Estimated reading time: 6 minutes
Nearly three-quarters of mid-market business owners say they buy cyber insurance. Almost a quarter report having no AI policies, controls, or oversight.
Nationwide’s latest survey puts two measures of preparedness side by side. Insurance ownership reaches 73% among mid-market respondents. The share reporting no AI governance measures reaches 24%, twice the small-business figure.
Nationwide publishes these findings separately, leaving the overlap between insurance buyers and control gaps unspecified. The comparison still presents underwriters with a practical question: what daily controls support the insurance purchase?
The insurer released the findings on September 15. Its 2026 cybersecurity report records a 34-percentage-point increase in mid-market cyber insurance ownership since its 2024 survey. Small-business ownership remains at 42%.
Buying cover completes a transaction. Governing AI takes decisions throughout the working day.
The AI Governance Gap Starts At Work
The report’s business section moves from insurance ownership and cyber preparedness into employees’ use of AI. Here, the pooled headline numbers conceal differences that matter to underwriting.
Public tools can form part of an approved workflow. Nationwide separately asked owners about unauthorized use, often called shadow AI. Some 39% of small-business owners believe employees use unapproved tools. The mid-market figure reaches 30%.
General cybersecurity training also tells only part of the story. Among mid-market owners, 95% report formal cybersecurity training at least annually. Responsible AI training reaches 39%. Small-business owners report 72% and 35%, respectively.
An existing training calendar can leave newer business decisions unresolved. Which customer records can staff upload? Who checks an AI-written recommendation before a client receives it?
Bobbie Goldie, Nationwide’s vice president of commercial cyber, put visibility first. “Business owners need to know which tools employees are using and set clear expectations,” she said.
Those expectations need to follow the information. Our May 2025 coverage of Thales’ Data Threat Report examined AI adoption alongside data integrity and security concerns. Nationwide now supplies a closer view of the rules business owners say they have introduced.
AI Risk Plans Lag Behind Confidence
The report then turns toward recovery, coverage expectations, and incident response.
Only 32% of small-business owners report an up-to-date cyber incident response plan. Mid-market owners reach 38%. Another 35% and 36%, respectively, say their plans need updating.
The old plan has survived. Its usefulness needs another look.
Among mid-market owners who had experienced an attack, half said their business knew exactly what to do. Another 47% knew where to start and needed further research.
Among insured small-business owners, 90% trust their cyber coverage to meet all their needs following an attack. The corresponding mid-market figure reaches 77%. Those expectations give brokers a reason to revisit the contract alongside the response plan.
Our June coverage of Willis’ claims analysis explained why the event behind an AI loss matters. Willis flagged potential gaps involving model restoration, inaccurate AI output, and AI-related regulatory action.
Take The Cyber Insurance News Survey
Respondents get the results first.
An AI-assisted data breach can meet existing cyber coverage triggers. A loss from incorrect business advice may require different wording or another insurance line. Each scenario needs its own reading of the policy.
“Small and mid-market businesses are often balancing cyber preparedness with a long list of other business priorities,” Goldie said.
For a CFO, the useful exercise connects those priorities. A useful plan assigns authority to stop payments, contact counsel, notify insurers, and preserve evidence. In a crisis, those decisions come with a clock attached.
AI Fraud Enters The Claims Conversation
The report’s agent findings add pressure from outside the business.
Some 26% of small-business owners report a generative-AI scam or fraud attempt during the previous year. The mid-market figure reaches 36%. These answers describe attempted attacks. Successful fraud and resulting losses require separate evidence.
Among independent agents, 52% say they observed an increase in claims involving generative-AI scams or fraud attempts. That percentage measures the agents reporting an increase. The survey leaves the size of claims growth unquantified.
Email impersonation and AI-generated phishing feature among the reported attempts. The business consequence can look familiar: someone sends money or information to the wrong recipient.
Nationwide also asked about checking sensitive requests through a second communication channel. Some 28% of small-business owners and 25% of mid-market owners selected that preventive measure.
For brokers, that opens a specific conversation about payment authority, identity checks, and the evidence a claims team would need.
Get The Weekly Cyber Insurance News Upload
Subscribe to our newsletter!
Closing The AI Governance Gap Requires An Owner
Nationwide finds that 20% of small-business owners have designated an employee or team to oversee AI use. Mid-market owners reach 21%.
AI has found a desk. Businesses still need to decide who supervises the work.
Our agentic AI and cyber insurance panel put permissions at the center of that responsibility. Systems that act independently create additional questions about access, authority, and intervention.
Nationwide’s findings reach the earlier decision point: what employees may share, trust, and send using AI. Businesses can assign responsibility before they delegate greater authority to software.
Underwriters can ask for approved-tool lists, data-sharing rules, examples of output review, and evidence of response exercises. Brokers can connect those practices to specific loss scenarios and policy terms.
These survey answers provide starting points for that work. Testing establishes how the controls perform. The insurance schedule records what the company bought. The next underwriting question asks what the company actually does.
FAQ: AI Governance Gap
Edelman Intelligence surveyed 300 small-business owners, 300 mid-market owners, and 300 independent insurance agents in July 2026. The wider study included 1,000 consumers. The findings reflect participants’ answers.
Employees use AI tools at higher reported rates than businesses implement specific safeguards. Those safeguards include data-sharing rules, output checks, training, and designated oversight. The survey reports insurance ownership and controls separately.
Coverage depends on the policy wording and the event causing the loss. Data disclosure, misdirected payments, and inaccurate professional advice may engage different covers. Brokers should test each scenario against the relevant contracts.
It measures agents who observed an increase in claims involving generative-AI scams or fraud attempts. The survey provides no percentage increase in claim volumes. It also leaves the financial severity of those claims unquantified.
Related Cyber Insurance Posts
- Recovery Took Twice As Long As Planned. Nobody Priced For That.
- Companies Are Buying Cyber Insurance & Making (Repeat) Claims, But Ransomware Is Not Covered By About 30% of the Policies: Delinea Survey(Opens in a new browser tab)
- Considerations for Buying Cyber Insurance(Opens in a new browser tab)
- SMB Cybersecurity: Half The Market Has Been Bitten(Opens in a new browser tab)
- SMB Cybersecurity: Half The Market Has Been Bitten(Opens in a new browser tab)