Triple-I Logo

AI Adoption Outpaces Governance, Nationwide Finds

Featured Image
SPONSORED BY
September 23, 2026

By Lewis Nibbelin, Research Writer, Triple-I

While many organizations are reaping the benefits of AI’s rapid growth, governance of the technology has struggled to keep pace. A new Nationwide survey helps quantify the gap: six in 10 businesses say employees use AI for work, but only about one-third maintain written policies or responsible-use training.

“AI is already becoming part of how many businesses work, but the policies around its use haven’t necessarily caught up,” said Bobbie Goldie, vice president of commercial cyber at Nationwide. “Business owners need to know which tools employees are using and set clear expectations around what information can be shared and how AI-generated work should be reviewed.”

Among small and mid-market business owners, the survey found that roughly 35% believe employees are using unauthorized AI chatbots for work – a figure that stands out against the mere 27% who reported establishing rules on what company or customer information can be entered into AI tools. Only about 20% indicated they have designated employees or teams responsible for overseeing AI use.

Less visibility into AI use across operations can leave businesses of all sizes more vulnerable to cyberattacks, including those facilitated through AI. Chubb’s latest outlook on cyber claims revealed average claim severity doubled to more than $4.4 million for large U.S. businesses in 2025, propelled by increasingly advanced, AI-driven incidents.

As such, nearly a third of business owners in Nationwide’s survey said their company has been targeted by a generative-AI scam or fraud attempt in the past year. More than two-thirds were also concerned about attacks, particularly as AI raises their scale and complexity.

Preparedness remains uneven

Whereas 81% of mid-market business owners reported feeling prepared against cyber risk, only 63% of small business owners said the same. Similarly, 95% of the mid-market surveyed provides at least annual cybersecurity training, compared to 72% of small businesses.

Part of the preparedness gap lies in differing levels of insurance coverage. Mid-market businesses are substantially more likely to have cyber insurance, at 73%, compared to 42% of small businesses. Nationwide attributed the discrepancy to lack of knowledge rather than interest, as small business owners largely reported they didn’t know enough about the coverage to purchase it. Eighty-eight percent of small employers agreed they needed more information and resources on how best to protect their business from AI-related threats.

The findings align with a Triple-I and Munich Re study showing cyber incidents and AI ranked among the top risk concerns shared by five key industry segments, including small business owners and consumers. Though policyholders are more aware of the risks, cyber take-up rates in the small commercial and personal line spaces remain low, driven by misunderstandings surrounding coverage options and benefits.

A standardized framework

Formal AI governance laws are similarly inconsistent across states, though regulations are taking shape at the federal level. The National Association of Insurance Commissioners (NAIC) launched the AI Risk Evaluation Supplement to develop guidelines for assessing how insurers use AI. Currently in its pilot phase, the program awaits formal consideration at the NAIC Fall National Meeting in November 2026. Further information on the pilot is available in Triple-I’s State of the Tech Policy Brief, developed by the AI Policy Council.

Learn More:

AI Efficiency Gains Pave Way for Insurance Affordability

Who Trains Tomorrow’s Underwriters? Insurers’ AI Talent Puzzle

NAIC Expectations for AI Oversight, Explained

How AI Helps Insurers Combat Fraud, Legal System Abuse

Bridging the Cyber Risk Resilience Gap Among Insurance Carriers

Cyber Claim Severity Surges as AI, Litigation Accelerate Risk

Related

View All
Arrow Right