AI Artificial Intelligence
Standard wording or passing mentionDetail: GeneralSame as last period
CBNA · VA · Mid-size bank ($1B to $50B)
Total assets of FDIC-insured bank subsidiaries: $1.8B at the end of 2025
Filings on the SEC website · This bank on Bankgraph
| Report year | Using or planning AI | Explains how AI is controlled | Sees AI as a risk | Other mentions |
|---|---|---|---|---|
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 |
| In the 2025 report | This bank | Banks of its size |
|---|---|---|
| Using AI now | Yes | 26 of 221 (12%) |
| Explains how AI is controlled | Yes | 55 of 221 (25%) |
| Sees AI as a risk | Yes | 184 of 221 (83%) |
| Mentions generative AI | Yes | 112 of 221 (51%) |
| Mentions AI agents | No | 18 of 221 (8%) |
9 passages new in the 2025 report, 5 passages from the 2024 report no longer there.
AI Artificial Intelligence
AI Artificial Intelligence
AI Artificial Intelligence
•The development and use of artificial intelligence present risks and challenges that may adversely impact our business.
As a financial institution, we are susceptible to evolving cybersecurity threats, including attacks by cybercriminals, nation-state actors, insiders, and risks associated with rapid advancements in technology including developments in AI, machine learning, quantum computing, and other emerging technologies, which may compromise existing security measures. Fraudulent activity, information security breaches, and cyberattacks may target us, our service providers, or our clients, potentially resulting in financial losses, operational disruptions, unauthorized disclosure of sensitive or confidential information, misappropriation of assets, regulatory scrutiny, litigation, or significant reputational harm.
Fraudulent activity may manifest in numerous forms, including check fraud, electronic fraud, wire fraud, phishing, smishing, business email compromise, social engineering, identity theft, and other dishonest activities. Information security breaches and cybersecurity incidents may involve unauthorized access or compromise of systems used by us, our service providers, or our clients; denial-of-service or distributed denial-of-service attacks; ransomware; malware; insider-threats; exploitation of third-party vulnerabilities (such as cloud services, web browsers, or operating systems); attacks leveraging vulnerabilities in vendor supply chains or third-party software dependencies; AI-enhanced or deepfake-enabled impersonation techniques; quantum-enabled attacks on encrypted communications or stored data; physical damage to critical infrastructure; or human errors resulting in data leaks or system compromises. Several major corporations, including financial institutions, have experienced significant data breaches that exposed proprietary corporate information as well as sensitive financial and personal data of their clients and employees, heightening their vulnerability to fraud.
Our clients are also subject to growing risks related to identity theft, credit and debit card fraud, account takeover attempts, and unauthorized account access, including as threat actors increasingly deploy AI-automated or technologically sophisticated social-engineering schemes, particularly as technological advancements, such as quantum computing, threaten conventional encryption standards and protocols before quantum-resistant cryptographic solutions become widely adopted. We and our service providers have in the past been, and may in the future be, the target of electronic fraudulent activity, security breaches, and cyberattacks. Our extensive reliance on mobile and cloud technologies, as well as remote work arrangements, significantly expands our attack surface, increasing the risk of unauthorized access, data breaches, and cybersecurity incidents. Additionally, because we operate without a traditional branch network and instead rely heavily on digital channels, security breaches may disproportionately affect us compared to banks with multiple physical locations.
Rapid technological advancements — including quantum computing, AI, machine learning, and other advanced technologies — significantly increase cybersecurity threats by potentially enabling threat actors to more effectively decrypt sensitive information, circumvent authentication mechanisms, exploit vulnerabilities within our security infrastructure, or otherwise compromise our systems and these risks may be heightened until quantum-resistant standards are broadly implemented across the industry. Failure to promptly adapt to and effectively implement security measures in response to rapidly evolving technological threats could significantly heighten our risks of data breaches, financial fraud, operational disruptions, regulatory scrutiny, reputational harm, and financial losses.
Additionally, the rising sophistication of cyberattacks by criminal groups, state-sponsored entities, and vulnerabilities within third-party technologies could undermine critical security processes relied upon by us, our service providers, and our clients. Increasingly sophisticated AI-driven attacks could enable threat actors to more effectively predict and circumvent security protocols and detection systems, significantly escalating our cybersecurity risk.
The development and use of artificial intelligence present risks and challenges that may adversely impact our business.
We have incorporated, and may in the future further incorporate, AI technology in certain business processes, services, and products, including technologies that process sensitive financial and/or personal data. We currently rely on AI tools and models provided by third-party vendors, including through enterprise platforms that allow the creation of custom
configurations, prompts, or projects (such as custom GPTS or similar tools), and we do not currently develop proprietary foundational AI models for deployment in our operations, although we may configure or use approved tools in accordance with internal policies and controls. These AI technologies assist in drafting documents and communications, conducting research, and enhancing operational efficiency. Additionally, certain third-party vendors, clients, and counterparties may integrate AI technology into their own business processes, services, or products, which may directly or indirectly impact us.
The development and use of AI present a number of legal, regulatory, and operational risks to our business. The legal and regulatory landscape governing AI is highly dynamic, with evolving laws and regulations that include both AI-specific mandates and provisions within existing frameworks such as intellectual property, privacy, consumer protection, employment, and financial services laws. These changes could require modifications to our use of AI technologies, impose additional compliance burdens, and increase our exposure to regulatory scrutiny, enforcement actions, or litigation. For example, data privacy and security requirements under laws such as the Gramm-Leach-Bliley Act (“GLBA”) impose stringent obligations to safeguard consumer financial information, and the use of AI in processing such data may raise compliance challenges or expose us to legal liability, regulatory penalties, or other enforcement actions.
AI models, particularly generative AI models, may produce inaccurate, misleading, or unreliable outputs, inadvertently disclose private, confidential, or proprietary information, reflect biases embedded in training data, or generate content that is perceived as discriminatory, defamatory, or in violation of intellectual property rights. If AI-assisted or AI-generated outputs, including those from custom-configured tools, are relied upon in ways that are inaccurate, misleading, or inconsistent with applicable policies or legal requirements, we could face significant legal, financial, and reputational risks. Even where AI-assisted outputs are subject to human review, such review may not identify all errors or compliance concerns, particularly where outputs appear facially reasonable but are incomplete, biased, or contextually inaccurate.
Consistent with our internal policies, certain uses of AI, including custom-configured tools, may involve nonpublic personal information (“NPI”) or material nonpublic information (“MNPI”) for authorized roles and approved tools, subject to specified controls and human review requirements. Although we require human review of certain AI-assisted outputs and have implemented policies governing the appropriate use of AI and restrictions on the use of sensitive data, human review may not detect all inaccuracies, biases, inappropriate outputs, or compliance deficiencies. Employees could inadvertently or intentionally use AI tools in a manner inconsistent with applicable policies, controls, or legal requirements, and supervisory review processes may fail to identify such misuse in a timely manner or at all. Such misuse could result in the unauthorized disclosure of confidential information, regulatory penalties, legal liability, or reputational harm. We cannot assure that these policies and procedures will prevent all AI-related risks.
To the extent we rely exclusively on third-party AI providers and enterprise AI platforms, we may have limited visibility into how underlying AI models are developed, trained, or maintained. The proprietary nature of such models may restrict our ability to fully assess data sources, methodologies, and risk mitigation strategies employed by third-party AI providers. If an AI model incorporates unauthorized material, improperly sources training data, or fails to implement adequate controls against bias, discrimination, or intellectual property infringement, we may nonetheless be exposed to liability, regulatory scrutiny, or reputational harm arising for the model’s outputs, even where we lack visibility into or control over its development or training processes.
Additionally, AI-generated content could lead to regulatory and legal concerns if the outputs result in inaccurate, misleading, or deceptive communications. Regulations governing financial institutions may require institutions to provide accurate, non-misleading information in customer interactions, and if AI-generated outputs violate these standards, we could face regulatory scrutiny, penalties, or legal action.
Advancements in AI capabilities, including potential interactions with other emerging technologies, may further compound these risks. Such developments could accelerate data processing or automation while also increasing concerns regarding data privacy, security bias, or the misuse of synthetic or manipulated content for fraudulent or deceptive purposes.
Any of these risks could expose us to regulatory enforcement actions, civil liability, reputational damage, and erosion of client trust. Additionally, adverse public perception regarding AI risks, including concerns about bias, fairness, and privacy, could negatively affect our relationships with clients, vendors, regulators, and other stakeholders. If AI-related risks materialize, our business, results of operations, and financial condition could be materially and adversely affected.
Our governance framework for AI remains evolving, and regulatory expectations regarding financial institutions use of AI continue to develop, which may require further changes to our controls, monitoring processes, and documentation practices.
AI Artificial Intelligence
AI Artificial Intelligence
AI Artificial Intelligence
•The development and use of artificial intelligence present risks and challenges that may adversely impact our business.
As a financial institution, we are susceptible to evolving cybersecurity threats, including attacks by cybercriminals, nation-state actors, insiders, and risks associated with rapid advancements in technology such as quantum computing, sophisticated artificial intelligence (AI), and other emerging technologies, which may compromise existing security measures. Fraudulent activity, information security breaches, and cyberattacks may target us, our service providers, or our clients, potentially resulting in financial losses, operational disruptions, unauthorized disclosure of sensitive or confidential information, misappropriation of assets, regulatory scrutiny, litigation, or significant reputational harm.
Rapid technological advancements — including quantum computing, artificial intelligence, machine learning, and other advanced technologies — significantly increase cybersecurity threats by potentially enabling threat actors to more effectively decrypt sensitive information, circumvent authentication mechanisms, exploit vulnerabilities within our security infrastructure, or otherwise compromise our systems. Failure to promptly adapt to and effectively implement security measures in response to rapidly evolving technological threats could significantly heighten our risks of data breaches, financial fraud, operational disruptions, regulatory scrutiny, reputational harm, and financial losses.
Additionally, the rising sophistication of cyberattacks by criminal groups, state-sponsored entities, and vulnerabilities within third-party technologies could undermine critical security processes relied upon by us, our service providers, and our clients. Increasingly sophisticated AI-driven attacks could enable threat actors to more effectively predict and circumvent security protocols and detection systems, significantly escalating our cybersecurity risk.
The development and use of artificial intelligence present risks and challenges that may adversely impact our business.
We have incorporated, and may in the future further incorporate, AI technology in certain business processes, services, and products, including technologies that process sensitive financial and/or personal data. We rely exclusively on third-party AI models developed by external providers and do not develop, modify, or train proprietary AI models in-house. These AI technologies assist in drafting documents and communications, conducting research, and enhancing operational efficiency. Additionally, certain third-party vendors, clients, and counterparties may integrate AI technology into their own business processes, services, or products, which may directly or indirectly impact us.
The development and use of AI present a number of legal, regulatory, and operational risks to our business. The legal and regulatory landscape governing AI is highly dynamic, with evolving laws and regulations that include both AI-specific mandates and provisions within existing frameworks such as intellectual property, privacy, consumer protection, employment, and financial services laws. These changes could require modifications to our AI implementations, impose additional compliance burdens, and increase our exposure to regulatory enforcement and litigation. For example, data privacy and security requirements under laws such as the Gramm-Leach-Bliley Act (“GLBA”) impose stringent obligations to safeguard consumer financial information, and the use of AI in processing such data may raise compliance challenges or expose us to legal liability, regulatory penalties, or other enforcement actions.
AI models, particularly generative AI models, may produce inaccurate, misleading, or unreliable outputs, disclose private, confidential, or proprietary information, reflect biases embedded in training data, or generate content that is perceived as discriminatory, defamatory, or in violation of intellectual property rights. If AI-generated outputs are relied upon for business decisions or client interactions, we could face significant legal, financial, and reputational risks.
Although we have implemented policies requiring employees to review AI-generated content for accuracy, relevance, and completeness, and prohibiting the use of personally identifiable or nonpublic information with AI technologies unless expressly authorized, employees could inadvertently or intentionally upload personally identifiable client data into third-party AI models in violation of the GLBA or other applicable privacy laws, potentially leading to unauthorized disclosure of confidential client information, regulatory penalties, legal liability, or reputational harm. We cannot guarantee that employees will consistently adhere to these policies or that such policies will be sufficient to fully mitigate AI-related risks. Furthermore, AI technologies themselves may be susceptible to vulnerabilities that could result in improper disclosure, misuse, or unauthorized access to sensitive data.
Because we rely exclusively on third-party AI models, we do not have direct oversight or control over how these models are developed, trained, or maintained. The proprietary nature of these AI models means that we lack visibility into the data sources, methodologies, and risk mitigation strategies employed by third-party AI providers. If an AI model incorporates unauthorized material, improperly sources training data, or fails to implement adequate controls against bias, discrimination, or intellectual property infringement, we may be exposed to liability for the model’s outputs, despite lacking any control over its development.
Additionally, AI-generated content could lead to regulatory and legal concerns if the outputs result in inaccurate, misleading, or deceptive communications. Regulations governing financial institutions may require institutions to provide accurate, non-misleading information in customer interactions, and if AI-generated outputs violate these standards, we could face regulatory scrutiny, penalties, or legal action.
Advancements in AI capabilities, including potential interactions with quantum computing, may further compound these risks. Quantum-enhanced AI models could accelerate data processing but may also intensify concerns regarding privacy breaches, algorithmic bias, or the ability of AI-generated deepfakes or synthetic data to be used fraudulently.
Any of these risks could expose us to regulatory enforcement actions, civil liability, reputational damage, and erosion of client trust. Additionally, adverse public perception regarding AI risks, including concerns about bias, fairness, and privacy, could negatively affect our relationships with clients, vendors, regulators, and other stakeholders. If AI-related risks materialize, our business, results of operations, and financial condition could be materially and adversely affected.
Forward-looking statements include, among other things, statements relating to: (i) changes in trade, monetary and fiscal policies of, and other activities undertaken by, governments, agencies, central banks and similar organizations, including the effects of United States federal government spending and tariffs; (ii) the level of, or changes in the level of, interest rates and inflation, including the effects on our net interest income, noninterest income, and the market value of our investment and loan portfolios; (iii) the level and composition of our deposits, including our ability to attract and retain, and the seasonality of, client deposits, including those in the ICS® network, as well as the amount and timing of deposit inflows and outflows and the concentration of our deposits; (iv) our future net interest margin, net interest income, net income, and return on equity; (v) our political organization clients’ fundraising and disbursement activities; (vi) the level and composition of our loan portfolio, including our ability to maintain the credit quality of our loan portfolio; (vii) current and future business, economic and market conditions in the United States generally or in the Washington, D.C. metropolitan area in particular; (viii) the effects of disruptions or instability in the financial system, including as a result of the failure of a financial institution or other participants in it, or geopolitical instability, including war, terrorist attacks, pandemics and man-made and natural disasters; (ix) the impact of, and changes, in applicable laws, regulations, regulatory expectations and accounting standards and policies; (x) our likelihood of success in, and the impact of, legal, regulatory or other actions, investigations or proceedings related to our business; (xi) adverse publicity or reputational harm to us, our senior officers, directors, employees or clients; (xii) our ability to effectively execute our growth plans or other initiatives; (xiii) changes in demand for our products and services; (xiv) our levels of, and access to, sources of liquidity and capital; (xv)the ability to attract and retain essential personnel or changes in our essential personnel; (xvi)our ability to effectively compete with banks, non-bank financial institutions, and financial technology firms and the effects of competition in the financial services industry on our business; (xvii)the emergence, adoption and evolution of new technologies and payment methods, including stablecoins, digital assets, blockchains and other technologies based on distributed ledgers, and their effects on competition and our business; (xviii) the development, use and regulation of artificial intelligence, including by us, our vendors and our competitors; (xix) the effectiveness of our risk management and internal disclosure controls and procedures; (xx) any failure or interruption of our information and technology systems, including any components provided by a third party; (xxi) our ability to identify and address cybersecurity threats and breaches; (xxii) our ability to keep pace with technological changes; (xxiii) our ability to receive dividends from Chain Bridge Bank, N.A. and satisfy our obligations as they become due; (xxiv) the incremental costs of operating as a public company; (xxv) our ability to meet our obligations as a public company, including our obligation under Section 404 of the Sarbanes-Oxley Act; and (xxvi) the effect of our dual-class structure and the concentrated ownership of our Class B common stock, including beneficial ownership of our shares by members of the Fitzgerald Family.
Forward-looking statements include, among other things, statements relating to: (i) changes in trade, monetary and fiscal policies of, and other activities undertaken by, governments, agencies, central banks and similar organizations, including the effects of United States federal government spending and tariffs; (ii) the level of, or changes in the level of, interest rates and inflation, including the effects on our net interest income, noninterest income, and the market value of our investment and loan portfolios; (iii) the level and composition of our deposits, including our ability to attract and retain, and the seasonality of, client deposits, including those in the ICS® network, as well as the amount and timing of deposit inflows and outflows and the concentration of our deposits; (iv) our future net interest margin, net interest income, net income, and return on equity; (v) our political organization clients’ fundraising and disbursement activities; (vi) the level and composition of our loan portfolio, including our ability to maintain the credit quality of our loan portfolio; (vii) current and future business, economic and market conditions in the United States generally or in the Washington, D.C. metropolitan area in particular; (viii) the effects of disruptions or instability in the financial system, including as a result of the failure of a financial institution or other participants in it, or geopolitical instability, including war, terrorist attacks, pandemics and man-made and natural disasters; (ix) the impact of, and changes, in applicable laws, regulations, regulatory expectations and accounting standards and policies; (x) our likelihood of success in, and the impact of, legal, regulatory or other actions, investigations or proceedings related to our business; (xi) adverse publicity or reputational harm to us, our senior officers, directors, employees or clients; (xii) our ability to effectively execute our growth plans or other initiatives; (xiii) changes in demand for our products and services; (xiv) our levels of, and access to, sources of liquidity and capital; (xv) the ability to attract and retain essential personnel or changes in our essential personnel; (xvi) our ability to effectively compete with banks, non-bank financial institutions, and financial technology firms and the effects of competition in the financial services industry on our business; (xvii) the emergence, adoption and evolution of new technologies and payment methods, including stablecoins, digital assets, blockchains and other technologies based on distributed ledgers, and their effects on competition and our business; (xviii) the development, use and regulation of artificial intelligence, including by us, our vendors and our competitors; (xix) the effectiveness of our risk management and internal disclosure controls and procedures; (xx) any failure or interruption of our information and technology systems, including any components provided by a third party; (xxi) our ability to identify and address cybersecurity threats and breaches; (xxii) our ability to keep pace with technological changes; (xxiii) our ability to receive