Companies Push AI Use But Skip Training and Official Policy

Imported from official source

AI Classified by Officially

26% of knowledge workers without high technical security knowledge say there's no AI policy or guidance of any kind at their workplace. 43% say their employer hasn't provided any formal AI training.

Only 20% of workers are very confident they understand the security risks of using AI tools at work.

As a result, many workers don't fully understand the risks of AI. 74% of workers couldn't identify that a public-facing AI chatbot could be vulnerable to prompt injection.

Many employees are using AI at work without formal training. 43% of knowledge workers—office employees whose jobs center on information rather than manual work—say their company hasn't given them any AI security training, and 26% don't have a written AI security policy of any kind.

We surveyed over 500 U.S. knowledge workers, intentionally excluding cybersecurity professionals, to see how wide the disconnect runs and who ends up most exposed.

We found that many workers with a written AI policy still can't reliably spot one of AI's most common attack methods, making it clear that having a policy in place or feeling confident about AI doesn't guarantee actual understanding.

LLMs have privacy vulnerabilities, but only 29% of workers have been trained on AI data security 

We found that 53% of respondents have access to a company-managed or enterprise AI tool at work, and 47% say they're encouraged or required to use one for certain tasks. But that access hasn't come with much training. 

Nearly half (43%) of the knowledge workers we spoke with say their employer hasn't provided any formal AI training at all. For the workers who were given guidance, the training only minimally touched on what actually protects company data.

The most common types of training they received included:

AI basics, like how to write prompts or use specific tools: 33%

Ethical or compliance guidelines, like checking for accuracy or appropriate AI use: 29%

This is an extract. The publication continues at the source.

Read the original at the source: https://www.huntress.com/blog/llm-security-report

Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Huntress — imported from official source
Official source
https://www.huntress.com/blog/rss.xml RSS
Imported
October 03, 2026 08:00
Versions
1 recorded
Identity
https://www.huntress.com/blog/llm-security-report

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.