AI and Quantum Computing are Here: Credit Unions Must be Ready

By Jason Stverak

For years, artificial intelligence and quantum computing were treated as technologies of the future. That future has arrived. They are now operational, cybersecurity, regulatory, and competitive priorities for every credit union. The question is no longer whether they will affect financial services, but whether credit unions will have the policies, resources, and regulatory clarity to use them securely, responsibly, and affordably.

The stakes are especially high for defense credit unions. They safeguard financial information belonging to servicemembers, veterans, military retirees, civilian defense employees, and their families – populations targeted by cybercriminals, identity thieves, fraud networks, and foreign adversaries. Emerging technology can strengthen their defenses, but it also gives bad actors tools that make deception faster, cheaper, and more convincing.

Why Preparation Cannot Wait

Quantum computing illustrates why preparation cannot wait for a crisis. Today’s public-key encryption protects online banking, mobile applications, payment credentials, digital signatures, member communications, cloud platforms, and connections with core processors. A sufficiently capable quantum computer could eventually break widely used forms of that encryption. Adversaries can also collect encrypted information now and retain it for later decryption – the so-called “harvest now, decrypt later” threat.

No credit union needs to become a quantum-computing laboratory. Every credit union does need a migration plan. Institutions should inventory where cryptography is used, identify data that must remain confidential for years, question vendors about post-quantum roadmaps, and build quantum-ready requirements into procurement, contract renewals, architecture, and technology budgets. 

NIST has finalized post-quantum standards and urged organizations to prepare. Waiting until the threat fully matures will be too late.

Opportunity & Danger

AI presents a more immediate mix of opportunity and danger. Credit unions already use AI-assisted tools to detect unusual transactions, identify account takeover, improve member service, evaluate applications, and strengthen cybersecurity. Used responsibly, these systems can reveal patterns traditional tools miss and provide faster service to a military family overseas, a spouse managing finances during deployment, or a veteran in a rural community.

Meanwhile, deepfake videos, cloned voices, synthetic identities, fraudulent documents, automated phishing, and AI-powered chatbots are making scams more persuasive. Criminals can use public details about a veteran’s service, rank, family, or benefits to create a convincing impersonation. Credit union employees often know their members and can recognize an unusual withdrawal, sudden wire request, or person acting under coercion. Technology should strengthen that human judgment, not replace it.

Lending Governance

That principle must also govern lending. AI may expand access and improve efficiency, especially for members with limited traditional credit histories. But automation does not eliminate legal responsibility. When credit is denied, a member deserves an accurate, understandable explanation. Credit unions must test models for accuracy, stability, explainability, data quality, bias, and performance drift. 

Meaningful human review is essential when a result is disputed or overlooks military-specific income, benefits, or circumstances. A vendor cannot hide behind a proprietary model and leave the credit union holding the compliance risk.

Third-party dependence deserves equal attention. Most credit unions will obtain AI through core processors, cloud companies, fintech firms, identity-verification vendors, and model providers. Contracts must address permitted uses of member data, whether prompts and recordings may train a vendor model, encryption and deletion, material model changes, and security incidents. 

Credit unions also need audit rights, business-continuity protections, data portability, and a realistic exit strategy.

Regulators Have Work to Do

Regulators have work to do. NCUA permits AI when it is deployed safely, soundly, and in compliance with existing law. Yet GAO has identified gaps in NCUA’s model-risk guidance. Credit unions should not discover binding expectations during an examination, and examiners should not construct inconsistent standards from bank guidance. NCUA should issue clear, credit-union-specific, use-case-appropriate guidance and adopt new binding requirements through transparent notice-and-comment rulemaking.

Above all, smaller credit unions must not be left behind. They cannot maintain the data-science, cybersecurity, legal, and model-validation teams of the largest institutions. Grants, shared services, credit union service organizations, technical assistance, and public-private partnerships can broaden access to advanced defenses. Federal advisory groups, pilots, and standards-setting bodies must include credit unions from the beginning.

DCUC will continue advocating for a national framework that is risk-based, scalable, technology-neutral, and protective of responsible innovation. Comparable activities should receive comparable treatment whether performed by a credit union, bank, fintech, or technology platform. 

Policymakers should expand real-time fraud information sharing, protect institutions acting in good faith to stop scams, preserve human accountability in consequential decisions, and assign responsibility to the parties best positioned to control risk.

CUs Shouldn’t Have to Choose

Credit unions should not have to choose between innovation and trust, between security and service, or between new capabilities and the cooperative mission. With responsible governance, practical regulation, equitable access to technology, and preparation that begins now, they can protect members while remaining competitive. AI and quantum computing will shape the next era of financial services. 

Credit unions must have both a seat at the table and the tools to lead – continuing to Serve ALL Who Serve.

Jason Stverak is chief advocacy officer with the Defense Credit Union Council.

Facebook
Twitter
LinkedIn

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.