Credit Unions Are Less Worried About AI Model Risk Than Banks Are. That Should Worry You a Little
New research from American Banker turned up something worth sitting with. Only 18% of credit union respondents said AI model risk, meaning the risk of an AI model behaving incorrectly or drifting outside the boundaries it was trained on, counts as a critical or high threat. Banks, surveyed the same way, were meaningfully more likely to rate that same risk as high.
That gap could mean a couple of different things, and it's worth being honest that only one of them is reassuring.
Two explanations, and only one holds up well
The generous read is that credit unions have simply been more careful, deploying AI in narrower, lower-stakes ways than banks have, so the risk genuinely is lower for them today. There's some truth to that. Community financial institutions have historically moved a step behind the largest banks on model-heavy technology, partly by necessity and partly by design.
The less comfortable read is that credit unions are underestimating a risk that's about to grow fast, not staying flat. Separate research this year found that roughly two-thirds of credit unions now plan to use AI for credit decisioning, a very different risk category than a chatbot or a back-office automation tool. A model that's wrong about whether to approve a loan doesn't just create inefficiency. It creates member harm, fair-lending exposure, and exactly the kind of "model performing outside its training" scenario the American Banker research was asking about in the first place.
Why the gap probably isn't really about risk appetite
Teachers Federal Credit Union CEO Brad Calhoun put it plainly in the research: the decisions credit unions make today about AI, governance, and risk will shape both their competitiveness and their members' trust for years to come. That's not a call for caution over adoption. It's a call for the governance conversation to keep pace with the adoption conversation, which is usually where the real gap sits. Most institutions don't rate a risk as low because they've carefully concluded it's low. They rate it as low because nobody's formally reviewed it yet, and a survey response reflects that absence of review as much as it reflects an actual risk assessment.
A reasonable next step
The useful move here isn't to panic about a survey statistic. It's to ask a concrete internal question before your credit union expands AI further into lending: who inside your organization has actually reviewed what happens when one of your AI-assisted credit decisions goes wrong, and what "wrong" would even look like before it shows up in a complaint or an exam finding. If nobody can answer that today, the 18% figure isn't describing your risk level. It's describing how much of that risk conversation hasn't happened yet.
Sources