BOULDER CITY, Nev. — One of the biggest misconceptions credit unions can make about artificial intelligence is believing they aren’t already using it, according to two industry executives, who said the rapid spread of AI makes continuous governance, data controls and model monitoring increasingly important.
Mike Orsomarso, SVP of data and analytics with AKUVO, and Linda Rossi, president and CEO of $1.5-billion Ventura County Credit Union in California, discussed those risks during “The AI Imperative: Data, Privacy, and Model Risk Management,” the sixth installment of a seven-part webinar series hosted by The CU Daily and Mitchell Stankovic and Associates.
Editor’s Note: The final session in this seven-part series will take part today with a live discussion between Dr. Brandi Stankovic and Frank J. Diekmann of the CU Daily that will seek to provide a topline overview of the first six sessions in this series. The conversation begins at 12 p.m. ET/9 a.m. PT and is free. You can sign up here.

Orsomarso said AI is increasingly embedded in products credit unions already use, including fraud detection and other third-party platforms. “You really don’t have a choice whether you have AI risk,” Orsomarso said.
The question, he said instead, is how the institution governs it.
Credit unions should inventory not only AI applications they have intentionally deployed, but also AI capabilities embedded in third-party systems, he said.
Employees Already Using AI
Rossi said Ventura County discovered the issue firsthand.
An internal review approximately a year ago found about 50% of employees were visiting AI websites from within the credit union’s network.

That prompted VCCU to reconsider whether policies alone provided sufficient protection and ultimately led to a decision to bring employee AI usage inside a controlled environment using Microsoft Copilot.
Rossi said the credit union is gradually transitioning employees rather than immediately prohibiting other tools, providing tips and training before eventually requiring employees to use the approved platform.
The biggest risk surrounding AI may still be human behavior, she said.
That includes both employees informally using AI and the people responsible for monitoring formal AI systems to ensure their outputs remain reliable.
Beware the ‘Quiet’ Failure
Beyond cybersecurity, Orsomarso said one of his biggest concerns is model drift — an AI model that doesn’t dramatically fail but instead becomes progressively less accurate as economic conditions, portfolios or other underlying factors change.
A model might be validated when implemented and then never reviewed again.
“It doesn’t crash, it doesn’t stop working,” Orsomarso said. “Everyone thinks it’s working and functioning properly, but it just slowly degrades.”
That makes AI governance an ongoing operating discipline rather than simply another policy document, he said.

“A policy or a document can’t detect that drift,” Orsomarso said. “Only a monitoring process can.”
Rossi said VCCU similarly views governance as continuous. Even with traditional underwriting models, the credit union tests whether results continue to meet expectations. AI-driven systems require that type of scrutiny at an even greater level, she said.
Old Data Can Bring Old Biases
The decades of member information accumulated by credit unions can provide valuable material for AI models, but both speakers cautioned that historical data must be understood before it is used.
Orsomarso recommended applying several tests: determining the purpose for using particular information, establishing why the data is justified and understanding its origin and accuracy.
System conversions and changes in how data fields are populated can create problems that go unnoticed for years, he said.
Free-form collection notes present another risk because they may contain biases introduced by employees who originally entered the information. Training AI on those records without addressing the bias could produce unintended results.
Rossi said AI itself can help institutions review historical data for trends, discrepancies and other indications of questionable data quality.
Third Parties Require Scrutiny
Vendor management represents another significant concern because AI providers may themselves rely on other third parties.
Rossi said credit unions need to understand how vendors use their data, what other companies they work with and how those organizations use the information.

She also recommended obtaining legal assistance when crafting vendor agreements addressing those concerns.
Orsomarso said AKUVO’s models are generated using customer information placed into a data lake that doesn’t contain personally identifiable information. That prevents models from directly training on prohibited characteristics, although he cautioned models can still develop bias through other variables and must be tested.
‘Innovate at the Speed You Can Explain’
Rossi said VCCU’s approach begins with determining how the credit union strategically wants to scale and then asking whether AI or automation can support that strategy — rather than allowing available technology to dictate the strategy.
Orsomarso offered a similar test for institutions deciding how quickly to move. “Innovate at the speed that you can explain,” he said.
Credit unions should be able to explain to boards, employees and others why an AI-driven decision was made, he stated, adding, “You can delegate the work to the model, but you can’t delegate the accountability,” Orsomarso said.
Rossi summarized the challenge with a principle she said another AI platform offered when she posed the same question: ethical stewardship grounded in the credit union mission of “people helping people.”
For more information on the AI Imperative series, go here.





One Response
This is an important discussion because AI governance cannot stop at governing the model. Credit unions absolutely need controls around data, bias, drift, explainability, third-party risk, and accountability. But even a well-governed AI model can make a poor business recommendation if it does not understand the organization in which the decision will be executed.
The next challenge is defining the causal boundaries within which AI operates. AI needs to understand how a proposed action affects activities, capacity, resources, funding, liquidity, risk, capital, and ultimately economic value. That requires more than policies, process maps, or an ontology; it requires an explicit causal model of the enterprise. As AI moves from performing well-defined tasks toward making consequential business decisions, that enterprise understanding becomes increasingly important.