk | Control that makes it examiner-ready |
| Growth & deposits — conversational onboarding; predictive deposit / balance-migration models |
Model risk & data quality — biased targeting, weak predictions, privacy of behavioral data |
Model inventory + validation; GLBA review of data use; human review of targeting |
| Fraud & cybersecurity — GenAI fraud detection; behavioral biometrics |
Adversarial AI — deepfakes / voice clones defeat controls; false positives hit good members |
Step-up auth that assumes synthetic media; red-team testing; SAR quality control |
| Member experience — contact-center & member-facing chat automation |
Hallucination & UDAAP — wrong answers, unfair statements, member-data leakage |
Retrieval guardrails + human escalation; AI-use disclosure; log every AI-influenced interaction |
| Efficiency & talent — back-office & compliance automation |
Over-automation & opacity — unexplainable BSA/AML decisions; staff skills erosion |
Human-in-the-loop on filings; retrievable audit trail; staff change management |
| Lending & credit — AI credit decisioning; loan-memo drafting |
Fair lending & explainability — ECOA / Reg B adverse-action, disparate impact |
Specific adverse-action reasons (CFPB Circular 2022-03); fair-lending testing; documented model validation |
No “black box” defense. Under CFPB Circular 2022-03, a model being too complex to explain does not excuse ECOA / Regulation B adverse-action duties — you must still give specific, accurate reasons. Seiche maps each AI use to its control using the NIST AI Risk Management Framework and NCUA’s existing expectations, so the risk ledger is something your board can approve and your examiner can follow.
Issues, upsides & opportunities
The balanced view a board needs before it votes: the headwinds to manage, the gains that justify the work, and the moves that turn AI from exposure into advantage.
5 issues
Headwinds to manage in 2026.
- Deployed but ungoverned — no inventory, policy, or named owner; vendor-embedded AI spreads faster than oversight
- Fraud escalating — deepfakes, voice clones, and first-party fraud; ~half of CUs saw higher losses in 2025
- Rising exam scrutiny — NCUA reviews AI through BSA/AML, fair-lending, vendor, and ERM lenses (Letter 26-CU-01)
- Adoption & talent gaps — tools bought, not used safely; fraud, data, and compliance roles hard to retain
- Earnings & ROI pressure — decade-high delinquencies and costlier funding demand measurable AI ROI, not scattered pilots
5 upsides
The gains that justify the work.
- Ahead of banks — 59% of CUs already run generative AI; a real window to compete on member experience
- Stronger fraud defense — real-time monitoring and behavioral biometrics cut losses
- Efficiency-ratio relief — back-office and compliance automation eases cost and talent pressure
- Growth & retention — conversational onboarding and contact-center AI win and keep members
- Faster lending — AI decisioning and memo drafting shorten turnaround against fintech lenders
5 opportunities
Moves that turn risk into advantage.
- Stand up lightweight governance now — inventory + policy + named owner turns exam risk into a board-approved program
- Lead with a governed fraud/BSA pilot — meet budget already flowing; prove ROI with scale/stop criteria
- Govern vendor AI before it switches on — control the digital-banking feature before launch (partner channel)
- Controlled GenAI productivity rollout — post-policy Copilot adoption with champions, not shadow AI
- Make “examiner-ready” a differentiator — durable governance becomes a member-trust and growth story
The threat landscape: AI as a weapon
AI isn’t only a tool for credit unions — it’s a tool for criminals. It compresses the time, skill, and cost an attacker needs. When attacks were expensive, criminals went after large institutions; at pennies per attempt, every institution and every member with an email address is worth attacking. This is why an AI strategy has to account for cyber-resilience, not just productivity.
Deepfake fraud losses
$1.1B
In U.S. deepfake fraud losses in 2025 — roughly 3× the 2024 total.
Pindrop, 2025 · Deloitte Center for Financial Services, 2024
Voice cloning
+680%
Year-over-year rise in voice-cloning fraud; 149% more banking fraud calls using deepfake audio.
Pindrop, 2025
Synthetic identity fraud
$6B
In annual losses — the fastest-growing financial crime in the U.S., projected to reach $23B by 2030. Most of it never gets counted as fraud; it books as credit loss.
Federal Reserve Bank of Boston, 2024 · Sumsub, 2025
Dark-web fraud tools
$50/mo
Entry-level subscription for turnkey fraud tooling; $220 buys lifetime access with source included. No technical skill required.
SlashNext, January 2025
AI-driven phishing
54%
Success rate of AI-crafted phishing against humans — 4.5× traditional attacks, which land around 12%.
Microsoft Digital Defense Report · Harvard research
Why it lands twice
A synthetic identity is a real Social Security number — often a child’s or an elderly member’s — attached to a fabricated name, aged into a good credit score, then busted out. It hits the balance sheet once and the relationship once. A member who gets defrauded doesn’t distinguish between fraud you caused and fraud you failed to catch.
The old defense is gone. Teaching staff to spot bad grammar and generic greetings no longer works against generated text. Countering AI-enabled attack requires AI-enabled defense — which makes it a strategy question, not just a line in the security budget.
A short window before AI oversight tightens
Two layers are moving at once. Domestically, oversight is fragmenting — fifty states writing their own rules at different speeds and in different directions. Internationally, foreign regimes reach U.S. credit unions through two doors: members moving money across borders, and technology built or hosted overseas. A U.S.-only reading of AI law leaves you exposed on both the member side and the vendor side.
| Date | What changes | Why it matters to a credit union |
| March 11, 2026 |
FTC AI Bias Policy Statement |
May preempt or reinforce state bias requirements — the direction is not yet settled |
| June 30, 2026 |
Colorado AI Act (SB 24-205) |
Impact assessments and transparency obligations for high-risk AI |
| August 2, 2026 |
EU AI Act high-risk deadline |
Credit scoring is classified high-risk; reaches any EU-touching operation or vendor |
| Ongoing 2026 |
Executive order on state AI laws |
DOJ challenging state AI laws; federal preemption is possible but unresolved |
| 2026 (draft) |
NIST AI Cybersecurity Profile |
Voluntary framework harmonizing regulatory expectations — a defensible reference point |
You don’t need to become an AI regulatory expert. You need an AI strategy that adapts as regulations evolve — so each new requirement is an adjustment, not a project. That is a cadence question the strategy answers once, rather than a scramble repeated every time a rule lands.
The Seiche AI Strategy Framework
Twenty-four elements across six domains — the same frame for every credit union we work with, which is what makes the scoring mean something. An AI strategy sets direction; it is not a procedure manual. The framework fixes your position on each element: what you believe, who owns it, and where the guardrail sits. Procedures, validation protocols, and vendor checklists are written downstream, against that direction.
DOMAIN 01
Direction
Where are we going, and who agreed?
- AI Strategy Statement
- Board & Executive Alignment
- Business Outcome Linkage
- External Forces Posture
DOMAIN 02
Governance & Trust
How do we decide, and how do we defend it?
- Governance Operating Model
- Regulatory & Compliance Posture
- Ethical Use & Member Fairness
- Human-in-the-Loop Doctrine
- Fraud, Security & AI Threats
DOMAIN 03
Portfolio
What do we do, and what does it replace?
- Use-Case Intake & Decision Rules
- Portfolio Balance & Ambition
- Process Re-Engineering Standard
- AI Inventory & Lifecycle
DOMAIN 04
Economics
What do we spend, and how do we prove it worked?
- Funding & Budget Model
- ROI & Value Validation
- Total Cost of Ownership
DOMAIN 05
Capability
Do we build it or buy it, and where does it run?
- Build / Buy / Partner Rule
- Hosting & Data Residency
- Vendor Selection & Oversight
- Data Foundation & Readiness
DOMAIN 06
People
Who does the work when the work changes?
- Change Management & Adoption
- Reskilling & Role Redesign
- Workforce Allocation
- AI Talent Retention
Every element scored twice — today, and a twelve-month target
| Stage | What it means | What you typically see |
| 1 · Absent |
No position exists. AI may already be in the building through vendor products, and no one owns it. |
Nothing written; no named owner |
| 2 · Ad Hoc |
Activity exists, driven by individuals or by vendors. No shared rule, so the outcome depends on who is in the room. |
Pilots, emails, individual judgment |
| 3 · Defined |
A position is written down and approved. Application is uneven and evidence is thin. |
Policy or statement exists; practice varies |
| 4 · Governed |
The position is applied consistently, owned by name, and can be evidenced to a board or an examiner. |
Decision records, inventory, review cadence |
| 5 · Compounding |
The practice improves itself. Results from one decision feed the next, and the capability becomes a competitive asset. |
Measured outcomes changing the next decision |
Not everything needs to reach five. Strategy is choosing where you’ll be excellent and where “defined” is honestly enough. Trying to be governed on all twenty-four at once is how credit unions stall.
How the engagement runs
One CEO-focused engagement, five steps. Light-touch by design: insight for the CEO without a burden on the organization.
1
Align
A working session with the CEO: current priorities, board posture, and what success looks like.
2
Interview
Confidential conversations with leaders you select — wherever AI stands today.
3
Assess & draft
Documentation and interviews synthesized into a preliminary view. Where they disagree is usually the most important finding.
4
Review & refine
Findings go back to you before anything is final — you validate and challenge them.
5
Results
Executive readout, the comprehensive report, and your Executive Action Agenda.
And where it leads: a five-phase roadmap
Our assistance concentrates in the early phases. After that, you lead the organization forward — that is the point of the engagement, not a limitation of it.
Phase 1
Current state
Detailed review of the credit union’s current AI program, including any existing AI strategy.
Seiche-assisted
→
Phase 2
Build foundation
Publish or amend AI policy, inventory AI, designate a governance lead, set acceptable-use rules, harden security, monitor budget.
Seiche-assisted
→
Phase 3
Deploy
Point solutions where the money is: BSA/AML, document processing, lending, AI quality monitoring.
Credit-union-led
→
Phase 4
Scale
Org-wide GenAI, chatbots, and CRM intelligence.
Credit-union-led
→
Phase 5
Transform
Reshape and reinvent how the institution operates.
Credit-union-led
What you walk away with
Deliverable I
Executive Readout & Strategic Recommendations
The strategic summary of the assessment, built so the CEO can lift it into a board meeting without translation.
- Key findings of the assessment
- Priority recommendations
- The value of acting — and the cost of waiting
- Your Executive Action Agenda
- On-site or virtual readout
Deliverable II
The AI Strategy Compass
The comprehensive record of the engagement — the rationale behind each recommendation, not just the conclusion.
- Methodology and who we engaged
- Current-state analysis and evidence
- Findings and recommendations
- Prioritized roadmap for execution
- Point-in-time — builds an audit trail
Deliverable III
Framework Templates
Three templates that let you maintain, measure, and manage progress against your own strategy after we leave.
- AI Strategy — position, owner, guardrails
- Assessment — maturity against the stages
- Execution record — progress against goals
- Strategy template is a living document
- Each new assessment adds to the trail
Concern → where the framework answers it
Each concern a CEO raises maps to specific elements of the framework. That mapping is what turns “we should do something about AI” into a scored position with a named owner.
| C-suite concern | Framework domain | What the assessment produces |
| Examiner asks about AI |
Governance & Trust |
A scored regulatory and compliance posture, a named governance owner, and an AI inventory you can evidence |
| Fraud / BSA losses rising |
Governance & Trust |
A documented position on fraud, security, and AI threats — and where human review stays mandatory |
| Copilot deployed, low adoption |
People |
Change management and adoption scored honestly, with reskilling and workforce allocation addressed |
| Digital vendor shipping AI |
Capability |
A build / buy / partner rule and vendor oversight standard — set before the feature switches on |
| Board wants “our AI strategy” |
Direction |
An AI Strategy Statement and documented board–executive alignment, in words everyone can repeat |
| Pilots everywhere, nothing scaled |
Portfolio |
Use-case intake rules, portfolio balance, and the discipline to redesign the process rather than layer AI on it |
| Earnings pressure / unclear ROI |
Economics |
A funding model, total cost of ownership, and — the half most institutions skip — value validation after the fact |
| Peers and regulators moving faster than us |
Direction |
An external forces posture: member expectations, peer moves, and regulation translated into implications for you |
The critical distinction: tool-driven vs. strategy-driven
Most credit unions are on the left-hand column today. That isn’t a failure — it’s where AI adoption naturally starts. The work is moving across.
| Tool-driven — where most credit unions are today | Strategy-driven — what future-proofing looks like |
| Adoption |
Teams experiment freely. No framework, no guardrails, no shared results. Fear inhibits employees from using the tools openly. |
Problems first, tools second. Deliberate, sequenced rollout. Change management actively encourages employee use. |
| Governance |
IT owns AI decisions — or no one does. The board has never reviewed it. Budget is unclear. The AI roadmap cuts across business goals rather than serving them. |
Holistic and outcome-driven. Compliance built in from day one. Budget managed. The AI roadmap aligns to business goals. |
| Outcomes |
Demos deployed and pilot purgatory. No measured value. Capacity and resources absorbed with nothing to show a board. |
Fraud caught. Regulatory findings avoided. Members retained. Measurable gains in productivity and efficiency. |
A fair question to ask your own team: does everyone here have free rein to try AI tools right now? Most executives say yes. That answer is the left-hand column — and it is the honest starting point for the assessment, not something to be embarrassed about.
What every board member needs to know
The board’s job is governance and strategy. Give them the framing and the questions, and they can lead the organization rather than pressure it.
The framing
Four things a board should hold as settled before it debates any specific tool.
- You already use AI — fraud detection, core systems, vendor tools
- You need a policy; regulators expect one
- The risk of inaction outweighs the risk of action
- Start with governance, not technology — policy first, then pilots
The questions
What a board should be asking management, at every meeting until the answers are boring.
- Do we have an AI inventory?
- Do we have a formal AI policy?
- Are we doing fair-lending testing?
- Is there a company-wide AI strategy?
- Do we have an advisory roadmap?
The cost of inaction
Without a strategy there is no way to know whether AI spending is working.
- Erosion, not stability — the gap widens each quarter
- Capacity without direction — uncoordinated pilots drain resources
- Silent member and talent loss — visible only after they’ve decided
- Reactive decisions — you act after a fraud event, not before one
- Boards lose confidence in AI investment altogether
What Seiche is — and isn’t
Credibility matters with C-suite buyers. We set the direction that governs the fraud and technology spend you’re already making.
- We do not replace core lending or credit risk management
- We do not resell BSA/fraud platforms — we establish how you select and govern them
- We do not run your AI program for you; phases 3 through 5 are led by your team, by design
- We do not write your procedure manuals — an AI strategy sets direction, and procedures are written downstream against it
AI in banking is not a technology decision. It’s a strategic decision. The institutions that win won’t be the ones that adopt AI first — they’ll be the ones that adopt it wisely. You don’t need to be JPMorgan and you don’t need to be Chime. You need to be a better version of your own institution.
Request an engagement outline
Sources
- NCUA, NCUA’s 2026 Supervisory Priorities, Letter 26-CU-01, January 2026. ncua.gov
- NCUA, Artificial Intelligence (AI) — supervision FAQ and vendor diligence resources, updated April 2026. ncua.gov
- Cornerstone Advisors, What’s Going On in Banking 2026: AI, Crypto, and Fraud: Oh My!, press release, January 29, 2026 (survey of 416 senior executives; 54% credit unions). PR Newswire
- Finopotamus, coverage of Cornerstone 2026 report including FAIRWINDS and Marine CU executive commentary, January 2026. finopotamus.com
- Jack Henry, 2025 Strategy Benchmark Study — CEO priorities including AI, cyber, fraud, digital banking. discover.jackhenry.com
- CFPB, Consumer Financial Protection Circular 2022-03: Adverse Action Notification Requirements in Connection With Credit Decisions Based on Complex Algorithms, May 26, 2022. consumerfinance.gov
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023. nist.gov
- Pindrop, 2025 Voice Intelligence & Security Report — deepfake fraud losses and voice-cloning growth, 2025.
- Deloitte Center for Financial Services, generative-AI fraud loss projections, 2024.
- Federal Reserve Bank of Boston, synthetic identity fraud research, 2024; Sumsub identity fraud reporting, 2025.
- SlashNext, dark-web AI fraud-tooling pricing research, January 2025.
- Microsoft, Digital Defense Report, and Harvard research on AI-generated phishing efficacy.
- Colorado General Assembly, SB 24-205 — Consumer Protections for Artificial Intelligence, effective June 30, 2026. leg.colorado.gov
- European Union, Artificial Intelligence Act (Regulation 2024/1689) — high-risk system obligations applying August 2, 2026. artificialintelligenceact.eu
Sources 8–12 are carried forward from the Seiche AI Strategy webinar deck and are pending URL-level verification before external distribution.