Many employees are using AI at work without formal training. 43% of knowledge workers—office employees whose jobs center on information rather than manual work—say their company hasn't given them any AI security training, and 26% don't have a written AI security policy of any kind.
We surveyed over 500 U.S. knowledge workers, intentionally excluding cybersecurity professionals, to see how wide the disconnect runs and who ends up most exposed.
We found that many workers with a written AI policy still can't reliably spot one of AI's most common attack methods, making it clear that having a policy in place or feeling confident about AI doesn't guarantee actual understanding.
LLMs have privacy vulnerabilities, but only 29% of workers have been trained on AI data security
We found that 53% of respondents have access to a company-managed or enterprise AI tool at work, and 47% say they're encouraged or required to use one for certain tasks. But that access hasn't come with much training.
Nearly half (43%) of the knowledge workers we spoke with say their employer hasn't provided any formal AI training at all. For the workers who were given guidance, the training only minimally touched on what actually protects company data.
The most common types of training they received included:
AI basics, like how to write prompts or use specific tools: 33%
Data privacy and cybersecurity: 29%
Ethical or compliance guidelines, like checking for accuracy or appropriate AI use: 29%
Role-specific training: 24%
In an ideal setting, formal training is only half of what guides safe AI use at work. A written policy covers the rest, spelling out what's allowed once company data meets a chatbot. But most workplaces don't have one that actually does that job.
Only 24% of workers say their company has a clear AI policy that's been communicated to employees. The rest fall into cloudy communication:
14% have a policy that exists on paper but was never explained well
25% are working off of informal, unwritten rules
26% have no policy or guidance of any kind
Most people using AI at work today have been doing so for only a couple of years, and employers have largely been playing catch-up with the technology rather than getting ahead of it.
When comparing these training and policy numbers side by side, we see that many workers lack clear, written guidance at the exact moment they need to decide what's safe to type into an AI tool. That missing oversight is what separates an honest mistake from a data breach.
74% of workers wouldn't catch an attack that leaks company logins
A company chatbot can be manipulated to leak login credentials or other sensitive information without anyone breaking in through the front door. That's called prompt injection, a proven attack method in which malicious instructions are slipped into an AI system's prompts.
Unlike most of the risks explored in this survey (like feeding internal data to AI), prompt injection doesn't require an employee to make a mistake first. An attacker just needs access to the chatbot and the right prompt.
Most knowledge workers have never encountered the term. When asked if it's plausible that hackers could exploit a company's public-facing AI chatbot, 26% correctly recognized the risk, meaning roughly three in four workers wouldn't recognize this specific attack if it happened in front of them.
A written AI policy should teach people how to catch something like this, but it rarely does. Even workers with a clear written policy spotted prompt injection only 31% of the time, landing just a few points above that 26% average. Whatever these policies do cover, recognizing a manipulated chatbot doesn't appear to be in scope yet.
Most of the wrong assumptions, like believing AI can automatically block hackers, sound plausible at first glance:
15% believed AI tools would automatically flag and block anyone trying to hack them
13% believed hackers could only access a chatbot built with free AI tools, not enterprise versions
8% believed AI simply wouldn't respond to irrelevant customer prompts
The pattern here is fairly consistent: Workers assume an invisible safeguard already catches bad actors. But in actuality, a well-crafted malicious prompt doesn't have to look obviously out of place to slip through even an enterprise-level tool.
General AI basics training, the most common kind of training companies offer, mostly focuses on writing better prompts. It typically doesn't cover how others can manipulate those same prompts. That missing piece may explain why so many workers still assume some automatic safeguard is protecting them.
25% would still copy a client contract into a personal AI account
The same uncertainty about safeguards shows up in how workers handle sensitive documents. Asked whether they'd copy a client contract into ChatGPT to generate a summary, just 25% said they'd check with their manager or IT first, the most cautious response available. The largest group (36%) said they'd stick to a company-provided account instead, and 25% said they'd copy the contract into a personal account, whether that meant redacting sensitive details first (15%) or not (9%).
Attitudes loosen even more when it's a colleague's call rather than their own: 21% of workers say that using a personal account for work is fine as long as nothing confidential is shared.
Personal accounts don't come with the same data protections as enterprise tools. But some workers may acknowledge that a safer option exists and choose to use the personal account anyway, because it's quicker or just what they're used to.
Without a Written Policy, 28% of Workers Don't Trust Their Own Judgment on AI risk
Few workplaces have a clear AI policy, but those that do influence how confident their employees feel. Given how little formal training most workers receive, you may expect confidence to be low across the board. Instead, most workers still describe themselves as having at least some knowledge of AI's risks.
77% say they have some level of awareness or understanding of AI's security risks, although that number splits into very different levels once you look a bit closer. Only 20% feel very confident that they understand how AI tools can be exploited and how to use them without exposing company data. 30% feel they have a solid grasp of the risks of AI tools, and 27% know the risks exist without fully understanding what they are.
How confident people feel about AI safety largely depends on whether their company has an actual policy. Among workers with a clear, written AI policy, 96% feel at least somewhat confident using AI safely. Among workers with no policy at all, that number falls to 61%, and 28% admit that they don't understand the security risks well enough to trust their own judgment.
That's a big shift built on nothing more than whether a policy exists on paper. Workplaces that haven't said much are leaving people to guess at their own levels of risk exposure.
A written policy is one of the few AI safeguards that reliably works when it exists, which raises the question of who's actually supposed to put one in place.
49% assume their AI vendor is responsible for company security, but only enterprise plans guarantee that
Protecting company data isn't just an IT problem, according to most workers we surveyed. 40% of workers we surveyed said it's a shared responsibility among them, their employer, and the AI tool's developer, and 9% assume it's solely the developer's responsibility. But developers are only responsible under certain conditions.
Enterprise AI vendors such as OpenAI and Anthropic can be contractually bound to protect a company's data, but only when the company has signed a business agreement with the right data-processing terms in place. A personal ChatGPT or Claude account doesn't come with any of that protection, no matter how sensitive the information someone enters.
That puts the responsibility for having the right agreement and ensuring the right account is used on both the employer and the employee, and specifically on whoever handles IT or security policy.
How to update your security awareness training for the age of AI
In theory, AI training should look just like the phishing or data security training most companies already run: structured, mandatory, and revisited as the threats evolve. But in practice, many employees haven't done anything this rigorous, and employees who can't identify basic AI attacks are potentially taking security risks with sensitive data every time they open a chatbot.
There are several ways for companies to encourage safer AI use:
Put a written AI policy in place and actually communicate it, instead of leaving employees to piece together informal rules
Train for specific vulnerabilities, such as prompt injection, rather than focusing solely on prompt-writing basics
Use data loss prevention tools to flag sensitive information before it ever reaches a personal AI account
Route AI-related questions to IT or a manager before acting on them
Huntress helps IT and security teams govern LLM use with practical guardrails and AI-focused security awareness training—while its expert-led, 24/7 SOC and behavior-based monitoring help defend against the AI-enabled attacks those policies are designed to address.
Methodology
The survey was conducted by Centiment on behalf of Huntress. The survey was fielded between July 1, 2026 and July 16, 2026. The results are based on 501 completed surveys. To qualify, respondents had to be US adults employed full-time in office or knowledge worker roles at companies with 50 or more employees. They needed to use AI tools (ChatGPT, Claude, Gemini, Copilot, etc.) at least occasionally for work. The survey excluded cybersecurity professionals and roles that require high technical security knowledge. The data was directionally balanced on age, gender, census region, and company size. The margin of error is approximately ±4% for the overall sample with a 95% confidence level.