Tandem's seventh annual Cybersecurity GRC Report shows AI governance lagging behind adoption, with 27% of institutions discovering unapproved employee AI use.

Lubbock, TX – October 8, 2026 – Half of U.S. financial institutions (50%) have formally approved AI tools for use, up from 27% a year ago, according to the 2026 Cybersecurity GRC Report for the Financial Institution Industry released by Tandem. Over the same period, the number of institutions prohibiting AI fell from 32% to 9%.

Now in its seventh year, the report draws on responses from 306 cybersecurity, risk management, and compliance professionals at banks, credit unions, and other financial institutions across the United States.

AI Policies Are in Place, but Oversight Is Still Catching Up

Ninety percent of respondents reported having an approved AI policy. Still, 57% listed lack of AI governance and control as a concern, and 27% discovered employees using AI tools in unapproved ways during the past 12 months. Shadow AI was reported more often at institutions that have approved or are testing AI (30%) than at those that have not (17%), which may reflect greater visibility as well as greater use.

AI is also showing up in fraud and in examinations. Sixteen percent of institutions reported a fraud incident involving AI-generated content, such as deepfakes, voice cloning, or synthetic identities. AI was named a top examination priority by 12% of respondents, up from 4% in 2025.

Vendor AI oversight is uneven. While 53% evaluate a vendor's AI use during selection, 38% review it only informally, do not assess it, or do not know whether it is assessed.

Additional Findings

    • 71% of institutions reported their Board does not include a director with formal cybersecurity expertise.
    • 67% run IT and cybersecurity with five or fewer full-time staff, and 78% of respondents hold two or more roles.
    • 35% experienced a significant impact from a third-party incident in the past 12 months, most often a service disruption.
    • Incident response plans received the fewest "very mature" ratings (33%) of the six program areas measured.
    • After the FFIEC CAT sunset in August 2025, the NIST Cybersecurity Framework became the most used framework (69%), though 27% still include the CAT in their assessments.
    • Institutions describing a strong cybersecurity culture rated their programs more mature in every area measured, including risk assessments (97% at least somewhat mature, compared with 77% for institutions with a developing culture).

The full report, with recommendations for each topic, is available for download at https://tandem.app/state-of-cybersecurity-report.

About the Survey

Tandem invited participants through its email communications between June 1 and August 3, 2026. All 306 respondents work for U.S.-based financial institutions: 74% at banks, 21% at credit unions, and 5% at other institutions. Fifty-six percent work at institutions with less than $1 billion in assets. Responses were self-reported and not independently verified, and year-over-year comparisons draw on separate samples.

About Tandem

Tandem, LLC is one of four companies owned by CoNetrix, LLC. Tandem builds information security governance, risk management, and compliance (GRC) software used by more than 1,800 organizations to run their risk assessments, policies, vendor management, incident response, and business continuity planning. Tandem's experts monitor regulatory changes and update the software so institutions can walk into their next audit or exam prepared. Learn more or watch a demo at https://tandem.app.

Media Contact

info@tandem.app
844-698-9800