
Just 46% of survey respondents say their organizations have trained employees on how to evaluate AI outputs in terms of what to trust vs. what to challenge, according to Riskonnect’s 2026 New Generation of Risk Report, uncovering critical gaps in how organizations are governing AI and preparing employees to use it responsibly.
Only 17% of survey respondents say they feel very prepared to manage AI and AI governance risks.
And, while 66% of organizations have trained employees on rules, responsibilities, and defined roles around AI oversight and accountability, the data suggests fewer have gone deeper to provide training on practical skills or specific risks.
“An AI policy sets the rules. Training gives employees the practical knowledge to apply those rules in their day-to-day work. As AI permeates every corner of the organization, employees need to know how to validate what AI gives them, recognize the risks, and make responsible decisions. Pairing strong governance and policies with useful training allows organizations to accelerate AI innovation while minimizing risk to the enterprise,” says Jim Wetekamp, Riskonnect’s CEO.
Key takeaways:
· Only 35% have trained employees on how to interpret and act on AI-driven insights and just 18% have formally trained or briefed the entire company on risks related to agentic AI.
· Nearly four years into generative AI hitting the mass market, just 35% of survey respondents say they have trained or briefed the entire company on generative AI risks.
- 72% of survey respondents have a policy governing employee AI use, up from 58% last year. But only 54% say they have clear policies and guidelines on what AI tools can be used and how they can be used.
- 58% of the companies considering incorporating agentic AI solutions into their operations or products haven’t assessed the risks.
- Economic risk has caught up to cybersecurity as a top corporate threat. The percentage of survey respondents saying economic risk is having a “severe” or “significant” impact on their business is now tied with cybersecurity at 55%. Cybersecurity held the top spot for the past two years.
- The impacts hitting the hardest are higher operating or production costs (65%), increased cybersecurity threats or attacks (58%), supply chain and shipping disruptions or delays (50%), and increased energy costs (49%).
- 41% of respondents say, in the past year, another department made a risk-based decision without consulting the risk team that had a significant, unforeseen disruption elsewhere in the business.
- 75% of respondents say pressure has increased on their role over the past year. 37% say the pressure is “high” or “extreme.” Yet only 25% saw their risk management technology budget grow in the past six months. The majority (66%) say their budgets stayed flat.
- 74% of respondents currently or plan to use AI for risk management, up from 70% in 2025 and 62% in 2024. Top AI use cases for risk professionals include assessing risks (37%), scenario planning and simulations (34%), and surfacing risks they hadn’t previously considered (32%). 31% say AI has helped them uncover gaps or weaknesses in internal processes or controls in the past 12 months.



















