On May 11, 2026, a Pennsylvania community bank filed an SEC Form 8-K disclosing a material cybersecurity incident: an employee used an unapproved AI tool. According to American Banker, an employee at CB Financial Services uploaded customer names, Social Security numbers, and dates of birth to an AI app as part of a presentation they were building.
No hacker was involved.
No system was breached.
Nothing malfunctioned.
An employee simply used an AI tool via the browser to do their job, and the bank now has to deal with an SEC disclosure, a 36-hour notice to its regulator, and customer notifications.
What made this an SEC-reportable event without a breach?
Simply put: the leak of sensitive customer data and personally identifiable information.
Materiality doesn't require that a breach occurred. In CB Financial’s review of the event, the exposure of sensitive information was enough of a threshold, and CB Financial decided the materiality bar required them to report on it.
While this may be a first-of-its-kind SEC filing (American Banker notes that the “phrase ‘unauthorized artificial intelligence’ appears on only one SEC filing, and it’s the CB Financial one), the reality is that this kind of data leakage is happening every day.
Because legacy security tools and existing controls aren’t designed to stop it. CB Financial's COO, Jennifer George, told American Banker that the employee didn't email the file or copy it to a device — two processes that the bank's data-loss-prevention policies prohibit with tools built to watch for and stop from happening.
Instead, they logged into their corporate system with legitimate credentials, albeit on a personal device. They used the browser to access those systems, and they also used the browser to access AI tools to get their job done. CB Financial admitted that their DLP rules simply could not see this. That’s because legacy security tools fail in this hyper-digital and remote environment where employees regularly depend on AI.
Why is the browser the risk surface now, and not the endpoint or the network?
Because that's where work happens.
Neon Cyber’s research puts a number on it: 93.4% of knowledge workers do their business application work primarily in the browser, and 70.9% use AI tools daily or more.
Security built with email gateways, file-transfer monitoring, and endpoint controls is designed for a workplace that has moved somewhere else. CB Financial's incident is what that gap looks like when it produces a real disclosure instead of a hypothetical one.
Key takeaway: Security incidents don’t require a hack, a policy violation, or bad intent. Today, all you need is an authenticated employee, a browser, and a deadline.
Is CB Financial an outlier, or just the first to disclose data leakage via shadow AI?
CB Financial’s filing may look like an anomaly, but Neon’s research shows data leakage into unauthorized AI tools is closer to routine.
Neon found that 68.7% of knowledge workers have shared internal, sensitive, or regulated data with an AI tool. Among those who do this, 70.5% do it habitually — most, or almost every time, they use AI. This isn't a rare lapse under unusual pressure. It's a pattern that shows up in the large majority of people who've ever done it once.
Even more concerning, Neon Cyber’s research shows that the kind of regulated personal information CB Financial disclosed is regularly pasted or uploaded into AI tools. This includes:
- Financial information: 25.6% of knowledge workers admitted to pasting or uploading this into AI tools
- Customer data: 25.1% of knowledge workers admitted to pasting or uploading this into AI tools
- HR information, including employee data like salaries, or sensitive personal information, like Social Security Numbers: 20.3% of knowledge workers admitted to pasting or uploading these into AI tools
- Source code: 13.2% of knowledge workers admitted to pasting or uploading this into AI tools
- Credentials or API keys: 11.0% of knowledge workers admitted to pasting or uploading this into AI tools
Dive deeper in the full report.
Why doesn't an AI policy stop this?
Because knowing the rule and following it aren't the same thing, and most organizations only govern for the first one. Neon found that 63.0% of workers report having a clear AI policy they understand. Of that same group, the ones who understand the policy, 39.6% admit to using unapproved tools anyway. Not because the policy was unclear; but because there was no mechanism stopping them at the moment they reached for a new AI tool.
CB Financial had already solved this on paper. The bank offered an approved AI tool with bank-issued accounts for cleared employees. The employee had access to it and used an unapproved one instead, on a personal device, for a routine task. This isn't a training or policy issue, and that's made even clearer in the data in Neon Cyber's research.
How do you close the browser visibility gap before it becomes your disclosure?
Neon Cyber's platform is built to watch the layer where CB Financial's gap actually existed: the browser session itself, across any Chromium-based browser, on personal devices as well as corporate ones. Because it's tied to the browser profile a person is signed into rather than the physical machine they're using, a personal device stops being an automatic blind spot when an employee signs into their corporate profile — visibility and enforcement follow the employee, not the hardware.
See the full picture
CB Financial's SEC filing is one disclosed incident. Neon Cyber’s research highlights the behavior behind it is closer to the norm than the exception.
In Quantifying Shadow AI Risk in the Browser, we break down exactly how often this happens, in which industries, and with what kind of data. Get the full report.
And before we learned of the CB Financial disclosure, we used a very similar scenario to develop the story of Diana, an HR director who unknowingly leaks employee data. Check out the full infographic on her data leakage story, with some of our key research highlights: