On September 15, 2026, Nationwide published its 2026 Cybersecurity Survey, and one gap in it stuck with me: 54% of small-business owners say their staff use public AI chatbots or writing tools for work, but only 35% have a written AI policy. That gap is where shadow AI lives. Shadow AI is employees using AI tools the business hasn't approved or doesn't know about. Picture a crew lead pasting a customer's email into a free chatbot to write the reply, or an office manager asking one to clean up a bid.
In the same survey, 39% of those owners believe their staff already use AI tools the business hasn't authorized. That's a belief, not a count. A ban won't fix it. A one-page policy is a good start.
How common is shadow AI in small businesses?
Nationwide asked 300 small-business owners. It defines a small business as 1 to 50 employees and under $10 million in yearly revenue. Here is what those owners said:
- 54% say their staff use public AI chatbots or writing tools for work.
- 35% have a written AI policy or guidelines.
- 28% have rules on what company or customer information can go into AI tools.
- 28% have a way to check AI-generated information before it's used for business decisions.
- 20% have a person or team responsible for overseeing AI use.
Edelman Intelligence ran the online survey for Nationwide in July 2026. Nationwide is an insurance company, so it has an interest in this topic. You can read the full report yourself; the AI numbers are on page 25.
So the question isn't whether your staff will use AI. More than half these owners say their staff already do. The question is whether you know which tools, what goes into them, and who answers for the results.
Should you ban AI at work?
No. AI shouldn't be banned. It should be governed: written rules, and one person who owns them.
Banning it just pushes it out of sight. Your staff have phones and personal accounts, so a ban doesn't remove the tools. It removes your list of them, and the conversation where they'd tell you what they use. Allow it, with rules and guardrails.
How to find the shadow AI already in your business
I've talked to owners who don't know which AI tools their employees use. So start there. Ask your team. You could say: "I'm not taking anything away. I need a list of the AI tools you use for work and what you use them for." Tell them nobody is in trouble for the answer. You can't set rules for tools you don't know about.
The AI dabbler: when staff build their own AI tools
I've also talked to owners who know their staff use AI. There's another problem there, and I think we're going to see more of it. I call it the "AI dabbler."
Someone takes a few online courses, watches YouTube videos, experiments with public chatbots, and discovers AI building platforms like Base44. These are tools that let a person build their own app by describing it in plain words. Base44 describes itself as "a no-code AI development platform that turns builders' ideas into fully functional apps and websites." Suddenly they feel ready to build their own AI tools.
That's powerful, and the initiative behind it is worth having. It also means people can build systems more complex than they understand. The platform isn't the problem. What someone connects it to is.
Picture an office manager who builds a quoting tool over a weekend and connects it to your customer list and your accounting. It looks like it works. Nobody knows what it can read or change, where your data goes, or what happens when it breaks. That's where the risk climbs.
The three levels of AI use inside a business
- The everyday user. Uses AI because it makes the job easier. You may not know which tools, for what, or what goes into them.
- The AI dabbler. Has learned enough to build things, but may not understand the technical, security, or business side of what they built.
- The governed AI operator. Someone chose the tool on purpose, set what it can reach, tested it, and watches it. It has a named owner, guardrails, and someone accountable.
Level three is where businesses need to go.
The billboard rule: what stays out of public AI tools
If I could put one rule on a one-page AI policy, it would be this:
If you wouldn't put it on a public billboard, don't put it into a public AI tool.
A public AI tool here means one anyone can sign up for, where you can't be sure what happens to what you type. The rule covers customer information, including the names and addresses on your bids and estimates, and everything on the "never without approval" line of the template below. The only exception is a tool and a use the business has approved.
A one-page AI acceptable use policy template
Here is an outline you can fill in this week. It's a starting point, not legal advice; if you handle regulated records, have a lawyer look at your version.
- Approved tools: The AI tools staff may use for work, and who approved each one. Anything not on the list needs a yes first.
- The billboard rule: If you wouldn't put it on a public billboard, don't put it into a public AI tool.
- Never without approval: Customer information, personal information, financial data, passwords, and confidential documents.
- A person checks the output: Anything AI helped produce gets checked by a named person before it prices a job or reaches a customer.
- AI owner: One named person owns the approved list and handles problems. Name: ________
- No connections without sign-off: Nobody connects an AI tool, or anything built with AI, to real business systems (email, customer list, accounting, scheduling) without the AI owner's sign-off.
- Tell us what you use: Everyone lists the AI tools they use now and what for. Nobody gets in trouble for what they list. New tools go on the list before they touch company work.
- Review date: The AI owner rereads this page every ___ months and updates the approved list.
What a one-page policy can't do
You can write this page this week without hiring anyone. That's its strength. Its limit: it won't govern what someone has already built. The weekend quoting tool stays connected after you hand out the page. For that, you have to find each tool, see what it can reach, and decide who owns it or whether it gets switched off. To see what it can reach, ask the person who built it three things: which accounts did you sign it into, what can it read, and what can it change or send? If nobody can answer, switch that connection off until someone can.
A policy tells people what they can and can't do. It doesn't answer the bigger questions:
- What data can each tool reach?
- What should AI be involved in, and what should it stay out of? (AI vs automation sorts that task by task.)
- How is security handled?
- Who is accountable when something goes wrong?
That's what I mean by system ownership: one person who knows what each AI tool touches and answers for it.
Just because someone can build it doesn't mean they should own it. AI is getting easier to build, and that makes an owner and clear rules more important, not less.
Questions owners ask
What is shadow AI?
Shadow AI is employees using AI tools the business hasn't approved or doesn't know about, such as a free chatbot used to write an email or summarize a document. The risk is what goes in, and what comes out without anyone checking it.
Do I need an AI acceptable use policy with only 10 employees?
Yes, and one page is enough. A customer's home address pasted into a public chatbot carries the same risk whether you have 10 people or 500.
How do I decide which AI tools to approve?
First, what does the AI part do that something simpler couldn't? What is AI washing? covers how to tell a real AI feature from a label. Second, what happens to what you type into it? Read the tool's terms: does it keep what you type, and does it use it to train its AI? If the terms don't say, treat it as a public tool.