# The Employees Already Adopted AI. Management Is Writing the Rules Now.

2026-09-24 · Somerset County, New Jersey · Technology

A Nationwide survey captures the workplace problem from the bottom up: unofficial AI use is becoming ordinary faster than many companies are deciding what ordinary use is supposed to look like.

A Nationwide survey captures the workplace problem from the bottom up: unofficial AI use is becoming ordinary faster than many companies are deciding what ordinary use is supposed to look like.

---

A company can spend six months deciding how employees are allowed to use artificial intelligence. The employees can spend six minutes opening a browser tab.

That timing problem sits underneath a new Nationwide survey of small and mid-market business owners. Six in 10 respondents said employees use public AI chatbots or writing tools for work, while only 36% said their businesses have written policies governing employee AI use and 37% provide responsible-use training. The technology did not wait for the handbook.

The more revealing numbers are the ones showing what happens after adoption becomes difficult to see. Thirty-five percent of owners believe employees are using unauthorized AI tools. Only 27% said their businesses have rules specifying what company or customer information can be entered into AI systems, and just 25% said they have procedures for verifying AI-generated information before it influences business decisions. That is not merely a technology gap. It is a workflow gap.

Most organizations like to imagine change arriving through a recognizable sequence: leadership evaluates a tool, policy defines acceptable use, training explains the rules, and employees begin working inside the approved system. Consumer AI largely arrived in the opposite order. People found useful tools on their own, experimented with them on low-risk tasks, shared shortcuts with coworkers and gradually folded them into daily work. By the time management begins writing the formal process, an informal process may already exist.

This is how unofficial workflows become normal. A marketer uses a public chatbot to tighten a subject line. Someone in operations summarizes a long document. A manager asks for help turning notes into a presentation. A customer-service employee rewrites a difficult response. None of those actions necessarily feels like a major technology deployment. Taken together across a company, though, they can amount to one.

The important word is unofficial. A workflow does not need formal approval to become part of how work gets done. It only needs to be useful, repeatable and easy enough that people keep doing it. Once that happens, policy is no longer designing behavior from scratch. It is trying to catch behavior that has already acquired habits, expectations and internal champions.

That creates a strange management problem. A rule written before adoption can shape a new process. A rule written after adoption has to negotiate with an existing one. Employees may already have preferred tools, saved prompts, personal accounts, shortcuts and assumptions about what information is acceptable to paste into a system. The organization is not introducing AI at that point. It is discovering the version of AI use that introduced itself.

Nationwide's findings make the information problem especially clear. If employees are using public tools before companies have decided what data can safely enter them, the risk is not confined to spectacular failures. It can live inside mundane behavior: a customer record included for context, a contract pasted in for summarization, a spreadsheet uploaded because the employee wants help finding a pattern. The action can feel ordinary precisely because the tool feels ordinary.

The same is true on the output side. Only one-quarter of surveyed owners said they have procedures for checking AI-generated information before it is used in business decisions. That matters because generative systems can produce polished answers that still need verification. The workplace danger is not simply that AI can be wrong. It is that fluent output can slide into an existing process without creating the kind of friction that normally reminds someone to stop and check it.

Nationwide's survey also points to a wider cyber problem. Thirty-one percent of owners said their companies had been targeted by a scam or fraud attempt using generative AI in the previous 12 months, and only 35% said they had an up-to-date incident response plan. Eighty-two percent said they need more information and resources to protect their businesses from AI-enabled cyberattacks. The organization is therefore managing AI from both directions at once: employees are bringing it inside while attackers are using it outside.

There is an obvious temptation to treat this as an employee-compliance story: workers are using tools they should not be using, so companies need stricter rules. But that framing skips the more useful question. Why did the unofficial workflow become attractive enough to spread before the official one existed? Usually the answer is not mysterious. The tool solved a real problem quickly. It removed friction. It saved time. It was available when the approved process was slower, unclear or nonexistent.

That does not make governance optional. It makes governance more practical. A policy that simply tells people not to use the tools they have already found useful is competing with demonstrated convenience. A better system has to define the boundaries that matter: which tools are approved, what information cannot be entered, when human review is required, how outputs should be verified, and what employees should do when a useful new tool appears before the policy has caught up again.

This pattern is older than AI. Email, cloud storage, messaging apps, smartphones and consumer software all produced versions of shadow technology inside organizations. People adopt what helps them do the job, and institutions formalize the behavior later. AI compresses that cycle because the tools are unusually accessible and unusually broad. One public chatbot can be writing assistant, analyst, tutor, coder, researcher and brainstorming partner before procurement has scheduled its first meeting.

Nationwide's numbers are a snapshot of owners' reported experiences, not an audit of every employee or every business. The survey was conducted online by Edelman Intelligence from July 10 through July 26, 2026. But the structural problem it captures is easy to recognize: cultural adoption can move faster than institutional permission.

Management may think it is deciding whether the workplace will use AI. In many workplaces, that decision has already been made in hundreds of small, unofficial ways. The real work now is deciding what happens next.

SOURCE NOTES

• Nationwide, Sept. 15, 2026: Businesses Are Using AI Faster Than They Are Managing Its Risks • Methodology note: Nationwide says Edelman Intelligence conducted a 20-minute online survey July 10-26, 2026. The published release does not state the respondent count.

---

ProbleMattic is written and maintained by Matthew Kulcsar, a software engineer, project manager, technologist, platform builder, emergency-services-trained helper, grandfather, and lifelong collector of broken systems, odd behaviors, and useful nonsense.
