Seiche Advisors · Credit unions · 2026

What keeps credit union leaders up at night — and how we help

Your vendors already embed AI. Examiners will ask what governs it. Fraud budgets are rising. Most CUs have no inventory, no policy, and no named owner. AI pilots don't move credit unions — leadership and AI strategy do.

59%
Credit unions that have deployed generative AI going into 2026
~50%
CUs that saw higher fraud losses in 2025 — most expect more in 2026
75%
Institutions increasing fraud prevention budgets
80%+
Banks and CUs planning higher technology spend in 2026

Five concerns on every C-suite agenda

Synthesized from NCUA supervisory priorities, Cornerstone Advisors industry research (January 2026), and credit union CEO commentary. These are the questions behind closed-door meetings — not vendor slide decks.

Balance sheet

Earnings under pressure

Loan delinquencies and losses are at a 10+ year high. Higher-cost funding limits margin recovery. CEOs report widening stress in member affordability and portfolio quality — not abstract macro risk.

“Can we grow loans without blowing up credit quality — and still fund it?”

Fraud & payments

Fraud is a balance-sheet line item

Half of credit unions saw higher fraud losses in 2025. First-party fraud now accounts for more than 40% of total fraud losses. NCUA examiners are sharpening focus on payment-system governance and insider controls.

“Are we losing more to fraud than we’re saving with efficiency projects?”

AI governance

AI is deployed — not governed

NCUA has no AI-specific rule, but existing vendor management, security, and fair-lending expectations apply. Use cases are easy to spot; governance and implementation gaps leave institutions over-reliant on vendors.

“We already have AI in our stack — what governs it, and can I explain that to the board?”

Execution

Strategy without operators

Technology budgets are rising, but many institutions still miss planned deployments. 2026 is the year to operationalize GenAI — not experiment indefinitely.

“We bought Copilot — why isn’t anyone using it safely?”

Competition

Digital pressure from every direction

Deposit growth, member experience, and fintech competition remain top strategic priorities. Digital banking vendors are shipping AI features faster than institutions can govern them.

“Our digital vendor is rolling out AI — are we ready to turn it on?”

Exam readiness

NCUA 2026 supervisory lens

Letter 26-CU-01 emphasizes lending quality, liquidity and IRR, earnings and capital, payment-system risk, fraud prevention, and risk-based BSA/AML programs — all while AI use grows inside vendor stacks.

“What will the examiner ask that we can’t answer today?”

Where budget is going in the next six months

Credit unions are not holding cash — they’re allocating it. The gap is sequencing: fraud and vendor AI get funded first; governance and workforce adoption often lag until the board or examiner asks.

Spend categoryWhy nowTypical motion
Fraud / BSA / AML Rising losses; 75% increasing prevention budgets; NCUA BSA emphasis Alert triage tools, staffing, sanctions modules, vendor upgrades
Cybersecurity & payments NCUA payment-systems priority; deepfake and wire-fraud exposure MFA, wire controls, vendor security reviews
Digital banking & core-adjacent tech 80%+ raising tech spend; member experience competition Mobile features, AI in digital channels, payments modernization
GenAI licenses 59% CU genAI deployment rate Microsoft Copilot, contact-center AI, vendor-embedded assistants
AI governance NCUA vendor diligence expectations; no dedicated AI rule Often underfunded until board vote or exam — Seiche’s entry point
Automation pilots Agentic AI plans in fraud, lending, contact center, finance 90-day POCs with scale/stop criteria — not enterprise transforms
The white space: Budget flows to fraud tools and vendor AI features. The direction that governs them — who owns AI, what the guardrails are, how value gets proven — is what usually goes unfunded until the board or an examiner asks. That direction is what the Seiche AI Strategy Assessment establishes.

The risk ledger: every AI investment carries a risk

The investments above each carry a primary risk your board — and your examiner — will ask about. NCUA now reviews AI inside existing frameworks (BSA/AML, fair lending, vendor management, ERM): the use cases don’t change, the controls around them do. This is the layer Seiche makes examiner-ready.

The AI movePrimary riskControl that makes it examiner-ready
Growth & deposits — conversational onboarding; predictive deposit / balance-migration models Model risk & data quality — biased targeting, weak predictions, privacy of behavioral data Model inventory + validation; GLBA review of data use; human review of targeting
Fraud & cybersecurity — GenAI fraud detection; behavioral biometrics Adversarial AI — deepfakes / voice clones defeat controls; false positives hit good members Step-up auth that assumes synthetic media; red-team testing; SAR quality control
Member experience — contact-center & member-facing chat automation Hallucination & UDAAP — wrong answers, unfair statements, member-data leakage Retrieval guardrails + human escalation; AI-use disclosure; log every AI-influenced interaction
Efficiency & talent — back-office & compliance automation Over-automation & opacity — unexplainable BSA/AML decisions; staff skills erosion Human-in-the-loop on filings; retrievable audit trail; staff change management
Lending & credit — AI credit decisioning; loan-memo drafting Fair lending & explainability — ECOA / Reg B adverse-action, disparate impact Specific adverse-action reasons (CFPB Circular 2022-03); fair-lending testing; documented model validation
No “black box” defense. Under CFPB Circular 2022-03, a model being too complex to explain does not excuse ECOA / Regulation B adverse-action duties — you must still give specific, accurate reasons. Seiche maps each AI use to its control using the NIST AI Risk Management Framework and NCUA’s existing expectations, so the risk ledger is something your board can approve and your examiner can follow.

Issues, upsides & opportunities

The balanced view a board needs before it votes: the headwinds to manage, the gains that justify the work, and the moves that turn AI from exposure into advantage.

5 issues

Headwinds to manage in 2026.

  • Deployed but ungoverned — no inventory, policy, or named owner; vendor-embedded AI spreads faster than oversight
  • Fraud escalating — deepfakes, voice clones, and first-party fraud; ~half of CUs saw higher losses in 2025
  • Rising exam scrutiny — NCUA reviews AI through BSA/AML, fair-lending, vendor, and ERM lenses (Letter 26-CU-01)
  • Adoption & talent gaps — tools bought, not used safely; fraud, data, and compliance roles hard to retain
  • Earnings & ROI pressure — decade-high delinquencies and costlier funding demand measurable AI ROI, not scattered pilots
5 upsides

The gains that justify the work.

  • Ahead of banks — 59% of CUs already run generative AI; a real window to compete on member experience
  • Stronger fraud defense — real-time monitoring and behavioral biometrics cut losses
  • Efficiency-ratio relief — back-office and compliance automation eases cost and talent pressure
  • Growth & retention — conversational onboarding and contact-center AI win and keep members
  • Faster lending — AI decisioning and memo drafting shorten turnaround against fintech lenders
5 opportunities

Moves that turn risk into advantage.

  • Stand up lightweight governance now — inventory + policy + named owner turns exam risk into a board-approved program
  • Lead with a governed fraud/BSA pilot — meet budget already flowing; prove ROI with scale/stop criteria
  • Govern vendor AI before it switches on — control the digital-banking feature before launch (partner channel)
  • Controlled GenAI productivity rollout — post-policy Copilot adoption with champions, not shadow AI
  • Make “examiner-ready” a differentiator — durable governance becomes a member-trust and growth story

The threat landscape: AI as a weapon

AI isn’t only a tool for credit unions — it’s a tool for criminals. It compresses the time, skill, and cost an attacker needs. When attacks were expensive, criminals went after large institutions; at pennies per attempt, every institution and every member with an email address is worth attacking. This is why an AI strategy has to account for cyber-resilience, not just productivity.

Deepfake fraud losses
$1.1B

In U.S. deepfake fraud losses in 2025 — roughly 3× the 2024 total.

Pindrop, 2025 · Deloitte Center for Financial Services, 2024
Voice cloning
+680%

Year-over-year rise in voice-cloning fraud; 149% more banking fraud calls using deepfake audio.

Pindrop, 2025
Synthetic identity fraud
$6B

In annual losses — the fastest-growing financial crime in the U.S., projected to reach $23B by 2030. Most of it never gets counted as fraud; it books as credit loss.

Federal Reserve Bank of Boston, 2024 · Sumsub, 2025
Dark-web fraud tools
$50/mo

Entry-level subscription for turnkey fraud tooling; $220 buys lifetime access with source included. No technical skill required.

SlashNext, January 2025
AI-driven phishing
54%

Success rate of AI-crafted phishing against humans — 4.5× traditional attacks, which land around 12%.

Microsoft Digital Defense Report · Harvard research
Why it lands twice

A synthetic identity is a real Social Security number — often a child’s or an elderly member’s — attached to a fabricated name, aged into a good credit score, then busted out. It hits the balance sheet once and the relationship once. A member who gets defrauded doesn’t distinguish between fraud you caused and fraud you failed to catch.

The old defense is gone. Teaching staff to spot bad grammar and generic greetings no longer works against generated text. Countering AI-enabled attack requires AI-enabled defense — which makes it a strategy question, not just a line in the security budget.

A short window before AI oversight tightens

Two layers are moving at once. Domestically, oversight is fragmenting — fifty states writing their own rules at different speeds and in different directions. Internationally, foreign regimes reach U.S. credit unions through two doors: members moving money across borders, and technology built or hosted overseas. A U.S.-only reading of AI law leaves you exposed on both the member side and the vendor side.

DateWhat changesWhy it matters to a credit union
March 11, 2026 FTC AI Bias Policy Statement May preempt or reinforce state bias requirements — the direction is not yet settled
June 30, 2026 Colorado AI Act (SB 24-205) Impact assessments and transparency obligations for high-risk AI
August 2, 2026 EU AI Act high-risk deadline Credit scoring is classified high-risk; reaches any EU-touching operation or vendor
Ongoing 2026 Executive order on state AI laws DOJ challenging state AI laws; federal preemption is possible but unresolved
2026 (draft) NIST AI Cybersecurity Profile Voluntary framework harmonizing regulatory expectations — a defensible reference point
You don’t need to become an AI regulatory expert. You need an AI strategy that adapts as regulations evolve — so each new requirement is an adjustment, not a project. That is a cadence question the strategy answers once, rather than a scramble repeated every time a rule lands.

The Seiche AI Strategy Framework

Twenty-four elements across six domains — the same frame for every credit union we work with, which is what makes the scoring mean something. An AI strategy sets direction; it is not a procedure manual. The framework fixes your position on each element: what you believe, who owns it, and where the guardrail sits. Procedures, validation protocols, and vendor checklists are written downstream, against that direction.

DOMAIN 01

Direction

Where are we going, and who agreed?
  • AI Strategy Statement
  • Board & Executive Alignment
  • Business Outcome Linkage
  • External Forces Posture
DOMAIN 02

Governance & Trust

How do we decide, and how do we defend it?
  • Governance Operating Model
  • Regulatory & Compliance Posture
  • Ethical Use & Member Fairness
  • Human-in-the-Loop Doctrine
  • Fraud, Security & AI Threats
DOMAIN 03

Portfolio

What do we do, and what does it replace?
  • Use-Case Intake & Decision Rules
  • Portfolio Balance & Ambition
  • Process Re-Engineering Standard
  • AI Inventory & Lifecycle
DOMAIN 04

Economics

What do we spend, and how do we prove it worked?
  • Funding & Budget Model
  • ROI & Value Validation
  • Total Cost of Ownership
DOMAIN 05

Capability

Do we build it or buy it, and where does it run?
  • Build / Buy / Partner Rule
  • Hosting & Data Residency
  • Vendor Selection & Oversight
  • Data Foundation & Readiness
DOMAIN 06

People

Who does the work when the work changes?
  • Change Management & Adoption
  • Reskilling & Role Redesign
  • Workforce Allocation
  • AI Talent Retention

Every element scored twice — today, and a twelve-month target

StageWhat it meansWhat you typically see
1 · Absent No position exists. AI may already be in the building through vendor products, and no one owns it. Nothing written; no named owner
2 · Ad Hoc Activity exists, driven by individuals or by vendors. No shared rule, so the outcome depends on who is in the room. Pilots, emails, individual judgment
3 · Defined A position is written down and approved. Application is uneven and evidence is thin. Policy or statement exists; practice varies
4 · Governed The position is applied consistently, owned by name, and can be evidenced to a board or an examiner. Decision records, inventory, review cadence
5 · Compounding The practice improves itself. Results from one decision feed the next, and the capability becomes a competitive asset. Measured outcomes changing the next decision
Not everything needs to reach five. Strategy is choosing where you’ll be excellent and where “defined” is honestly enough. Trying to be governed on all twenty-four at once is how credit unions stall.

How the engagement runs

One CEO-focused engagement, five steps. Light-touch by design: insight for the CEO without a burden on the organization.

1
Align A working session with the CEO: current priorities, board posture, and what success looks like.
2
Interview Confidential conversations with leaders you select — wherever AI stands today.
3
Assess & draft Documentation and interviews synthesized into a preliminary view. Where they disagree is usually the most important finding.
4
Review & refine Findings go back to you before anything is final — you validate and challenge them.
5
Results Executive readout, the comprehensive report, and your Executive Action Agenda.

And where it leads: a five-phase roadmap

Our assistance concentrates in the early phases. After that, you lead the organization forward — that is the point of the engagement, not a limitation of it.

Phase 1
Current state Detailed review of the credit union’s current AI program, including any existing AI strategy. Seiche-assisted
Phase 2
Build foundation Publish or amend AI policy, inventory AI, designate a governance lead, set acceptable-use rules, harden security, monitor budget. Seiche-assisted
Phase 3
Deploy Point solutions where the money is: BSA/AML, document processing, lending, AI quality monitoring. Credit-union-led
Phase 4
Scale Org-wide GenAI, chatbots, and CRM intelligence. Credit-union-led
Phase 5
Transform Reshape and reinvent how the institution operates. Credit-union-led

What you walk away with

Deliverable I
Executive Readout & Strategic Recommendations

The strategic summary of the assessment, built so the CEO can lift it into a board meeting without translation.

  • Key findings of the assessment
  • Priority recommendations
  • The value of acting — and the cost of waiting
  • Your Executive Action Agenda
  • On-site or virtual readout
Deliverable II
The AI Strategy Compass

The comprehensive record of the engagement — the rationale behind each recommendation, not just the conclusion.

  • Methodology and who we engaged
  • Current-state analysis and evidence
  • Findings and recommendations
  • Prioritized roadmap for execution
  • Point-in-time — builds an audit trail
Deliverable III
Framework Templates

Three templates that let you maintain, measure, and manage progress against your own strategy after we leave.

  • AI Strategy — position, owner, guardrails
  • Assessment — maturity against the stages
  • Execution record — progress against goals
  • Strategy template is a living document
  • Each new assessment adds to the trail

Concern → where the framework answers it

Each concern a CEO raises maps to specific elements of the framework. That mapping is what turns “we should do something about AI” into a scored position with a named owner.

C-suite concernFramework domainWhat the assessment produces
Examiner asks about AI Governance & Trust A scored regulatory and compliance posture, a named governance owner, and an AI inventory you can evidence
Fraud / BSA losses rising Governance & Trust A documented position on fraud, security, and AI threats — and where human review stays mandatory
Copilot deployed, low adoption People Change management and adoption scored honestly, with reskilling and workforce allocation addressed
Digital vendor shipping AI Capability A build / buy / partner rule and vendor oversight standard — set before the feature switches on
Board wants “our AI strategy” Direction An AI Strategy Statement and documented board–executive alignment, in words everyone can repeat
Pilots everywhere, nothing scaled Portfolio Use-case intake rules, portfolio balance, and the discipline to redesign the process rather than layer AI on it
Earnings pressure / unclear ROI Economics A funding model, total cost of ownership, and — the half most institutions skip — value validation after the fact
Peers and regulators moving faster than us Direction An external forces posture: member expectations, peer moves, and regulation translated into implications for you

The critical distinction: tool-driven vs. strategy-driven

Most credit unions are on the left-hand column today. That isn’t a failure — it’s where AI adoption naturally starts. The work is moving across.

Tool-driven — where most credit unions are todayStrategy-driven — what future-proofing looks like
Adoption Teams experiment freely. No framework, no guardrails, no shared results. Fear inhibits employees from using the tools openly. Problems first, tools second. Deliberate, sequenced rollout. Change management actively encourages employee use.
Governance IT owns AI decisions — or no one does. The board has never reviewed it. Budget is unclear. The AI roadmap cuts across business goals rather than serving them. Holistic and outcome-driven. Compliance built in from day one. Budget managed. The AI roadmap aligns to business goals.
Outcomes Demos deployed and pilot purgatory. No measured value. Capacity and resources absorbed with nothing to show a board. Fraud caught. Regulatory findings avoided. Members retained. Measurable gains in productivity and efficiency.
A fair question to ask your own team: does everyone here have free rein to try AI tools right now? Most executives say yes. That answer is the left-hand column — and it is the honest starting point for the assessment, not something to be embarrassed about.

What every board member needs to know

The board’s job is governance and strategy. Give them the framing and the questions, and they can lead the organization rather than pressure it.

The framing

Four things a board should hold as settled before it debates any specific tool.

  • You already use AI — fraud detection, core systems, vendor tools
  • You need a policy; regulators expect one
  • The risk of inaction outweighs the risk of action
  • Start with governance, not technology — policy first, then pilots
The questions

What a board should be asking management, at every meeting until the answers are boring.

  • Do we have an AI inventory?
  • Do we have a formal AI policy?
  • Are we doing fair-lending testing?
  • Is there a company-wide AI strategy?
  • Do we have an advisory roadmap?
The cost of inaction

Without a strategy there is no way to know whether AI spending is working.

  • Erosion, not stability — the gap widens each quarter
  • Capacity without direction — uncoordinated pilots drain resources
  • Silent member and talent loss — visible only after they’ve decided
  • Reactive decisions — you act after a fraud event, not before one
  • Boards lose confidence in AI investment altogether

What Seiche is — and isn’t

Credibility matters with C-suite buyers. We set the direction that governs the fraud and technology spend you’re already making.

  • We do not replace core lending or credit risk management
  • We do not resell BSA/fraud platforms — we establish how you select and govern them
  • We do not run your AI program for you; phases 3 through 5 are led by your team, by design
  • We do not write your procedure manuals — an AI strategy sets direction, and procedures are written downstream against it

AI in banking is not a technology decision. It’s a strategic decision. The institutions that win won’t be the ones that adopt AI first — they’ll be the ones that adopt it wisely. You don’t need to be JPMorgan and you don’t need to be Chime. You need to be a better version of your own institution.

Request an engagement outline

Sources

  1. NCUA, NCUA’s 2026 Supervisory Priorities, Letter 26-CU-01, January 2026. ncua.gov
  2. NCUA, Artificial Intelligence (AI) — supervision FAQ and vendor diligence resources, updated April 2026. ncua.gov
  3. Cornerstone Advisors, What’s Going On in Banking 2026: AI, Crypto, and Fraud: Oh My!, press release, January 29, 2026 (survey of 416 senior executives; 54% credit unions). PR Newswire
  4. Finopotamus, coverage of Cornerstone 2026 report including FAIRWINDS and Marine CU executive commentary, January 2026. finopotamus.com
  5. Jack Henry, 2025 Strategy Benchmark Study — CEO priorities including AI, cyber, fraud, digital banking. discover.jackhenry.com
  6. CFPB, Consumer Financial Protection Circular 2022-03: Adverse Action Notification Requirements in Connection With Credit Decisions Based on Complex Algorithms, May 26, 2022. consumerfinance.gov
  7. NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023. nist.gov
  8. Pindrop, 2025 Voice Intelligence & Security Report — deepfake fraud losses and voice-cloning growth, 2025.
  9. Deloitte Center for Financial Services, generative-AI fraud loss projections, 2024.
  10. Federal Reserve Bank of Boston, synthetic identity fraud research, 2024; Sumsub identity fraud reporting, 2025.
  11. SlashNext, dark-web AI fraud-tooling pricing research, January 2025.
  12. Microsoft, Digital Defense Report, and Harvard research on AI-generated phishing efficacy.
  13. Colorado General Assembly, SB 24-205 — Consumer Protections for Artificial Intelligence, effective June 30, 2026. leg.colorado.gov
  14. European Union, Artificial Intelligence Act (Regulation 2024/1689) — high-risk system obligations applying August 2, 2026. artificialintelligenceact.eu

Sources 8–12 are carried forward from the Seiche AI Strategy webinar deck and are pending URL-level verification before external distribution.