Banks

Community Financial System, Inc.

CBU · NY · Mid-size bank ($1B to $50B)
Total assets of FDIC-insured bank subsidiaries: $17B at the end of 2025

Filings on the SEC website · This bank on Bankgraph

In short. In its 2025 annual report, Community Financial System, Inc. mentions AI in 9 passages. It says it is using AI now, for compliance and anti-money laundering, cybersecurity and fraud detection. It lists AI as a risk and explains how AI is controlled. Compared with banks of its size, it gives more detail than most.

Compare with peers

In the 2025 annual reportThe yearly report a listed company files with the SEC, called a 10-K. It describes the business, its risks and its results.

Mentions AI
Yes
9 passages
Highest detail levelHow specific a passage is about AI at this bank. General: could be in any bank's report. Names an area: says where AI is used or how it is controlled. Concrete example: names a tool or vendor, gives a number, a date or a result.
Names an area
What it says
Sees AI as a risk; Explains how AI is controlled; Standard wording or passing mention; Using AI now
Kinds of AI named
Process automation, Generative AI, Machine learning
How AI is controlled
Committee, Human review, Model risk management, Policy or framework, Responsible AI, Vendor oversight, Staff training

AI in its annual reports over time

What this shows
How many passages about AI each annual report contains, 2022 to 2025, by what they say.
What it means
0 passages in 2022, 9 passages in 2025.
How to read it
Each bar is a report year, split by what the passages say. Hover or tap a bar for the count.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
Passages about AI in Community Financial System, Inc.'s annual reports, by report year.
Show as a table
Report yearUsing or planning AIExplains how AI is controlledSees AI as a riskOther mentions
2022
2022
2022
2022
2023
2023
2023
2023
2024
2024
2024
2024
2025
2025
2025
2025

Compared with banks of its size

What this shows
This bank's 2025 annual report next to all 221 banks of its size ($1B to $50B).
What it means
Its most specific passage is "Names an area"; for banks of its size the typical level is "General".
How to read it
Yes or no for this bank; the share of banks of the same size for comparison.
Where it comes from
Banks' annual reports (10-K) filed with the SEC, up to 6 Oct 2026. How we did this
In the 2025 reportThis bankBanks of its size
Using AI nowYes26 of 221 (12%)
Explains how AI is controlledYes55 of 221 (25%)
Sees AI as a riskYes184 of 221 (83%)
Mentions generative AIYes112 of 221 (51%)
Mentions AI agentsNo18 of 221 (8%)

What changed from 2024

6 passages new in the 2025 report, 0 passages from the 2024 report no longer there.

Every passage about AI

What this shows
All 22 passages about AI in this bank's annual reports, quarterly reports and earnings materials since 2023, newest first.
What it means
9 passages say the bank is using AI now.
How to read it
Highlighted words are the terms that matched. Labels show what each passage says. Follow the link to read it in the filing.
Where it comes from
Banks' annual reports (10-K), quarterly reports (10-Q) and earnings materials (8-K) filed with the SEC. How we did this

Quarterly report, Q2 2026 filed 7 Aug 2026

The increase in salaries and benefits expense for the quarter was primarily driven by incremental costs associated with acquisitions and de novo bank branches opened between the periods, along with the impact of annual merit-based increases. Data processing increases were reflective of the Company’s continued investment in customer-facing and back-office technologies, including artificial intelligence applications and other workflow efficiency initiatives. Increases in occupancy and equipment expenses were primarily due to incremental costs associated with the opening of de novo bank branches and regional headquarters and the Santander branch acquisition. Amortization of intangible assets increased primarily due to the Santander and ClearPoint acquisitions. The increase in acquisition expenses was driven by the transaction-related costs associated with the ClearPoint acquisition. The decreases in business development and marketing expenses was attributable to the Company’s efforts to more selectively allocate marketing resources toward channels with higher expected returns.
Using AI nowDetail: Names an areaCustomer serviceOperationsNew since the annual report
Quarterly report, page 53Read it in the reportReport an error

Earnings release, Q2 2026 filed 28 Jul 2026

· Data processing and communications expenses increased $3.0 million, or 17.9%, from the second quarter of 2025 reflective of the Company’s continued investment in customer-facing and back-office technologies, including artificial intelligence applications and other workflow efficiency initiatives. The increase also included a one-time $0.6 million early termination charge related to a debit card processing platform conversion.
Using AI nowDetail: Names an areaCustomer serviceOperationsNew since the annual report

Quarterly report, Q1 2026 filed 8 May 2026

The increase in salaries and benefits expense for the quarter was primarily driven by incremental costs associated with acquisitions and de novo bank branches opened between the periods, along with the impact of annual merit-based increases. Data processing increases were reflective of the Company’s continued investment in customer-facing and back-office technologies, including artificial intelligence applications and other workflow efficiency initiatives. Increases in occupancy and equipment expenses were primarily due to incremental costs associated with the opening of de novo bank branches and regional headquarters and the Santander branch acquisition. Amortization of intangible assets increased primarily due to the Santander acquisition. The increase in acquisition expenses was driven by the transaction-related costs associated with the pending acquisition of ClearPoint Federal Bank & Trust. The decrease in other expenses includes a $0.5 million benefit from the non-service related components of the Company’s pension.
Using AI nowDetail: Names an areaCustomer serviceOperationsNew this periodNew since the annual report
Quarterly report, page 45Read it in the reportReport an error

Earnings release, Q1 2026 filed 29 Apr 2026

· Data processing and communications expenses increased $1.7 million, or 10.8%, from the first quarter of 2025 reflective of the Company’s continued investment in customer-facing and back-office technologies, including artificial intelligence applications and other workflow efficiency initiatives.
Using AI nowDetail: Names an areaCustomer serviceOperationsNew this periodNew since the annual report

Annual report, report year 2025 filed 27 Feb 2026

Regulation in the areas of privacy, data protection, data management, resiliency, data transfer, third-party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity could increase the Company’s costs and affect or limit business opportunities and how the Company collects and/or uses personal information.
Sees AI as a riskDetail: GeneralMachine learningSame as last year
Legislators and regulators are increasingly adopting or revising privacy, data protection, data management, resiliency, data transfer, third-party oversight, account access, artificial intelligence (“AI”) and machine learning and information security and cybersecurity laws, including data localization, authentication and notification laws. As such laws are interpreted and applied (in some cases, with significant differences or conflicting requirements across jurisdictions), compliance and technology costs will continue to increase, particularly in the context of ensuring that adequate privacy, data protection, data management, incident management, resiliency, third-party management, data transfer, security controls, account access mechanisms and controls related to artificial intelligence and machine learning are in place. Additionally, new laws and regulations related to automated decision making, artificial intelligence and machine learning as well as the application of existing laws and regulations to these technologies may restrict or impose burdensome and costly requirements on the Company’s ability to use them or impact other aspects of the Company’s business.
Sees AI as a riskDetail: GeneralMachine learningSame as last year
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. The effective use of technology increases efficiency and enables financial institutions to better serve customers and to reduce costs. The Company’s future success depends, in part, upon its ability to address the needs of its customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in the Company’s operations. The Company or its third-party vendors may incorporate artificial intelligence technology into certain business processes, services, or products. The use of artificial intelligence presents several risks, including an uncertain and evolving legal and regulatory environment in the U.S. and internationally and the complexity and rapid pace of change in these artificial intelligence models presents additional risks in understanding the accuracy and relevance of their outputs. Many of the Company’s competitors have substantially greater resources to invest in technological improvements, including artificial intelligence. The Company may not be able to effectively implement new technology-driven products and services or be successful in marketing these products and services to its customers and the costs of this technology may negatively impact the Company’s results of operations. Failure to successfully keep pace with technological changes affecting the financial services industry could have a material adverse impact on the Company’s financial condition and results of operations.
Sees AI as a riskDetail: GeneralSame as last year
The methods used to obtain unauthorized access, disable or degrade service or sabotage systems are constantly evolving and may be difficult to anticipate or to detect for long periods of time. Cyberattacks can originate from a variety of sources, including foreign governments and third-parties affiliated with them, organized crime or terrorist organizations, and malicious individuals both outside and inside a targeted company, including through use of relatively new AI tools or methods that can be used to create deepfakes for impersonation or to enable attack campaigns more quickly and effectively. The constantly changing nature of the threats means that the Company may not be able to prevent all data security breaches or misuse of data. Any failure, interruption or breach in security of these systems could result in failures or disruptions in the Company’s online banking system, its general ledger, and its deposit and loan servicing and origination systems or other systems. Furthermore, if personal, confidential or proprietary information of customers or clients in the Company’s or third-party service providers’ possession were to be mishandled or misused, the Company could suffer significant regulatory consequences, reputational damage and financial loss. Such mishandling or misuse could include circumstances where, for example, such information was erroneously provided to parties who are not permitted to have the information, either by fault of the Company’s systems, employees, or counterparties, or where such information was intercepted or otherwise inappropriately taken by third parties. The Company has policies and procedures designed to prevent or limit the effect of the possible failure, interruption or security breach of its information systems; however, any such failure, interruption or security breach could adversely affect the Company’s business and results of operations through loss of assets or by requiring it to expend significant resources to correct the defect, as well as exposing the Company to customer dissatisfaction and civil litigation, regulatory fines or penalties or losses not covered by insurance.
Sees AI as a riskDetail: GeneralNew this year
The Company is a frequent target of unauthorized attempts to access financial records, destroy data, degrade services, or sabotage systems. The sophistication and diversity of these threats is increasing. Against a backdrop of geopolitical tensions, the increasing use of AI by threat actors, and the growing involvement of organized cyber criminal groups, including state-sponsored groups, the Company expects greater frequency and sophistication of attacks in the future (malware, ransomware, phishing, supply chain compromise, and insider-assisted intrusions). Organized criminal actors include financially motivated ransomware gangs, criminal networks that monetize stolen data, and transnational fraud rings. These groups often operate at scale, use professionalized tools and affiliate ecosystems, and in some instances collaborate with nation state actors or exploit third-party vendors to gain access.
Sees AI as a riskDetail: GeneralNew this year
The exploitation of third-party vendors and contractors increases the risk that a vendor compromise, outage, or failure to meet contractual security obligations could lead to unauthorized access or operational disruption. In addition, the Company’s increasing use of analytics, machine-learning and generative AI introduces additional data and model risks, including threats to data privacy and integrity, biased or incorrect model outputs, exploitation of third-party models or vendors, and automation-enabled escalation of attacks.
Sees AI as a riskDetail: Names an areaMachine learningGenerative AIProcess automationNew this year
CFSI maintains enterprise-wide AI and Data Governance frameworks designed to promote the accuracy, privacy, security, and responsible use of data and AI across our operations. Executive oversight is provided by the Management Risk Committee and IT Steering Committee, with operational accountability assigned to business and system data stewards and data asset owners. The CISO jointly oversees data and AI governance, supports validation and control requirements, and enforces security, privacy, and incident-response protocols. The Company has deployed machine learning and generative AI capabilities to enhance monitoring, automated classification of events and data, and threat-detection and prioritization. These tools support faster triage, playbook-driven remediation and realistic simulation for control validation. AI solutions are subject to formal approval, validation, and periodic re-validation proportional to their inherent risk; higher-risk applications retain a human-in-the-loop approach. Controls include encryption, role-based access, audit logging, vendor due diligence, and employee training. These programs are periodically reviewed to reflect evolving regulatory requirements and technological advances.
Explains how AI is controlledDetail: Names an areaMachine learningGenerative AIProcess automationCybersecurityOperationsCompliance and anti-money launderingNew this year
In addition, cybersecurity risk is a fundamental risk of the Company which is overseen by the Risk Committee of the Board, including Directors with experience in risk management, internal audit, cybersecurity and/or the operations of financial service companies. In particular, the Chair of the Board, Eric E. Stickels, has experience with the risks associated with operating a financial institution based upon his prior service as the President of Oneida Financial Corp. In addition, the Chair of the Risk Committee, Director Kerrie D. MacPherson, has received the Cyber-Risk Oversight Certification issued by the National Association of Corporate Directors (“NACD”), and utilize their business experience and cyber-risk expertise to assist the Risk Committee in its evaluation of management’s cybersecurity systems. Directors Knauss and Singh also serve as Board representatives on the Company’s IT Steering Committee and provide valuable oversight and insight to the committee based on their knowledge and business experience across the digital, technology and/or artificial intelligence sectors.
Standard wording or passing mentionDetail: GeneralNew this year
Total non-personnel noninterest expenses, excluding amortization of intangible assets, acquisition-related expenses, restructuring expenses and litigation accrual, increased $17.2 million, or 10.0%, in 2025, reflective of increases in data processing and communications expenses, other expenses, legal and professional fees, and occupancy and equipment expenses, partially offset by a decrease in business development and marketing expenses. The increase in data processing and communications expenses is reflective of the Company’s continued investment in key technologies, including artificial intelligence applications, customer payment fraud and cybersecurity risk management software, credit administration software and other workflow efficiency initiatives, as well as a $1.4 million consulting expense in connection with a contract renegotiation with the Company’s banking core system provider, which is expected to result in proportionally lower future processing costs for that system infrastructure. Occupancy and equipment expenses increased due to higher property maintenance costs as well as incremental expenses associated with acquisitions and the Bank’s de novo branches opened between the periods. The increase in other expenses includes $1.7 million lower gains on the sale of properties related to the branch consolidations completed in 2025. Legal and professional fees increased due to legal expenses associated with the development of new collective investment funds.
Using AI nowDetail: Names an areaFraud detectionCybersecurityNew this year

Earnings release, Q4 2025 filed 27 Jan 2026

· Data processing and communications expenses increased $1.9 million, or 11.6%, from the fourth quarter of 2024 reflective of the Company’s continued investment in customer-facing and back-office technologies including artificial intelligence applications, customer payment fraud and cybersecurity risk management software, credit administration software and other workflow efficiency initiatives.
Using AI nowDetail: Names an areaOperationsCustomer serviceFraud detectionCybersecurityNew this periodNew since the annual report

Quarterly report, Q3 2025 filed 6 Nov 2025

The decrease in salaries and benefits expense for the quarter was driven by lower employee medical costs that reflected rebates received and a decrease in performance-based incentive compensation expense for certain business units. The increases in salaries and benefits expense for the YTD period were driven by merit and market-related increases in employee wages and select staff additions. Data processing increases were reflective of the Company’s continued investment in key technologies, including artificial intelligence applications, customer payment fraud and cybersecurity risk management software, credit administration software and other workflow modernization initiatives as well as a $1.4 million consulting expense in connection with a contract renegotiation with its core system provider which is expected to result in lower future core system costs. Increases in occupancy and equipment expenses were primarily due to higher property maintenance costs along with incremental expenses associated with the Bank’s de novo branches opened between the periods. The Company also recorded $1.5 million in costs in the second quarter of 2025 that related to severance payments accrued for a workforce optimization plan due to planned branch consolidations and other consumer banking operational initiatives.
Using AI nowDetail: Names an areaFraud detectionCybersecurityNew this periodNew since the annual report
Quarterly report, page 51Read it in the reportReport an error

Quarterly report, Q2 2025 filed 8 Aug 2025

The increases in salaries and benefits expense were driven by merit and market-related increases in employee wages and incentive compensation, select staff additions and higher employee medical costs. Data processing increases were reflective of the Company’s continued investment in key technologies, including artificial intelligence applications, customer payment fraud and cybersecurity risk management software, credit administration software and other workflow modernization initiatives. Increases in occupancy and equipment expenses were primarily due to higher property maintenance costs along with incremental expenses associated with the Bank’s de novo branches opened between the periods. The Company also recorded $1.5 million in costs related to severance payments accrued for a workforce optimization plan due to planned branch consolidations and other consumer banking operational initiatives.
Using AI nowDetail: Names an areaFraud detectionCredit and lendingOperationsCybersecurityNew this periodNew since the annual report
Quarterly report, page 52Read it in the reportReport an error

Quarterly report, Q1 2025 filed 9 May 2025

Noninterest expenses increased $7.2 million, or 6.1%, between the first quarter of 2024 and the first quarter of 2025, primarily due to a $3.4 million increase in salaries and employee benefits, a $1.8 million increase in data processing and communications expenses and a $1.4 million increase in occupancy and equipment expenses. The increase in salaries and employee benefits was primarily driven by merit and market-related increases in employee wages and incentive compensation. The increase in data processing and communications expenses was reflective of continued investment in customer-facing and back-office technologies including investments being made in the development of artificial intelligence applications along with additional technology to enhance the detection and prevention of customer payment-related fraud and cybersecurity-related incidents. Occupancy and equipment expenses increased due to higher winter weather-related property maintenance costs along with incremental expenses associated with the Bank’s de novo branches opened between the periods.
Testing or planning AIDetail: Names an areaOperationsCustomer serviceNew this periodNew since the annual report
Quarterly report, page 39Read it in the reportReport an error
The increase in salaries and benefits expense was driven by merit and market-related increases in employee wages and incentive compensation. Data processing increases were reflective of the Company’s continued investment in key technologies, including artificial intelligence applications and customer payment fraud and cybersecurity risk management software. Increases in occupancy and equipment expenses were primarily due to higher property maintenance costs along with incremental expenses associated with the Bank’s de novo branches opened between the periods.
Using AI nowDetail: Names an areaFraud detectionCybersecurityOperationsNew this periodNew since the annual report
Quarterly report, page 45Read it in the reportReport an error

Annual report, report year 2024 filed 28 Feb 2025

Regulation in the areas of privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity could increase the Company’s costs and affect or limit business opportunities and how the Company collects and/or uses personal information.
Sees AI as a riskDetail: GeneralMachine learningNew this year
Legislators and regulators are increasingly adopting or revising privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity laws, including data localization, authentication and notification laws. As such laws are interpreted and applied (in some cases, with significant differences or conflicting requirements across jurisdictions), compliance and technology costs will continue to increase, particularly in the context of ensuring that adequate privacy, data protection, data management, incident management, resiliency, third party management, data transfer, security controls, account access mechanisms and controls related to artificial intelligence and machine learning are in place. Additionally, new laws and regulations related to automated decision making, artificial intelligence and machine learning as well as the application of existing laws and regulations to these technologies may restrict or impose burdensome and costly requirements on the Company’s ability to use them or impact other aspects of the Company’s business.
Sees AI as a riskDetail: GeneralMachine learningNew this year
The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. The effective use of technology increases efficiency and enables financial institutions to better serve customers and to reduce costs. The Company’s future success depends, in part, upon its ability to address the needs of its customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in the Company’s operations. The Company or its third-party vendors may incorporate artificial intelligence technology into certain business processes, services, or products. The use of artificial intelligence presents several risks, including an uncertain and evolving legal and regulatory environment in the U.S. and internationally and the complexity and rapid pace of change in these artificial intelligence models presents additional risks in understanding the accuracy and relevance of their outputs. Many of the Company’s competitors have substantially greater resources to invest in technological improvements, including artificial intelligence. The Company may not be able to effectively implement new technology-driven products and services or be successful in marketing these products and services to its customers and the costs of this technology may negatively impact the Company’s results of operations. Failure to successfully keep pace with technological changes affecting the financial services industry could have a material adverse impact on the Company’s financial condition and results of operations.
Sees AI as a riskDetail: Names an areaOperations

Annual report, report year 2023 filed 29 Feb 2024

The financial services industry is continually undergoing rapid technological change with frequent introductions of new technology-driven products and services. The effective use of technology increases efficiency and enables financial institutions to better serve customers and to reduce costs. The Company’s future success depends, in part, upon its ability to address the needs of its customers by using technology to provide products and services that will satisfy customer demands, as well as to create additional efficiencies in the Company’s operations. Many of the Company’s competitors have substantially greater resources to invest in technological improvements, including artificial intelligence. The Company may not be able to effectively implement new technology-driven products and services or be successful in marketing these products and services to its customers and the costs of this technology may negatively impact the Company’s results of operations. Failure to successfully keep pace with technological changes affecting the financial services industry could have a material adverse impact on the Company’s financial condition and results of operations.
Sees AI as a riskDetail: GeneralNew this year