AURORA, Calif.–There is an AI crisis that “you won’t see coming,” according to one expert, who shared what will lead to that crisis and how credit unions can take steps to at least mitigate it, even if the approach presently being taken by most CUs is “flabbergasting.”
In remarks to the GoWest Credit Union Association’s MAXX Conference, Jen Anthony, chief advisory officer with NetCov (Network Coverage), the company formerly known as ThinkStack and which has 180 CU clients, shone a light on that risk CU leaders don’t see coming and offered some specifics around what they should be doing now.

Anthony, a former CISO in the Air Force cyber command who said she spent her career “fighting the bad guys” by being engaged in offensive cyber operations against Russia, China, Iran and North Korea, said she and NetCov “care deeply” about both AI and credit unions, and during her remarks used a show of hands to reveal an audience that believes they are at a “mature” point in implementing AI, only to point out that most have gaping vulnerabilities.
Question Posed
First, Anthony posed this question: “When someone contacts the credit union, what is the member providing? Information, opportunity, a request for help or guidance. I would argue they are handing you trust. They are trusting that you understand that and that you take that very seriously. We can talk about technology all day long, but at the end of the day what this comes down to is you maintaining trust with your members.”
And it is in the enormous potential for violating that trust where the crisis credit unions don’t see coming is lurking, according to Anthony.
Anthony said she is just as worried as credit unions are about the risks and worries presented by AI, but she is simultaneously excited about what she sees as “incredible opportunities.”
“But I am flabbergasted at the way we are using it without any thought or planning,” Anthony told the meeting.
Paying to Get Out of Trouble
Anthony cited research that found 79% of credit unions are researching or actively implementing AI, and a show of hands in the session found most of the credit unions said they are already actively involved in AI work. One person observed that the decision to become involved in AI wasn’t made by the credit union but by its vendors.
Just like introduction of the Intneret, when credit unions plunged in with no regulations. “Except that this is moving much faster,” said Anthony. “We have set the stage for an interesting scenario. As someone who understands the bad guys, they don’t have to invent any new ways to come after you. The U.S. leads the world in the amount of money we will hand over to get out of a cyber crisis–$3.9 trillion a year. Russia is leading the way.”
Anthony said her firm sees at least 10 examples a week of a cybercriminal getting into the credit union because an employee clicked on a link.
A CU’s Worst-Day Scenario
Certainly, cybercriminals are using AI to attack credit unions, but Anthony said the Ai crisis credit unions are going to fade is going to be much different than what they expect. It won’t be all credit unions taken down by a piece of malicious software.
Anthony’s vision for a credit union’s “worst day” involves this scenario. It’s a Tuesday at a credit union where the board wants it to innovate quickly but safely. As a result, the CU has added a number of capabilities, including a tool that summarizes loan applications and recommends how they should be handled. The business case was faster arrival at a loan decision. But on that Tuesday a 17-year member, Maria, calls after being denied for a modest auto loan. The explanation provided doesn’t match her information, she said.
The employee, seeking to help, opens the application and uses a personal AI assistant that she uses at home and which is available to her at her credit union workstation, and she removes the information in the vendor portal and puts it into the chatbot the credit union uses to understand why the member was rejected.
A Different Story
The staff member has a completely different story than the one she got from the AI vendor. Maria wants to know who the “person” was who reviewed the application, and now the credit union has to explain that. The leadership team becomes aware of what’s happening, and IT wants to know what’s going on, as well, and is scrambling to lock it down. The lending department is flustered. They want the loan tool turned off. The question becomes whether the issue involves one member or all loan applicants. The CU’s management team. doesn’t know if AI toll can be disabled and doesn’t know who has access to what.
“I think for credit unions this is where your AI risk is, because you haven’t put the guardrails in place,” said Anthony. “The well-meaning vendor sold the CU a loan tool without guidance and controls.”
One audience member blamed the management team for not properly vetting the new solution. Another person added, “The vendors don’t know what they are delivering.”
Anthony said her company is seeing the use of AI by fraudsters moving exponentially faster, adding that data show the average person is getting something delivered to their work email, telephone, or personal email that is a scam. The result is people become fatigued by it, which makes for mistakes—such as clicking on a malicious link.
Four Identified Gaps
According to Anthony, there are four identified gaps in the use of AI by credit unions:
- Visibility. Anthony “pleaded” with people to ask questions.
- Boundaries. There is a lack of guardrails.
- Accountability. Credit unions are great at putting policies in place, but not so great at holding anyone accountable, said Anthony, sharing the story of how one CU CFO on two occasions clicked on a link to allow a threat-actor to penetrate the CU and cause losses. No action had been taken after the first violation. “You get what you tolerate,” said Anthony.
- Recovery. No one goes one step beyond to ask what the credit union will do when a breach scenario occurs, according to Anthony.
NCUA AI Rules of Engagement
Anthony shared this guidance from NCUA, which she acknowledged is sparse: “All current resources and FAQs describe AI with existing supervision including internal controls, ongoing monitoring and appropriate third-party oversight.”
“That is your call to action,” said Anthony.
What You Can Do Now
Anthony said credit unions should take these steps:
Know where your AI Is
“You have to ask tough questions and be a demanding client,” she said, adding the question to ask is NOT, “Do we buy an Ai system, tool or platform?”
Instead, it’s “Are we using technology that generates content, makes a recommendation, classifies a member or taken an action?” Anthony said. “Talk to business units. What does it solve? What happens if something goes wrong? Who owns it?
Have Usable Staff Boundaries
Most credit unions have a policy, but they are real “generic,” according to Anthony. “Add some specificity to your policy letter. You need a clear approval path and clear guardrails around what they can and cannot do.”
The policy should also identify which outputs require review, and by whom, she added.
Hold Vendors Accountable
‘We are so excited about some of the capabilities being delivered to credit unions,” Anthony told the meeting. “Don’t ask your vendor, ‘Is this tool safe?’ They will say yes. Make them prove to you that that is indeed true.”
Anthony said credit unions should ask:
- What does this AI feature do in our workflow?
- Who owns the data?
- Is your tool going to learn from our data?
- If there is an incident, what are you going to do in this situation? “I’ve seen incidents in which vendors shut down and leave you in the cold.”
- How do we stop using it?
- How do you back this out of your workflow?
- How will you support an incident?
Practice the first Hour
“This year make your tabletop about an AI tool or capability and what you will do,” Anthony advised.
She urged credit unions to:
- Discuss unapproved staff use
- Name an incident leader
- Convene the right team
- Keep one decision log. “There needs to be one source of truth. Take notes with time and date stamps on what occurred and what decisions were made.”
- Protect the member





