Key Takeaways:
- Unauthorized use of AI inside the enterprise can become a cybersecurity, disclosure, and governance event without a traditional cyberattack or operational disruption.
- Materiality remains fact-specific and may turn on qualitative considerations, including the volume and sensitivity of information, not only immediate financial loss.
- AI governance must cover shadow, embedded, third-party, and agentic AI, and assess the resulting cybersecurity, disclosure-control, ITGC, and SOX/ICFR implications based on the facts, without assuming every AI use is in scope.
—
Cybersecurity disclosure discussions often focus on external attackers. This incident began inside the business: non-public customer information was handled through an unauthorized AI-based software application. No operational disruption. No expected material financial impact. Still material.
That is the shadow AI paradox. AI used outside approved governance and control channels can create consequences far beyond the technology itself.

When Unauthorized AI Became a Disclosure Event
On May 5, 2026, CB Financial Services, Inc. became aware of an internal incident involving certain non-public customer information handled through an unauthorized AI-based software application. The company determined on May 7 that the incident was material and filed a Form 8-K under Item 1.05 on May 11.
Customer names, Social Security numbers, and dates of birth were among the information disclosed. The incident did not disrupt operations, customer access, payment systems, or core IT infrastructure, and the company did not expect a material effect on its consolidated financial condition or results. Nevertheless, citing the volume and sensitive nature of the information, the company determined the event was material.
The filing does not establish that unauthorized AI use or exposure of a particular type of information is automatically material. Materiality remains fact-specific and should be evaluated under the traditional reasonable-investor standard with legal counsel, the disclosure committee, and other appropriate advisors.
Why This Matters for Public Companies
Item 1.05 creates a two-stage disclosure clock. Management must make its materiality determination without unreasonable delay after discovery. If the incident is determined to be material, the Form 8-K is generally due within four business days after that determination (not within four business days after discovery). Management therefore needs a process that can assemble facts, involve the right decision-makers, and document a defensible conclusion under time pressure.
The analysis may include quantitative and qualitative considerations: the nature and sensitivity of information, regulatory or litigation exposure, customer trust, reputational harm, business disruption, remediation costs, and the possible effect of related incidents. AI-related scenarios belong in cybersecurity, disclosure, and crisis-management playbooks before an event occurs.
AI Is Already Inside the Enterprise
Employees use generative AI to summarize documents, analyze data, draft communications, and create code. The issue is not necessarily intent: unapproved AI can move information outside established security, privacy, contractual, and records-management controls.
AI also arrives embedded in productivity suites, enterprise resource planning (ERP) and customer relationship management (CRM) platforms, finance and HR systems, cybersecurity tools, and outsourced services, sometimes through routine releases. Together, employee-selected and embedded AI expand the control perimeter faster than inventories and approvals can respond.
Public-company AI disclosures must also be accurate, appropriately tailored, and consistent with the company’s actual governance and risk-management practices. Generic or promotional claims can create a separate disclosure risk when they outrun the facts.
Shadow AI Is Becoming an Internal Controls Issue
Depending on where AI enters a business process and what information or systems it affects, the control implications may extend to IT general controls, application controls, data governance, and disclosure controls and procedures. When financial reporting is implicated, Sarbanes-Oxley (SOX)/internal controls over financial reporting (ICFR) may also apply.
AI governance and ICFR intersect, but they are not identical. Management needs a documented, top-down analysis to determine whether an AI capability affects financially relevant transactions, estimates, management-review controls, or disclosures. The broader control environment may include data classification, identity and access, change management, vendor oversight, monitoring, incident escalation, human review, and decision evidence. Management should not automatically place every AI capability in SOX scope.
What Boards and Audit Committees Should Expect
Boards do not need an inventory dump or a policy-status report. They need five decision-useful answers supported by contemporaneous evidence showing what management knew, evaluated, decided and why:
- Where is AI operating in material, regulated, financially relevant or customer-facing processes — including through employees and vendors?
- Who owns each material AI use and can approve, change, suspend, or retire it?
- What sensitive data, systems, decisions, or transactions can it access or influence?
- How do incidents and exceptions reach cybersecurity, legal, disclosure, and finance leaders?
- Can management reconstruct and support its risk, materiality, control, and remediation conclusions?
Key Actions to Take Before an Incident Happens
The objective is not to prohibit AI. It is to make approved use easier, unapproved use harder, and material risk visible sooner. The following actions can help management build that foundation by establishing accountability, improving visibility into AI use, strengthening controls, and connecting AI risks to existing incident response and disclosure processes:
- Assign accountability: Name an accountable executive and define decision rights across business and control functions.
- Inventory and assess: Identify employee-selected, embedded, vendor, and agenctic AI; tier each use by data sensitivity, business consequence, regulatory exposure, and automation.
- Establish guardrails: Set acceptable-use rules, role-based training, access restrictions, data-loss prevention, logging, monitoring, and human review.
- Connect response processes: Link AI incidents to cybersecurity, legal, disclosure, finance, and crisis processes; define escalation and evidence requirements; rehearse the two-stage disclosure clock.
- Evaluate control implications: Document a top-down analysis of ITGC, application-control, disclosure-control, and SOX/ICFR implications; do not assume scope.
- Reassess third parties: Reassess vendors when functionality, models, data practices, subprocessors, automated actions or contracts change.
What Strong Readiness Looks Like
Strong readiness is not a policy binder. It is management’s ability to show what AI is operating, who owns it, what it can access or influence, how exceptions are escalated, and what evidence supports the company’s conclusions. That same evidence should support not only risk and disclosure decisions, but also where AI should be scaled, redesigned, restricted, or retired based on business value and risk. The goal is responsible adoption so that management can understand, oversee, and defend its AI use.
How MGO Can Help
MGO can help public companies translate these expectations into a practical, risk-based program by:
- Mapping employee-selected, embedded, and third-party AI across material business processes.
- Assessing governance and controls based on data sensitivity, business consequences, regulatory exposure, autonomy, and financial-reporting relevance.
- Connecting AI incident response with legal, disclosure, finance, and crisis processes.
- Evaluating vendor AI, contracts and evidence, and preparing leaders through scenario-based exercises.
Scope depends on the company’s objectives, risks, requirements, governance, and auditor independence considerations. Contact MGO to discuss whether your organization can identify material AI use, respond to an incident, and support its conclusions before the clock starts.