If your employees use AI tools like ChatGPT or Copilot without a formal policy, your business is likely out of step with updated NIST guidance and may already be uninsured for AI-related losses. Shadow AI use, tightening federal risk guidance, and new insurance exclusions are converging at the same time, and most SMB leaders have not been told.
Shadow AI refers to employees using AI tools that IT never approved, vetted, or even knows about. This is not a fringe problem. A 2026 workplace survey on unauthorized AI use found that two out of three office professionals have used an AI tool at work that they believed was not permitted, and 88 percent have shared work-related information with public AI tools like ChatGPT, Claude, or Gemini.
The risk is not that employees are being malicious. It is that they are trying to work faster and have no visibility into what happens to the data once it leaves the company's control. A support rep pastes a customer complaint into a chatbot to draft a response. A finance analyst uploads a spreadsheet to summarize it. Neither thinks twice, because no one told them not to.
The same survey found that 34 percent of office professionals have put customer data into a public AI tool, and 31 percent have shared financial information or confidential company documents. That is not a handful of careless employees. That is roughly a third of your workforce, on a normal week, doing something your cyber insurance underwriter and your compliance auditor would both want to know about.
The direct cost of shadow AI shows up after the fact, not before. When a company discovers customer or financial data has passed through an unapproved AI tool, it has to figure out what was shared, whether the AI vendor retained it, whether a breach notification obligation was triggered, and how to answer that question for every regulator or client who asks. Without an inventory of which tools employees use, that investigation starts from zero.
Most SMBs have no such inventory. There is no list of approved tools, no logging of what data leaves the network through a browser tab, and no one specifically accountable for answering the question when it comes up. The absence of that groundwork is itself the exposure. You cannot manage a risk you cannot see, and right now most small businesses cannot see this one at all.
NIST's AI Risk Management Framework has been extended twice in the past two years: a Generative AI Profile released in mid-2024 that addresses risks specific to tools like ChatGPT and Copilot, and a Critical Infrastructure Profile added in April 2026 for operators of essential systems. Together they sharpen expectations for how organizations should identify, document, and manage AI-related risk, including risk introduced by employees using AI tools day to day rather than only risk from AI systems a company formally builds or deploys.
You do not have to be a federal contractor for this to matter. Frameworks like this tend to become the reference point that auditors, insurers, and even courts use to judge whether a business acted reasonably once something goes wrong. NIST's own materials do not carve out an exception for smaller companies, and they describe the framework as intended for organizations broadly rather than for enterprises above a certain headcount.
The updated framework puts real weight on governance structure, meaning documented ownership of AI risk decisions, not just technical controls. If your business cannot show who is responsible for approving AI tools, monitoring their use, and responding when something goes wrong, you are behind where current guidance says a reasonably managed organization should be, regardless of your size.
Yes. A documented policy is increasingly what insurers and business partners expect to see as evidence you understand your own risk, separate from any legal requirement to have one. Without a policy, you have no way to demonstrate that shadow AI use is being managed rather than ignored, which matters the moment an incident happens and someone asks what your business knew and when.
Increasingly, the honest answer is that you cannot assume so, and this is the part most business owners have not caught up on. Legal analysis describes this shift as the end of silent AI coverage: insurers that once covered AI-related losses implicitly, simply because their policy language never mentioned AI, are now writing explicit exclusions instead.
In January 2026, the Insurance Services Office introduced a generative AI exclusion for commercial general liability policies that strips coverage for injuries or damages arising out of, or attributable to, generative AI. Management liability policies, the kind that cover directors, officers, and employment practices, have gone further. Several carriers have added broad exclusions that purport to remove coverage for any claim arising out of the use, development, or deployment of artificial intelligence, full stop.
Some of this erosion is not even written as an obvious exclusion. Carriers are also narrowing coverage through revised base policy forms, tighter definitions, and underwriting file positions that carve out AI outputs, AI-driven decisions, and the use of third-party AI tools without ever using the word "exclusion" in a way a policyholder would notice while shopping for a renewal.
Pull your current policy and your renewal application and look specifically for how AI is defined, whether any endorsement references generative AI, and whether the application asked what AI tools your business uses. If the application did not ask, and you did not disclose shadow AI use because you did not know about it, you have a gap that will not become visible until you file a claim.
The practical danger here is called gap risk, where exclusions in one policy assume another policy will pick up the loss, and neither one actually does. A ransomware event that started because an employee's AI browser extension leaked credentials could get argued as an AI-related loss under a cyber policy's new exclusion, a technology errors and omissions exclusion, and a management liability exclusion all at once, with no policy left standing to pay the claim.
These three things are not separate problems that happen to share a news cycle. They are one problem viewed from three directions. Shadow AI is the actual exposure sitting inside your business right now. The NIST framework is the standard an outside party will use to judge whether you managed that exposure reasonably. The insurance exclusion is what happens financially when you did not.
An insurer that denies a claim tied to an AI-related loss will look for exactly the kind of documentation the NIST framework describes: a policy, an inventory of approved tools, a named owner of AI risk decisions, and evidence that employee AI use was monitored rather than left to chance. A business that has none of that is not just harder to defend in a claims dispute. It is a worse risk to underwrite in the first place, which shows up as higher premiums or narrower terms at the next renewal even before a claim is filed.
Start with visibility. Find out which AI tools your team is actually using, not which ones IT approved, since those are often two different lists. From there, write a short policy that names an owner for AI risk decisions, states which tools are approved, and sets a basic rule against pasting client or financial data into public AI tools without a business agreement in place covering that data.
Then take that policy to your insurance broker before your next renewal, not after an incident. Ask directly whether your current cyber and management liability policies carry AI exclusions, and get the answer in writing rather than assuming silence means coverage. A short conversation now is considerably cheaper than finding out the answer during a claim.
A structured cyber risk assessment is a reasonable place to start, since it gives you a documented baseline of where AI tools, data flows, and existing controls actually stand today, which is the same evidence an insurer or auditor will eventually ask to see. Pairing that with a governance framework built for AI use specifically, rather than retrofitting a general IT policy, closes the gap faster than trying to write a policy from scratch.
Securafy's AI governance and security services are built around exactly this problem: giving SMBs a documented, defensible AI policy and monitoring approach without requiring an in-house compliance team. If you want a broader view of where your overall security posture stands before you talk to your insurer, Securafy's 2026 Cybersecurity Buyer's Guide walks through what to prioritize first and what questions to ask any provider you are evaluating.
Shadow AI, the updated NIST framework, and new insurance exclusions are not three items on separate to-do lists. Fixing the visibility gap on AI use is the single step that improves your standing against all three at once.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.