Six in 10 small and mid-market business owners say employees use public AI chatbots or writing tools for work, yet just 36% have written policies governing that use. A new Nationwide survey released September 15, 2026, shows the gap between AI adoption and risk management is widening, with nearly a third of businesses reporting they've been targeted by generative-AI scams in the past year.
The survey, conducted by Edelman Intelligence between July 10-26, 2026, found that 37% of business owners provide responsible-use training for AI. Only 27% have rules about what company or customer data can be entered into AI tools, and just 25% have procedures for verifying AI-generated information before it's used in business decisions. More than a third (35%) believe employees are using unauthorized AI tools, reducing visibility into how the technology is deployed across their operations.
"AI is already becoming part of how many businesses work, but the policies around its use haven't necessarily caught up," said Bobbie Goldie, Vice President of Commercial Cyber at Nationwide. "Business owners need to know which tools employees are using and set clear expectations around what information can be shared and how AI-generated work should be reviewed."
AI-enabled fraud hits small and mid-market businesses
Cybercriminals are using the same technology to target businesses from the outside. Thirty-one percent of owners said their company was targeted by a generative-AI scam or fraud attempt within the past 12 months. The problem appears to be accelerating: 52% of independent insurance agents reported seeing an increase in claims tied to generative-AI fraud over the same period.
Business owners expect the threat to grow. Nine in 10 said AI makes it easier for criminals to launch attacks at scale, while 88% said AI-enabled attacks have become more sophisticated over the past year.
Incident response plans lag behind
Only 35% of small and mid-market business owners have an up-to-date incident response plan. Goldie said many businesses are balancing cyber preparedness against competing priorities. "That makes it especially important to understand where the business may be exposed, make sure employees know what to do and have a plan in place before an incident occurs," she said. "Business owners should also talk with their insurance professional about how their risks are changing and whether their protections are keeping pace."
Most owners acknowledge the knowledge gap. Eighty-two percent said they need more information and resources to protect their businesses from AI-enabled cyberattacks. For managers building internal AI policies, understanding both the operational and security dimensions is increasingly critical - topics covered in depth in AI for Management and AI for Cybersecurity Analysts training.
Why this matters for managers
The survey makes one dynamic clear: employees are using AI whether or not formal rules exist. For managers, the risk isn't just external scams - it's also data leakage through public tools, unchecked AI-generated outputs influencing decisions, and incident response plans that haven't been updated for AI-specific threats. The 35% of businesses with no policy, no training, and no verification procedures are operating with significant exposure. Closing that gap starts with knowing which tools are in use, setting clear data-sharing boundaries, and making sure the incident response plan reflects current threats - not the threat landscape from two years ago.
Your membership also unlocks: