AI Governance Gap: Mid-Market Firms Buy Cover – AI Rules Lag.

Estimated reading time: 6 minutes

Nearly three-quarters of mid-market business owners say they buy cyber insurance. Almost a quarter report having no AI policies, controls, or oversight.

Nationwide’s latest survey puts two measures of preparedness side by side. Insurance ownership reaches 73% among mid-market respondents. The share reporting no AI governance measures reaches 24%, twice the small-business figure.

Nationwide publishes these findings separately, leaving the overlap between insurance buyers and control gaps unspecified. The comparison still presents underwriters with a practical question: what daily controls support the insurance purchase?

The insurer released the findings on September 15. Its 2026 cybersecurity report records a 34-percentage-point increase in mid-market cyber insurance ownership since its 2024 survey. Small-business ownership remains at 42%.

Buying cover completes a transaction. Governing AI takes decisions throughout the working day.

The AI Governance Gap Starts At Work

The report’s business section moves from insurance ownership and cyber preparedness into employees’ use of AI. Here, the pooled headline numbers conceal differences that matter to underwriting.

Nationwide AI governance gap chart shows public AI use exceeding written policy adoption among small-business and mid-market owners.

Public tools can form part of an approved workflow. Nationwide separately asked owners about unauthorized use, often called shadow AI. Some 39% of small-business owners believe employees use unapproved tools. The mid-market figure reaches 30%.

General cybersecurity training also tells only part of the story. Among mid-market owners, 95% report formal cybersecurity training at least annually. Responsible AI training reaches 39%. Small-business owners report 72% and 35%, respectively.

An existing training calendar can leave newer business decisions unresolved. Which customer records can staff upload? Who checks an AI-written recommendation before a client receives it?

Bobbie Goldie, Nationwide’s vice president of commercial cyber, put visibility first. “Business owners need to know which tools employees are using and set clear expectations,” she said.

Those expectations need to follow the information. Our May 2025 coverage of Thales’ Data Threat Report examined AI adoption alongside data integrity and security concerns. Nationwide now supplies a closer view of the rules business owners say they have introduced.

See also  Vulnerability Exploitation Overtakes Stolen Credentials As The #1 Breach Vector

AI Risk Plans Lag Behind Confidence

The report then turns toward recovery, coverage expectations, and incident response.

Only 32% of small-business owners report an up-to-date cyber incident response plan. Mid-market owners reach 38%. Another 35% and 36%, respectively, say their plans need updating.

The old plan has survived. Its usefulness needs another look.

Among mid-market owners who had experienced an attack, half said their business knew exactly what to do. Another 47% knew where to start and needed further research.

Among insured small-business owners, 90% trust their cyber coverage to meet all their needs following an attack. The corresponding mid-market figure reaches 77%. Those expectations give brokers a reason to revisit the contract alongside the response plan.

Our June coverage of Willis’ claims analysis explained why the event behind an AI loss matters. Willis flagged potential gaps involving model restoration, inaccurate AI output, and AI-related regulatory action.

Take The Cyber Insurance News Survey

Respondents get the results first.

Cyber insurance survey graphic from Cyber Insurance News asking what the market actually sees and whether loss data is good enough, with an eight minute completion time

An AI-assisted data breach can meet existing cyber coverage triggers. A loss from incorrect business advice may require different wording or another insurance line. Each scenario needs its own reading of the policy.

“Small and mid-market businesses are often balancing cyber preparedness with a long list of other business priorities,” Goldie said.

For a CFO, the useful exercise connects those priorities. A useful plan assigns authority to stop payments, contact counsel, notify insurers, and preserve evidence. In a crisis, those decisions come with a clock attached.

AI Fraud Enters The Claims Conversation

The report’s agent findings add pressure from outside the business.

Some 26% of small-business owners report a generative-AI scam or fraud attempt during the previous year. The mid-market figure reaches 36%. These answers describe attempted attacks. Successful fraud and resulting losses require separate evidence.

See also  Did This Illinois Town Learn Its Lesson After Cyber Scam That Cost Over $400,000? 

Among independent agents, 52% say they observed an increase in claims involving generative-AI scams or fraud attempts. That percentage measures the agents reporting an increase. The survey leaves the size of claims growth unquantified.

Email impersonation and AI-generated phishing feature among the reported attempts. The business consequence can look familiar: someone sends money or information to the wrong recipient.

Nationwide also asked about checking sensitive requests through a second communication channel. Some 28% of small-business owners and 25% of mid-market owners selected that preventive measure.

For brokers, that opens a specific conversation about payment authority, identity checks, and the evidence a claims team would need.

Get The Weekly Cyber Insurance News Upload
Subscribe to our newsletter!

Closing The AI Governance Gap Requires An Owner

Nationwide finds that 20% of small-business owners have designated an employee or team to oversee AI use. Mid-market owners reach 21%.

AI has found a desk. Businesses still need to decide who supervises the work.

Our agentic AI and cyber insurance panel put permissions at the center of that responsibility. Systems that act independently create additional questions about access, authority, and intervention.

Nationwide’s findings reach the earlier decision point: what employees may share, trust, and send using AI. Businesses can assign responsibility before they delegate greater authority to software.

Underwriters can ask for approved-tool lists, data-sharing rules, examples of output review, and evidence of response exercises. Brokers can connect those practices to specific loss scenarios and policy terms.

These survey answers provide starting points for that work. Testing establishes how the controls perform. The insurance schedule records what the company bought. The next underwriting question asks what the company actually does.

See also  GuidePoint Security Unveils Cyber Risk Quantification Service for Financial Clarity

FAQ: AI Governance Gap

Who Took Part In Nationwide’s Survey?

Edelman Intelligence surveyed 300 small-business owners, 300 mid-market owners, and 300 independent insurance agents in July 2026. The wider study included 1,000 consumers. The findings reflect participants’ answers.

What Does The AI Governance Gap Mean Here?

Employees use AI tools at higher reported rates than businesses implement specific safeguards. Those safeguards include data-sharing rules, output checks, training, and designated oversight. The survey reports insurance ownership and controls separately.

Does Cyber Insurance Cover Every AI-Related Loss?

Coverage depends on the policy wording and the event causing the loss. Data disclosure, misdirected payments, and inaccurate professional advice may engage different covers. Brokers should test each scenario against the relevant contracts.

What Does The 52% Claims Figure Measure?

It measures agents who observed an increase in claims involving generative-AI scams or fraud attempts. The survey provides no percentage increase in claim volumes. It also leaves the financial severity of those claims unquantified.

Leave a Comment

×