Right now, somewhere in your institution, someone is asking about AI. Maybe it is your board. Maybe it is a frontline employee who started using Copilot on their own. Maybe it is you, reading the latest industry soundbite late at night and wondering how far behind you are.
You are not behind. But you do need a clear-eyed answer to that question, and that is what this article is all about.
We recently hosted two webinars on AI and Copilot in community banking. They drew the largest audiences of any online event we have ever put on: compliance officers, IT directors, CEOs, frontline managers, all showing up with the same urgency. The questions came in by the dozens across a spectrum of topics. We collected every one of them, and we promised to respond. What follows is that response.
Whether you were in those sessions or this is your first introduction to Navanta, the questions our community raised are almost certainly the same ones you are carrying. Beneath all the specifics about licensing tiers and agent sharing and data classification, nearly everyone was really asking the same thing.
Are we doing this right, and is it safe?
That is the question. Not “how do I build an agent” or “what is the difference between Basic and Premium.” Those are the next level questions. The real question, the one that every community banker I talk to is wrestling with, is whether they can pursue AI without putting their institution, their customers, or their people at risk.
The answer is yes. But only if you approach it the same way good bankers approach everything: with discipline, with a clear decision framework, and with the right partner.
Start somewhere real, not somewhere impressive.
The most common mistake we see institutions make is not moving too slowly. It is aiming too high, too fast. They want to begin with the most sophisticated use case, the one that will transform an entire workflow, and then they stall because the complexity outpaces their readiness. It is worth remembering that AI is a tool; not a solution. And like any tool, it is only valuable if it delivers better outcomes than what you had before. The measure is not how advanced the technology is. It is whether it makes something better.
Skip Richman, Vice President of IT and Information Security Officer at First Peoples Bank in Georgia, did not start with a complex banking operations use case. He started with vendor management. Specifically, the part of his job that consumed five to six hours every time a new vendor packet landed on his desk: reading through documentation, answering question after question, manually building a summary. He asked himself what was eating up his time. Then he asked whether AI could help with that specific thing.
It could. With Copilot and some well-crafted prompts, he brought that process down to fifteen minutes. He still reviews everything. He still owns the judgment and the outcome. But the grinding, repetitive extraction work? AI handles that now.
Take the first step. Just start. Make a prompt. Make sure your leadership is behind you. And begin.
That is Skip’s advice, and I will add to it: start with a discrete use case your team already understands completely. Not every AI interaction looks like a chat prompt — it might be a document review, an invoice comparison, or a summarization task built into a workflow your team already runs. What matters is choosing something where your team knows what good looks like. When you can recognize the mistakes, you can correct them. You can build trust in the output before you scale it.
Several of you asked specifically about Copilot: why Navanta focused on it and whether it is the right choice. We are not telling you Copilot is the only answer. We use Copilot, Claude, and other tools internally at Navanta. The AI landscape is evolving so fast that whoever holds the marquee position today may not in six months. What we are saying is that Copilot is the most accessible starting point for most of you, because Microsoft is already a trusted vendor in your environment. Vendor management is done. The tools integrate with Office applications your teams use every day. And at the M365 Business Premium level, which many of you already have, meaningful Copilot capabilities are available right now at no additional cost.
You asked whether Copilot runs on Claude, ChatGPT, or something else. Microsoft offers multiple underlying models, including Claude Opus, and users with the full M365 Copilot license can switch between them directly within the interface. The M365 Copilot Chat has no billable components and consumes no Copilot Credits (Microsoft’s equivalent of Tokens), so you do not need to worry about running out of prompts at the business licensing level.
On the difference between M365 Copilot Basic and Premium that some of you asked about:
- Basic includes Copilot Chat with the ability to attach and reason over documents within a session. It also provides a limited version of Copilot Notebooks.
- Premium, the full M365 Copilot add-on, integrates directly with your Microsoft 365 environment—including email, Teams, SharePoint, and OneDrive—and unlocks the full Copilot Notebook experience for multi-document analysis.
Start where you are. Build toward where you want to go.
Several of you also asked whether Navanta will offer more hands-on training, including a dedicated session on Agents and prompt building. The answer is yes. The interest has been clear and consistent, and we are finalizing a new service to support this request. Watch for announcements in upcoming emails and on our LinkedIn page.
The tools are only as safe as the governance around them.
This is where most of your questions landed. Getting this right is not optional for regulated institutions. It is the foundation for everything that follows.
Let me start with something Trisha Ackerman, CEO of Neighbors United Federal Credit Union, said in our first webinar. Her board and her staff both asked her two questions when she began exploring AI: Is my job going to be taken? And how do we guarantee that confidential information does not get out? Her answer to the second question was honest and worth repeating: there is no 100% guarantee. There never has been. You cannot guarantee that an employee will never carry a sensitive file out of a branch. You can only build the controls, the training, the policy, and the culture that make it unlikely, and make it detectable when it happens.
That is the right framework for AI security. Not a guarantee or single silver bullet, but a layered defense framework.
Governance is not a destination. It is a practice.
Several of you shared you are behind on your governance framework. You are gathering regulatory guidance, preparing risk assessments, and building policies. But that takes time, and in the meantime, Copilot is showing up in your Microsoft environment whether you asked for it or not.
I want to address that directly. I will start with what Emily Strickland, Navanta’s compliance and regulatory expert, said in our first webinar: there is no FFIEC handbook specifically on AI. What exists is a body of guidance, IT examination frameworks, model risk management expectations, and third-party risk standards that you are already operating under. AI does not change that framework. It expands its scope. The questions regulators will ask about an AI deployment are the same ones they already ask about any significant technology initiative: What are the risks? What are the controls? Who is accountable? How do you monitor it?
If you are in the gap between where you are and where your governance program needs to be, here is where to focus first:
- Publish an AI Acceptable Use Policy now. It does not need to be perfect. Define what employees can and cannot do, require formal acknowledgment, and commit to updating it as your program matures.
- Assign accountability. Someone needs to own AI governance in your institution. If you have not identified that person, that is the first gap to close.
- Require all users to undergo baseline AI training. Do not distribute Copilot broadly before your people understand the boundaries.
- Audit your Microsoft tenant. Know which AI capabilities are active. Document the decisions you make about each one.
- Document your rationale. Regulators increasingly want to see that AI decisions are tied to risk assessments, reviewed by appropriate leadership, and recorded, not just implemented.
One attendee told us that a regulator informed them Microsoft has made it impossible to disable Copilot in their environment. Setting aside the specifics of that claim, the concern it reflects is real. AI cannot be “turned off” – it is increasingly present across a variety of technologies, applications and environments. The right response to a capability you cannot fully disable is not resignation. It is governance and monitoring. Define what is permitted. Build the controls you can build. Train your people. Monitor usage. Document everything. That is how regulated industries have always managed technology risk, and AI is no different.
On sharing our own Copilot training program: yes, we will. We are formalizing what we are calling AI Enablement Solutions, including governance frameworks, acceptable use templates, and training resources built specifically for community financial institutions. Not generic AI guides. Resources built for your regulatory environment and your operational reality.
The question underneath all the questions.
I want to come back to where I started, because I think it matters.
One attendee asked whether AI is actually performing the employee’s job while the employee just watches.
At Navanta, we use AI to review 100 percent of our service call transcripts. Before, our QA team manually sampled a fraction of those transcripts each month. Today, AI evaluates every single one, assessing empathy, cadence, and adherence to our standards, and our QA team spends their time improving the operation rather than grading individual calls. We see the same shift happening at community financial institutions.
An IT team that once spent significant time monitoring for application updates, patching systems, and manually verifying that everything deployed correctly can redirect that attention toward strengthening the institution’s risk posture, evaluating new value-added business applications, and building the talent and strategy that moves the organization forward.
The updates still happen. AI handles the monitoring, alerting, and routine verification. The IT team handles the technology strategy, the risk decisions, and the work that requires institutional knowledge. Is AI doing their job? No. AI is doing the part of the job that was mundane and repetitive, so our people can do the part that requires judgment, expertise, and human relationship. That distinction matters enormously. Every institution deploying AI should be explicit about where that line sits in their own workflows.
Another attendee said something I suspect many community bankers feel but do not always say out loud: we hire bankers, not developers. How do you close the AI knowledge gap when your team has deep banking expertise but no technical background?
You do not have to be an AI expert. That is our job. What you need are guardrails, clarity, and a partner who treats safety the way a banker does: as non-negotiable.
Here is the thing: you do not need a DevOps engineer to use Copilot effectively. You need people who understand your workflows, your customers, your data, and your documents. That describes your team exactly. The skill that makes someone good at prompting AI is not technical knowledge. It is domain knowledge. A banker who understands a vendor contract deeply will write better prompts about that contract than a developer who has never read one. Your team’s banking expertise is not a gap. It is an asset. Start with what they know. Build confidence with low-risk, high-value tasks. Expand from there.
At Navanta, AI will enhance our relationship-first approach – making interactions more meaningful, effective, and empowering.
The questions you submitted across these two webinars told me something I already believed but was glad to see confirmed: community bankers are approaching AI seriously, thoughtfully, and with exactly the right instincts. You are asking about governance before capability. You are protecting your institutions and your customers even as you explore new tools. That is not caution born of fear. That is the instinct of good bankers doing what they have always done: moving carefully, on purpose, in the right direction.
You are not behind. You are asking the right questions and digging in to understand more. Navanta will continue to bring you practical resources, honest guidance, and the expertise to help you move forward safely and with confidence. I would love to hear where your institution is on this journey. Please feel free to reach out to me personally or your Navanta advisor, and let’s talk. We are building this together for 700 community financial institutions, all working towards the same goals.
More on AI
-
-
ARTICLES6 Things Every Community Financial Institution Needs to Know About AI Security
Read the Article -
ARTICLESFive Tips Beyond the Prompt: A Plain-language Guide to AI Agents, Notebooks, and Workflow Automation
Read the Article
