
Meet the Authors
Shadow AI in finance is growing as employees adopt AI tools faster than governance, procurement, and security controls can keep pace.
Unauthorized AI use can expose sensitive financial and customer data even when organizations already provide approved enterprise AI tools.
CFOs need greater visibility into actual AI use as finance, IT, security, procurement, and compliance share responsibility for AI governance.
An employee at CB Financial Services, the parent of Community Bank, entered non-public customer data, including names, Social Security numbers, and dates of birth, into an unauthorized AI tool. The bank discovered the incident on May 5, decided within two days that it was material, and filed an SEC Form 8-K on May 11. No hacker was involved. The incident brought the bank into overlapping SEC disclosure, prudential-regulator notification, and customer-notification requirements, offering a preview of a broader governance problem as finance organizations adopt AI faster than procurement, security, and compliance functions can track it.
What Shadow AI Actually Is
Shadow AI describes AI use that takes place outside an organization’s approved or monitored environment. That can mean a personal AI account, a standalone tool adopted without IT review, or an AI capability added to software the organization already uses.
CB Financial illustrates the first problem particularly well. The bank had already made an approved AI tool available, yet the employee still reached for one it had not cleared. Sanctioned enterprise AI does not close the gap on its own because employees can still choose other tools based on convenience, familiarity, or the immediate task in front of them.
The category is also expanding as AI becomes embedded inside existing software. Global Banking & Finance Review highlights the risk that applications already approved by an organization can acquire new AI features and permissions over time. That creates a different visibility problem: the software itself may be sanctioned even when its newer AI capabilities have not been separately assessed.
Shadow AI, then, is not simply employees secretly using chatbots. It is a gap between the AI an organization believes it governs and the AI its workforce can actually access.
Why Finance Is Particularly Exposed
Finance teams routinely handle sensitive customer, transaction, reporting, forecasting, and compliance data. At the same time, employees have strong incentives to use AI to summarize documents, prepare presentations, analyze information, and accelerate repetitive work.
The CB Financial incident shows how ordinary employee behavior can create serious exposure without an external attack or compromise of core systems. American Banker reported that the bank’s existing controls did not prevent customer information from being entered into the unauthorized application, illustrating how data can leave governed environments through everyday workflows.
The wider problem is a growing gap between AI adoption and the controls meant to govern it. Finance teams are being encouraged to use AI to work faster, but governance, procurement, data management, and ownership models are not always developing at the same pace. That creates room for shadow AI to emerge alongside existing problems such as fragmented data, technical debt, and unclear accountability.
There is also a model-governance gap. Financial institutions may have mature processes for reviewing and monitoring AI systems that are formally deployed, while having far less visibility into tools employees adopt independently. Shadow AI can therefore sit outside established model inventories, leaving governance processes unable to assess technology the organization does not know is being used.
What CFOs Should Do
The first requirement is visibility. Finance leaders need to understand which AI tools employees are actually using, what information is entering them, and which new AI capabilities are appearing inside software the organization already owns.
CB Financial’s experience shows why policy and approved technology alone are insufficient. The bank already offered a sanctioned AI tool. After the incident, it blocked domains associated with unapproved applications, tightened access to customer information, and expanded its data-security policies.
Governance also has to account for why employees move outside approved channels. Slow procurement, unclear policies, and difficulty accessing sanctioned tools can encourage employees to find their own alternatives. Providing practical approved options is therefore part of controlling shadow AI, not separate from it.
Organizations also need to revisit AI capabilities appearing inside existing software rather than assuming a previous vendor approval covers every feature added later. That requires coordination across finance, IT, security, procurement, and compliance because no single function has a complete view of AI usage, data exposure, spending, and regulatory obligations. Shadow AI is exposing the gaps between those functions.
What This Means for SAPinsiders
- Routine AI use can create material consequences. The CB Financial incident did not require a hacker or compromised core system. One employee moving sensitive information into an unauthorized tool was enough to create disclosure and notification issues.
- Approved AI does not eliminate shadow AI. Finance teams need visibility into what employees actually use, not simply an inventory of the AI products the organization has purchased.
- Governance has to extend beyond standalone tools. AI capabilities can also appear inside software already in the enterprise environment, requiring finance, IT, security, procurement, and compliance teams to reassess what is actually being used and where sensitive data is going.



