Survey Finds Gaps in Workplace AI Security Training and Policies

Summary
A survey of 501 U.S. knowledge workers found that 43% received no formal AI training and 26% had no workplace AI policy or guidance. Most respondents failed to recognize prompt-injection risks to public-facing chatbots.
Key points
- The survey was conducted for Huntress by Centiment in July 2026, with 501 U.S. knowledge workers at companies with at least 50 employees; cybersecurity professionals were excluded.
- 43% of respondents said their employer provided no formal AI training, and 26% said their workplace had no AI policy or guidance.
- Only 24% reported having a clear AI policy communicated to employees; 25% relied on informal, unwritten rules.
- Only 26% recognized that hackers could exploit a company’s public-facing AI chatbot through prompt injection.
- Just 29% said their training covered data privacy and cybersecurity, while 33% reported training focused on AI basics such as prompting.
- For a hypothetical client contract, 25% said they would put it into a personal AI account; the article notes personal accounts may not provide enterprise data protections.
- Huntress recommends communicated AI policies, training on attacks such as prompt injection, data-loss-prevention tools, and directing AI security questions to IT or a manager.
Article Details
- Publisher
- Huntress
- Report Period
- 2026-07-01 to 2026-07-16
- Scope
- Survey of U.S. full-time office or knowledge workers at companies with 50 or more employees who use AI tools at work; cybersecurity professionals and roles requiring high technical security knowledge were excluded.
- Sample Size
- 501 completed surveys; approximately ±4% margin of error at 95% confidence for the overall sample.
- Key Statistics
- 43% of surveyed knowledge workers said their employer had provided no formal AI training.
- 26% said their workplace had no AI policy or guidance of any kind; 24% reported a clear AI policy communicated to employees.
- Only 26% correctly recognized that hackers could exploit a company's public-facing AI chatbot; workers with a clear written policy identified the risk 31% of the time.
- 53% had access to a company-managed or enterprise AI tool at work, and 47% said they were encouraged or required to use one for certain tasks.
- Only 20% felt very confident that they understood AI security risks; among workers with no AI policy, 28% said they did not understand the risks well enough to trust their own judgment.
- Recommendations
- Put a written AI policy in place and communicate it to employees.
- Train employees on specific vulnerabilities such as prompt injection, not only prompt-writing basics.
- Use data loss prevention tools to flag sensitive information before it reaches a personal AI account.
- Route AI-related questions to IT or a manager before employees act on them.
People
Vendors
AnthropicEnterprise AI vendors such as OpenAI and Anthropic can be contractually bound to protect a company's data, but only when the company has signed a business agreement with the right data-processing terms in place. AHuntressHuntress helps IT and security teams govern LLM use with practical guardrails and AI-focused security awareness training—while its expert-led, 24/7 SOC and behavior-based monitoring help defend against the AI-enabledOpenAIEnterprise AI vendors such as OpenAI and Anthropic can be contractually bound to protect a company's data, but only when the company has signed a business agreement with the right data-processing terms in place. A
Products
ChatGPTshows up in how workers handle sensitive documents. Asked whether they'd copy a client contract into ChatGPT to generate a summary, just 25% said they'd check with their manager or IT first, the most cautiousClaudehas signed a business agreement with the right data-processing terms in place. A personal ChatGPT or Claude account doesn't come with any of that protection, no matter how sensitive the information someone enters. Copilotroles at companies with 50 or more employees. They needed to use AI tools (ChatGPT, Claude, Gemini, Copilot, etc.) at least occasionally for work. The survey excluded cybersecurity professionals and roles thatGeminiworker roles at companies with 50 or more employees. They needed to use AI tools (ChatGPT, Claude, Gemini, Copilot, etc.) at least occasionally for work. The survey excluded cybersecurity professionals and roles