SYDNEY, Australia—Geopolitical conflict, state-sponsored cyberattacks, artificial intelligence and emerging digital payment systems are creating new risks for credit unions while also offering opportunities to improve service to members, financial cooperative leaders said during a panel discussion at the World Credit Union Conference.
The session was moderated by Paul Andrews, vice president of international advocacy for the World Council of Credit Unions.
Panelists included:
- Scott Simpson, president and CEO of America’s Credit Unions.
- Fabíola da Silva Nader Motta, superintendent of OCB Brazil.
- Jeff Guthrie, CEO of the Canadian Credit Union Association.
- Anthony Hughes, president and CEO of Teachers Mutual Bank.
The following is an edited transcript of the discussion. Comments have been edited for grammar, punctuation and clarity, but not for length or substance.

Andrews: When I think about geopolitical issues, I think about cyberattacks, ground wars, air wars, trade escalations and trade fragmentation. We are also seeing an increase in targeted, government-sponsored cyberattacks from around the world that affect every organization and institution represented in this room, as well as those that are not represented here.
What about financial sovereignty, particularly as it relates to digital currencies? We are seeing products such as stablecoins become increasingly prevalent, and we are seeing new laws being adopted around stablecoins. As these global payment rails emerge, how should credit unions and cooperatives approach the issue and create an environment in which members can take advantage of the technology while also being protected?
Simpson: I think our membership is watching this emerging technology and the potential for deposit flight. What would happen if the payment rail system on which we rely were to change?
I have to acknowledge that the U.S. system is not monolithic. We have a dual-chartering system, and that is something we tend to want to protect. We believe that diffuse regulatory structure benefits and protects the credit union sector, but it also makes the implementation of things such as central bank digital currencies, or CBDCs, and new payment rail systems difficult.
Our biggest concern with the creation of the GENIUS Act is making sure credit unions fit within the framework. The credit union sector is very large in the United States, but it represents only about 9% of the country’s financial assets, deposits or loans. We need to make sure the regulatory structure, as it is drafted, includes credit unions and recognizes the distinctions that apply to credit unions.

Implementation beyond that is also going to be very challenging. In the rulemaking process, we have multiple regulators operating horizontally, as well as regulators at the state level. We need to make sure that, as the rulemaking process moves forward, it does not lose the tone or intent of the original legislation. We are living through the middle of that process right now.
Hughes: In Australia, we recently introduced something called the Digital Assets Framework, which brings digital assets into our regulatory environment. It covers custody providers, payment providers, stablecoins and other digital assets.
We have not yet reached the point of introducing a central bank digital currency, but the framework brings these other products into the regulatory environment. First and foremost, I think that is important.
There are some really exciting emerging payment technologies. We look at them from the perspective of whether they translate into faster and safer payments, lower transaction costs, more convenient access or faster settlement. Those are genuine benefits.
At the same time, emerging technologies clearly present some threats. Tokenized deposits are issued by banks, so they fall within the regulatory environment. Stablecoins are typically issued by private institutions, and I think the risks associated with that difference have been highlighted.
We look at stablecoins and other emerging payment technologies as another opportunity to serve our members, but we also recognize some of the threats they represent, particularly as they relate to the potential effect on available deposits.
Banks perform a very important role by accepting deposits, taking risks, lending money and helping their customers and communities. There are risks if emerging payment systems undermine that role. We have also seen risks in overseas jurisdictions where central bank digital currencies have been launched.
We currently benefit from traditional payment guardrails. We have real-time payments for members that provide speed, convenience and safety, and we hope they ultimately deliver lower costs.
However, we also have to navigate these developments carefully and ensure that we do not weaken the extremely important relationship with members that has been built on trust.

Da Silva Nader Motta: Stablecoins are not yet widely used by cooperatives. In Brazil, they face some regulatory limitations, so most credit unions remain focused on serving their members and communities.
For now, stablecoins are more of a future regulatory and innovation issue than an immediate priority. However, we believe the strategic direction is quite clear. We should not have to choose between global and national systems. We need infrastructure that connects people while protecting our members, their financial capabilities and their trust.
We must always be very clear that innovation has to create value. Innovations such as stablecoins and other digital technologies must make payments faster, less expensive and more accessible, especially across borders.
However, that efficiency cannot come at the expense of financial stability, consumer protection, transparency or the ability of national authorities to monitor financial flows.
Andrews: Is there any concern that stablecoins could become weaponized?
Guthrie: First, I recommend that everyone download the World Council’s white paper on stablecoins.
Every day, money is transferred across borders, and one of the major friction points involves international remittances. It is extremely important for credit unions to remain on top of this issue. When people are looking to send remittances home, they want as little friction as possible. I believe U.S. stablecoins are going to catch on with many people who want to send money home.
Regulators love to regulate. Members and consumers, however, look for the option that creates the least amount of friction when they are trying to solve a problem. Stablecoins can solve the problem of sending money very quickly through a platform that allows one hard currency to be exchanged for another.
Our members will find ways to use this technology.
Andrews: What about cybersecurity? What seems different today is the rise of state-sponsored cyberterrorism and AI-generated cyberterrorism. The threat appears to be quantitatively different from what institutions faced in the past.
I cannot help but think about some of the smaller institutions. How can they fight these threats when significant investments in technology are required? Does the cost and complexity simply create more pressure for consolidation?

Hughes: I do not want to speak for the entire sector, but I can imagine that almost every mutual bank in Australia—and possibly in the United States, Canada, Brazil and many of the other countries represented in this room—has identified cybersecurity as either the No. 1 risk on its risk framework or one of its top three risks.
We are all wrestling with it. We are all being challenged either to significantly redirect resources or to significantly increase investment.
One of the arguments we made just a couple of years ago was that small banks were small targets. We now have to take our cyber improvement plans and ask how we should plan for the future and what different operating models might look like.
Typically, in an era of AI, there are fewer skilled resources available in the market than institutions would like. That means the cost of obtaining expertise is high. For smaller institutions, it may not be practical or even possible to maintain all the necessary capabilities internally.
There is a hard road ahead, and we may need to move with greater speed because of the pace of technological change. We also have to consider what these new models expose in terms of our information assets. Even getting the basics right, including security patching, is difficult. It is hard to be small.
However, I think the cooperative model involves partnership. It involves using common vendors, sharing expertise and working together.
Andrews: How are you approaching cybersecurity from a regulatory perspective?
Da Silva Nader Motta: Cybersecurity is not an operational issue. It is a strategic issue.
It is becoming increasingly difficult to maintain the technology and make the continuous investments needed for AI-enabled projects and other evolving technologies.
That is where our networks and vertical cooperative systems in Brazil become a real advantage. Rather than facing cybersecurity challenges alone, our cooperatives work through their systems and networks to share business-impact analysis, technology, cybersecurity capabilities, fraud-prevention systems, monitoring and risk management.
When they share these platforms, they create scale while still preserving the local identity of each cooperative. When a threat is detected at one institution, an alert can be sent across the entire network. In other words, our information can move faster.
Of course, we understand that shared infrastructure can also create concentration risks. That is why we have to support the entire system with strong governance and clearly defined responsibilities for all the parties involved.
Our credit unions need to share information. They need to invest collectively. They need to train their employees and treat cyber resilience as a permanent responsibility of boards and executives.

We have been facing this challenge, and cybersecurity is not a competitive advantage that an individual institution should try to protect for itself. It is a shared responsibility throughout the system. When one cooperative becomes safer, we understand that the entire cooperative system in Brazil becomes stronger.
Guthrie: No small institution can do this alone. It starts by educating members about the risks they face and how they can protect themselves. It then requires institutions to work with partners, build the right capabilities around their particular risk levels and establish the right governance.
In Canada, we came to the realization two years ago that cybersecurity was not simply a credit union sector problem. It was an institutional and countrywide problem. It did not matter whether we had the best cybersecurity defenses if the telecommunications companies were not involved or if the social media platforms were not involved. We therefore put together a coalition involving all of those parties. We included law enforcement, government regulators and all of the organizations that are part of the infrastructure in which cybercriminals look for vulnerabilities.
We then extended the work all the way down to the individual citizen and made sure people understood the role they have to play. We all know cybersecurity is not a victimless crime. It may be a faceless crime, but it is not a victimless crime.
I think smaller institutions have an opportunity to work together and potentially become even more effective than the largest institutions.
Simpson: It is almost unimaginable to understand what our leaders and executives feel as they carry the responsibility for the life savings of—in some cases—millions of people on their backs. I worry about that.
To add to the discussion, I think there is an approaching inflection point that we are not talking about enough, and that is quantum computing.
Quantum computing is on the verge of moving beyond the theoretical stage and becoming operational. When artificial intelligence and quantum computing come together, the entire cryptographic universe on which we have relied will face a new level of risk.
I do not believe any government on Earth is devoting enough policy attention or financial resources to the issue. I think that risk could emerge within five years. We are not talking about it enough.




