Tandem's seventh annual Cybersecurity GRC Report shows AI governance lagging behind adoption, with 27% of institutions discovering unapproved employee AI use.
Lubbock, TX – October 8, 2026 – Half of U.S. financial institutions (50%) have formally approved AI tools for use, up from 27% a year ago, according to the 2026 Cybersecurity GRC Report for the Financial Institution Industry released by Tandem. Over the same period, the number of institutions prohibiting AI fell from 32% to 9%.
Now in its seventh year, the report draws on responses from 306 cybersecurity, risk management, and compliance professionals at banks, credit unions, and other financial institutions across the United States.
Ninety percent of respondents reported having an approved AI policy. Still, 57% listed lack of AI governance and control as a concern, and 27% discovered employees using AI tools in unapproved ways during the past 12 months. Shadow AI was reported more often at institutions that have approved or are testing AI (30%) than at those that have not (17%), which may reflect greater visibility as well as greater use.
AI is also showing up in fraud and in examinations. Sixteen percent of institutions reported a fraud incident involving AI-generated content, such as deepfakes, voice cloning, or synthetic identities. AI was named a top examination priority by 12% of respondents, up from 4% in 2025.
Vendor AI oversight is uneven. While 53% evaluate a vendor's AI use during selection, 38% review it only informally, do not assess it, or do not know whether it is assessed.
The full report, with recommendations for each topic, is available for download at https://tandem.app/state-of-cybersecurity-report.
Tandem invited participants through its email communications between June 1 and August 3, 2026. All 306 respondents work for U.S.-based financial institutions: 74% at banks, 21% at credit unions, and 5% at other institutions. Fifty-six percent work at institutions with less than $1 billion in assets. Responses were self-reported and not independently verified, and year-over-year comparisons draw on separate samples.
Tandem, LLC is one of four companies owned by CoNetrix, LLC. Tandem builds information security governance, risk management, and compliance (GRC) software used by more than 1,800 organizations to run their risk assessments, policies, vendor management, incident response, and business continuity planning. Tandem's experts monitor regulatory changes and update the software so institutions can walk into their next audit or exam prepared. Learn more or watch a demo at https://tandem.app.
info@tandem.app
844-698-9800