Your AI Chats Aren’t Private: How Chrome Extensions Stole Data From 900,000 Users
Recently experts found 2 Chrome Extensions on the Chrome Web Store that are designed to steal Chat GPT and Deep Seek AI chat history. Fortun...
Published on July 20, 2026
On 9 July 2026, Cisometric, in collaboration with ISACA Indonesia Chapter, gathered professionals from banking, fintech, risk, compliance, audit, and IT governance at The Grand Mansion, Menteng, for our latest #CyberTalks session: AI in Banking and Financial Services: When Governance Gaps Become Liabilities.
The premise was simple, and a little uncomfortable: AI is already running inside financial institutions. The governance around it, in many cases, is not. This session set out to examine what happens in that gap, and what it takes to close it.
Why This Matters Now
AI is no longer a pilot project in financial services. It is already embedded across banking, payment systems, insurance, fintech, corporate finance, and capital markets, powering everything from customer service and fraud detection to KYC, payment processing, credit scoring, claims management, investment management, and process automation.
But adoption has outpaced oversight.

Drawing on ISACA's AI Pulse Poll 2026, the session highlighted a recurring pattern: organizations are using AI in genuinely practical ways, yet still struggle with policy, skill building, and risk management. Governance, in other words, is lagging behind adoption, even as AI risks become increasingly visible.
For banking and financial services, that lag is not a minor operational detail. It touches privacy, security, compliance, operational resilience, and, ultimately, customer trust.
The Risks
Much of the discussion focused on the risks that come with Generative AI, several of which are already surfacing in real deployments:
Prompt injection: manipulating a model's behavior through crafted inputs
Hallucination: confident outputs that simply aren't true
Copyright infringement: exposure through training data and generated content
Data leakage: sensitive information escaping through model interactions
Deepfake and identity misuse: a direct threat to identity verification processes
Harmful content generation: reputational and regulatory exposure
Lack of explainability: decisions that cannot be traced or justified

What connects these risks is that none of them are solved by better technology alone. They require clear ownership, human oversight, controls, and accountability, which is exactly why AI governance cannot be treated as a purely technical problem.
Governance and Best Practices
The session then moved from problems to structure, introducing governance references and approaches that help organizations build something more deliberate than ad hoc policy, including:
AI management systems
Risk management frameworks
AI system governance
AI principles
A risk-based approach featured prominently: rather than applying uniform controls everywhere, organizations can classify AI systems by potential impact and calibrate the level of control accordingly. Not every model carries the same weight, and governance should reflect that.
AI Governance in Indonesian
The conversation also turned closer to home, touching on existing references around AI governance and AI ethics guidelines in Indonesia.
As local adoption grows, organizations need more than an awareness of global best practices, and they also need to understand where AI governance in Indonesia is heading, and build with that direction in mind.
The Key Takeaway
If there was one message that carried through the session, it was that AI governance is not a document. It is not a policy filed away for the next audit, or a procedure that exists only on paper.

Governance has to become a living system, one that shapes how people, processes, and technology actually work day to day. AI should support human decision-making, not quietly absorb the accountability that comes with it.
Done well, strong AI governance does double duty. It mitigates financial, legal, and reputational risk, while enabling innovation that is responsible and sustainable rather than reckless.
Conclusion
As AI becomes further embedded in banking and financial services, the conversation around governance needs to move from principle to practice.
Through this #CyberTalks session, Cisometric and ISACA Indonesia Chapter encouraged financial institutions to look beyond adoption, and start building the governance, controls, and accountability required to use AI responsibly.
If you're exploring how your organization can strengthen its AI governance, risk posture, and regulatory readiness, schedule a consultation with our team today, click here.

For more updates on digital scams, cybersecurity insights, and expert tips, follow our social media:
LinkedIn: Cisometric
Instagram: @cisometric
Youtube: @Cisometric
Recently experts found 2 Chrome Extensions on the Chrome Web Store that are designed to steal Chat GPT and Deep Seek AI chat history. Fortun...
Artificial intelligence is often marketed as a productivity booster, a creativity engine, or even a digital assistant that understands us. B...
AI is rapidly moving from experimental pilots to core business infrastructure. Organisations are now using AI to score credit, triage patien...
Search Article by Category
We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy