Artificial Intelligence & Machine Learning
,
Governance & Risk Management
,
Next-Generation Technologies & Secure Development
Bank Filing Shows Why Unauthorized Tools Belong in Cyber Response Plans

Frontier artificial intelligence models have made the news for their potential as weapons in the hands of cyber attackers. But AI risks could be walking in the front door – through creating regulatory and legal nightmares for enterprises.
See Also: Why an AI Harness May Matter More Than the Latest Model
Community Bank in Pennsylvania became the first company to publicly file a report to the U.S. Securities and Exchange Commission earlier this year in response to a shadow AI incident when it was discovered that an employee had used an unauthorized AI tool to handle customer data that included customer names, Social Security numbers and dates of birth.
No hacker accessed corporate networks, and there was no system outage to resolve. But parent company CB Financial Services determined the data exposure crossed the reporting threshold for a cybersecurity incident.
The company had four days to file an Item 1.05 Form 8-K, which it did on May 7, 2026, just two days after the incident. The incident had no material impact on earnings, the bank said.
The Community Bank incident should be a wakeup call for CIOs, CISOs, corporate counsels and other business leaders. Shadow AI use is expanding in organizations and it is creating a new category of risk at a time when the SEC is considering whether to streamline disclosure requirements for public companies.
SEC Chair Paul Atkins launched a comprehensive review of Regulation S-K in January, arguing that disclosures should focus more closely on information that a reasonable investor would consider important. The comment period formally ended April 13, although the SEC has continued accepting and posting submissions. The commission has not yet changed the cybersecurity disclosure rules, which currently require companies to report a material cybersecurity incident within four business days of determining that it is material.
Even if the SEC does loosen the reins when it comes to cybersecurity incident disclosure, experts say companies will need to stay vigilant. Risk and exposure is expected to grow as AI tools and agents proliferate. State breach laws, sector-specific rules, privacy regulators and class-action litigation will continue to shape how companies respond to cyber and AI incidents.
Amy Worley, managing director and data protection officer at Berkeley Research Group, said today’s environment is “differently regulatory,” rather than deregulatory. Companies may get relief at the federal level, but their overall risk profiles will remain high.
“There’s more state law, there’s more state attorney general action and there’s more private litigation risk,” Worley said.
A Breach Without a Hacker
The CB Financial incident illustrates the ways in which AI is transforming the corporate landscape and traditional notions of cybersecurity. A breach is no longer necessarily about a hacker getting in. It could happen when employees use unauthorized AI.
It’s a question of data, said Shawn Tuma, a cybersecurity and data privacy attorney at Spencer Fane.
“Regulators generally don’t care about our company’s cybersecurity for the sake of our company’s cybersecurity,” Tuma said. “It’s for the sake of the data that we are entrusted to protect.”
Breach laws may differ from state to state, but many are triggered when protected personal information is compromised in some way, such as an employee uploading a spreadsheet of customer data into a shadow AI application. “It doesn’t have to be a hacker,” Tuma said. “All it has to be is something that poses a material risk to sensitive data.”
In the event of an incident, an organization may need to notify customers, state attorneys general and other regulators. Those notifications can attract the attention of attorneys, which could lead to lawsuits.
Worley said state laws add another layer of complexity because different states define a breach in different ways. Some focus on the unauthorized acquisition of information, while others include unauthorized access. Many regulations allow companies to avoid notification, if there’s a documented determination that the incident is unlikely to cause harm. But when Social Security numbers and birth dates are involved, the bar is raised automatically.
That data is the “crown jewels of identity theft,” Worley said.
The Matter of Materiality
Determining whether a shadow AI incident is material forces companies to look beyond immediate operational disruption or financial loss, experts say, even if the SEC does loosen requirements.
“What they’re still looking for is what is a material risk to the company that justifies notifying the investors, so that your common everyday investor has the benefit of the same amount of information that a company insider would know? How do we put them on a level playing field?” Tuma said.
Cybersecurity, privacy and AI incidents occur inside companies every day, he said. Most are contained and resolved without becoming significant to investors. The threshold may be crossed when an incident is likely to generate meaningful financial losses through customer notification, regulatory scrutiny, remediation, lawsuits or business disruption.
“The SEC will and should continue to encourage and require disclosures like this,” he said.
For public companies, Tuma said the materiality analysis must be part of incident response from the beginning. A technical response team will naturally focus first on affected data, compromised systems, business disruption and containment. But the company also needs legal, finance, communications and business leaders involved early enough to determine whether the event may be material.
Companies should test that process through tabletop exercises that include shadow AI, embedded AI and unauthorized data transfers, Tuma said.
“You’ve got to build in your materiality determination from the outset as part of your incident response preparation and tabletop it,” he said.
Waiting until a technical investigation is substantially complete to notify the disclosure committee could leave the organization struggling to meet the SEC deadline.
Alla Valente, principal analyst at Forrester, said disclosures are also complicated by the fact that downstream consequences can take months or years to understand, as exposed information could eventually affect customers or business partners, produce reputational damage or lead to a multimillion-dollar class action litigation.
“Even with this regulatory ambiguity – and maybe it’s because of it – we’re seeing this escalation in litigation,” Valente said. “When organizations aren’t quite sure what the rules say, those rules are tested in a court of law.”
The litigation concern is often a greater threat to organizations than any regulatory penalty, she said. “When you get taken to court, even if you win, you lose,” she said. “The longer the lawsuit continues, the more you have to pay attorneys and pay for motions.”
Adding potential damages to that bill can often be enough to make companies err on the side of caution, she said, even when cases never make it to trial.
“They’re settling for larger amounts, because during discovery, both sides have to turn over evidence,” Valente said. “You might be turning over information that is embarrassing, or maybe they’re turning over information that can be viewed as potentially intellectual property. And at that point, [it makes sense] to settle.”
Worley said litigation is the big driver these days.
“You have decreased certainty and heightened litigation risk. And so I don’t think companies are in a better position than they were before,” Worley said. “It’s less certain what you need to do to be compliant, because you don’t have the predictability of, ‘here’s the regulation, follow this.’ And the litigation is going nuts.”
Governance and Third-Party Risk
When it comes to shadow AI, the greatest challenge a company faces is: You can’t govern something you can’t see.
“Shadow AI often emerges when employees don’t have clear, trusted ways to use approved AI tools,” said Nirupama Suryanarayanan, CTO for risk and regulatory platform at PwC. “Making responsible AI the easiest option is one of the most effective controls an organization can put in place.”
Valente said shadow AI should be considered a third-party risk because companies are relying on external models, data, open-source components and service providers. Another blind spot is embedded AI, in which an existing software supplier adds AI capabilities to a product that was originally approved and assessed for a different purpose.
“Today every vendor is an AI vendor, especially if you are deploying any of their AI features,” Valente said. “We need to look at shadow AI in the same context as embedded AI, and get a clear understanding of the AI that is coming in through third parties.”
Open source, she said, may be free of cost, but “that doesn’t mean it’s free of risk.”
AI agents add another dimension because they can move between databases and applications autonomously, often through API connections that conventional identity tools may not fully trace, Worley said. Conventional identity tools may not be up to the job.
“There’s just a real lack of transparency and traceability in how these things are typically configured,” she said. “Security teas really need to be thinking about education – making sure, one, that the security team itself is educated about how agents present new risks, and then also making sure that their executives are ready to educate their boards.”
Suryanarayanan said the organizations making the most progress are those connecting AI governance with data governance, cybersecurity, compliance and enterprise risk management.
“Responsible AI depends on visibility, governance and connected data, not policies alone,” she said.
Creating more risk-averse systems will require education and training, Tuma said.
“I don’t think people are paying enough attention to how fast this is moving, and how quickly what we know today and yesterday is being outdated,” he said. “Because the one common denominator in so much of AI risk is still the human element. And we just can’t develop tools fast enough.”
For CIOs, the Community Bank story shows that the rules for AI can’t be written once an incident is discovered. Governance must come first.
Organizations need visibility into the AI tools already being used, clear policies backed by technical controls and approved alternatives that employees can use without slowing down their work. They also need incident response plans that bring security, legal, finance, communications and business leaders together early enough to assess materiality and meet multiple reporting deadlines.
The SEC may ultimately narrow or simplify its cybersecurity disclosure requirements, but that will not make shadow AI incidents less damaging or easier to manage. Companies will still face overlapping state breach laws, industry-specific reporting rules, privacy obligations and litigation risks that can turn an employee’s use of an unauthorized tool into an expensive public mistake.
The CIO mandate is to build visibility, governance and incident readiness around the risks their organizations actually face, not merely the minimum requirements regulators ultimately decide to retain.
“These rules, these regulations, are your minimum operating requirements,” Valente said. “It’s like that seatbelt you use when you get into the car. In many cases, it’s better than not having anything, but there are still risks outside of that. If the brakes aren’t working, or the driver is impaired, or there’s a Mack truck coming at you, that seatbelt is not enough.”
