Invest1 distinct publisher3 min readPublished
Eighteen percent of credit unions rate AI model risk a critical or high threat against 62% of national banks, yet 71% say they are not prepared, within two points of the national banks' 73%, a pattern that points to a difference in belief, not in staffing.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
Subtract readiness from concern and the segments stop resembling each other: credit unions leave 53 points between the 71% who say they are not prepared for AI model risk and the 18% who rate it a critical or high threat [1][2][1], where national banks leave 11 [2], community banks 11 and midsized banks 8 [3]. Two points separate credit unions from national banks on whether they are ready, and 44 points separate them on whether it matters [6].
The mechanism Javelin Strategy & Research's Tracy Goldberg names is what makes that belief expensive: credit unions often work with third-party vendors and assume the vendor is managing the AI risk [3]. Model risk here means a model performing poorly or outside its programming or training, leading to bad decisions or financial risk [4], and the decision still leaves the building under the credit union's name. Cornerstone Advisors' John Meyer supplies the concrete version his clients are already asking about: whether alternative credit decisioning carries a bias that creates fair lending or UDAAP problems [5], and where large language model data sits, down to whether a meeting notetaker parks member-services discussion in Europe or lets it train on other call data [6].
One alternative reading is that the 18% reflects calibration rather than complacency. A credit union running a handful of vendor models on narrow tasks does face less model surface than a national bank running hundreds, and "not prepared" is a cheap thing to concede in a survey where almost nobody claims to be prepared. The figure that would settle it is a model inventory by charter type, which the research as reported does not provide; nor does it break out the 63% of institutions raising budget, staff or tools for AI model risk over the next twelve months [7], the single largest destination for new risk spending and five points ahead of external fraud at 58% [7]. So whether credit unions sit inside that two-thirds or outside it is not knowable from here.
What an 18% rating reliably shows is that the money is going elsewhere. Teachers Federal Credit Union's Brad Calhoun frames the biggest risk as failing to prepare rather than moving too fast [8], and points to collaboration as the substitute for resources the largest banks have and credit unions do not [9]; Patelco's Kal Majmundar describes building governance and expertise in at the front end, across a stack that mixes in-house platforms with outside partners [10]. Both are describing documentation work, or rather the unglamorous half of it: model inventories, validation files, bias testing on decisioning models. That work is invisible until somebody asks for it, and it competes for budget with fraud tooling that shows a return this quarter. The 71% figure looks like the honest one; the 18% figure is more likely to be the one that gets revised, most likely by whoever first asks a credit union to produce the validation file behind an alternative credit model. If those inventories turn out to be as thin as the low concern rating implies, then the rating was accurate and the readiness answer was just modesty.
Ranked by verification strength, evidence, and original report placement.
Only 18% of credit union respondents say AI model risk is a critical or high threat, compared to 62% at national banks, 54% of midsized banks and 50% of community banks.
Seventy-one percent of credit unions say they aren't prepared for the AI model risk threat, compared to 73% of national banks, 62% of midsized banks and 61% of community banks.
Credit unions often work with third party vendors and assume the third party will manage AI risk, which Tracy Goldberg, director of cybersecurity at Javelin Strategy & Research, calls a dangerous assumption.
AI model risk refers to a machine learning or AI model performing poorly or outside of its programming or training, leading to bad decisions or financial risk.
John Meyer, a managing director at Cornerstone Advisors, said credit union clients are asking about AI models, particularly whether alternative credit decisioning carries a bias that causes issues with fair lending or UDAAP compliance.
Meyer said other model concerns, especially with large language models, centre on data privacy and where data is stored, citing the need to vet even simple tools such as meeting notetakers so data is not stored in Europe or used to train on other call data, since internal credit union meetings cover member services and differentiation.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
SBA's proposed size standards pour 114,500 firms into a fixed $182 billion set-aside pool1 distinct publisher
invest
Washington steps back on BNPL, so Brussels now sets the underwriting floor1 distinct publisher
invest
Model the correspondent line as a decaying annuity, not fixed plumbing1 distinct publisher
invest
FinCEN's Banque Misr action reaches past the three U.S. banks that hold the accounts1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One proprietary survey, no methodology
Every percentage in this story — the 18%, the 71%, the 63% — traces to research American Banker owns and has not shown: no sample size, no respondent counts by segment, no field dates, and no second outlet has looked at it. The named quotes from Teachers FCU, Patelco, Javelin and Cornerstone are on the record and specific, which is the stronger half of the evidence. The weaker half is that the arithmetic doing the interpretive work cannot be audited, and the published copy breaks off mid-sentence twice, once losing the supporting statistic about bankers unsure of their own model inventories.
Intent booked, controls scarce
Strip out the survey and what is actually in place is one institution and one absence: Patelco describing a hybrid of in-house platforms and outside partners with governance at the front end, and Cornerstone saying it has yet to meet a vendor whose models an outside firm has validated. The 63% budgeting more for model risk is a twelve-month promise, and the practice standing in for validation today is asking vendors to sign an attestation. That is an early market, not a deployed one.
The word "gap" is doing unearned work
Calling this a risk gap presumes credit unions are underrating a danger they equally face, and the survey never establishes that they run comparable numbers of models — a smaller model footprint would explain a lower threat rating without any complacency at all. Against that, the piece is notably unpuffed: no product is being sold in it, and the loudest voice, Teachers FCU's Calhoun, argues for preparation rather than urgency. Mild overstatement in the framing, not in the reporting.
Everyone quoted sells into the worry
Javelin sells cybersecurity research, Cornerstone sells third-party risk advisory and is actively telling clients to rewrite vendor contracts, and American Banker is publicising a survey it owns and monetises. The two credit union executives have a reputational interest in appearing prepared. None of that makes the 18% wrong, but no voice in this story gains from the number being reassuring — and the one testable assertion against interest, Cornerstone admitting it has found no validated vendors, cuts against its own recommendation.
Direction believable, magnitude unverifiable
That credit unions worry less about model risk than national banks while reporting similar unreadiness is easy to credit and consistent with everything the practitioners here describe. The size of the split, though, comes from one survey we cannot inspect, and the story's most consequential idea — that perception trails exposure — is inference layered on top. Enough to act on cautiously as an operator; not enough to quote as a settled measurement.