Blog

Alarming AI Governance Statistics Every Small Business Leader Needs to See

Employees of small businesses and nonprofits are using AI for all types of business needs, but the formulation and execution of necessary policies and guardrails found in robust AI governance continues to lag. As a result, the sensitive information of your organization and your clients is increasingly at risk. The eye-opening statistics in this article emphasize the extent of the problem and how costly the risk of insufficient AI governance has become.

The statistics presented in this article are from the following sources: UpGuard, CSA Labs, CybSafe, KPMG, Resume Now, ActivTrak, IBM, Reco AI, Pew Research Center, Harris, and Gartner.

Scary AI Governance Statistics

  1. Most organizations don't know what AI they're using.
    More than half of organizations lack a systematic inventory of the AI systems currently in production or development within their own environment. It’s impossible for managers to effectively monitor and understand AI issues when they’re unfamiliar with the AI platforms being used at their company.
  2. Only 40% of workplaces have any AI policy or guidance in place.
    In a KPMG study of nearly 50,000 workers, researchers found that less than half worked at organizations with any AI policy to follow.
  3. 4 out of 5 employees are using AI tools without manager approval.
    A staggering 80% of workers — including nearly 90% of security professionals — are using unapproved AI tools on the job to complete every type of business task. As a result, sensitive client and company information is being increasingly entered into unsecure AI platforms, causing great risk to small businesses.
  4. 40% of employees are using tools that are not permitted.
    Among employees who use generative AI at work, 55% are using unapproved tools. Even worse, 40% are using AI tools that their company has prohibited.
  5. More than a third of employees are sharing confidential data with AI — without supervisor permission.
    38% of workers admit to inputting sensitive information into AI platforms without their employer's knowledge or approval.
  6. 57% of employees are hiding their AI use from management.
    A global study found that the majority of employees who use AI at work are concealing their efforts. To make matters worse, they are presenting AI-generated work as their own.
  7. 57% of employees believe they may already be violating company policy.
    Even among the workers who are aware their company has an AI policy, more than half say they may be using AI in ways that violate it.
  8. 1 in 5 organizations has already been breached because of shadow AI use.
    This statistic tells the awful truth, and it will only get worse with greater unrestricted AI use. One comprehensive study found that 20% of organizations experienced a security breach directly tied to shadow AI use (use of unapproved AI tools) by their employees.
  9. The high cost of poor AI governance: $670,000 extra per breach.
    Organizations with high shadow AI use face breach costs up to $670,000 higher than those with proper governance controls in place. Cybersecurity is difficult enough for companies who have their AI use under control; having weak AI governance will only result in more downtime and reduced income as well as reputational damage.
  10. 63% of breached organizations had no AI governance policy.
    Among organizations that experienced an AI-related breach, nearly two-thirds either had no AI governance policy or were early in the process of developing one at the time of the incident.
  11. Small businesses face the highest exposure.
    This one particularly hits home. Similar to being the favorite target for cybercriminals, small businesses are also the weakest when it comes to AI governance. Companies with 11–50 employees average 269 shadow AI tools per 1,000 employees and typically lack the security resources to monitor or control them. This lack of AI governance, combined with the already disturbing trend in increased cyberattacks, should make every small business owner nervous.
  12. Only slightly more than 10% of employees have received any AI-specific training.
    While half of workers underwent some form of training in the past year, only 12% received training that specifically covered AI tools and risks. This is a stunning statistic when considering the negative impact of shadow AI use on small businesses.
  13. 55% of companies lack the resources to train employees on AI effectively.
    72% of U.S. companies are now using AI in their operations, and their employees may be using other AI tools without permission. Slightly more than half of companies admit they don't have the training resources in place to help employees use AI safely or well. Small business managers and owners need to recognize the danger of poor AI governance for their organizations and make a point of finding the necessary training resources and tools to address this important issue.
  14. AI regulation is rapidly increasing in all global markets.
    By 2030, experts predict that fragmented AI regulation will extend to 75% of the world's economies, driving over $1 billion in compliance spend. Organizations that start building governance frameworks now will be far better positioned to achieve and maintain necessary AI compliance standards than those that wait.
  15. AI governance tools and frameworks are effective— but most organizations haven't implemented them.
    Organizations that have deployed AI governance platforms are three and a half times more likely to achieve high effectiveness in AI governance than those that haven't. Valuable AI governance tools and frameworks exist, but the problems of awareness and implementation persist.

Consult with an AI Governance Expert

These frightening statistics tell the story convincingly: AI usage at small businesses has increased rapidly without enough AI governance in place. Too many managers are not aware of the extent of the AI shadow use problem at their organizations and don’t have the policies, tools, and training in place to meet this daunting challenge.

However, the statistics also clearly show that a comprehensive AI governance program will dramatically reduce the probability and impact of a security breach. An experienced IT partner will help you audit your current AI exposure, formulate an acceptable AI use policy, train your employees, and implement the technical controls to protect your sensitive data and networks. This is exactly the type of work Network Depot does for its clients.

If your organization takes the time to understand the challenges illuminated by the statistics above and works closely with an AI governance expert, you will be able to develop and implement an effective AI governance program to keep your company safe and successful.

Business IT Solutions,
Backed by Proven Experts

Since 1991, Network Depot has delivered enterprise-level IT support at small business prices. Our experienced team acts as your outsourced IT department—resolving issues quickly and proactively, so you can focus on growth, not tech problems.

Get a Free Consultation

Schedule a Free Consultation