AI FOR SMALL BUSINESS
How to manage AI risks in your small business — without slowing down
AI can save you time, help you write better, find information and take care of repetitive jobs. But it can also create problems if you use it without thinking about what could go wrong.
You don’t need a big AI policy or an IT department. You do need to know the main risks, decide where AI is appropriate and give yourself and your staff a few simple rules to follow.
The short answer
AI isn’t automatically dangerous, but using it without sensible controls can create problems with your data, customers, money, staff and reputation. Start by deciding what AI can be used for, what information must stay out of it and where a human must check the result.
We’ll send a password for the resource area and regular UK-focused AI updates. Unsubscribe anytime.
Why AI risks matter to a small business
You might think AI risk is something for banks, government departments and large technology companies.
It isn’t.
Imagine you run a small plumbing business.
One employee copies a customer’s email into a free AI chatbot and asks it to write a reply. The email contains the customer’s name, address, details of the plumbing problem and information about their home.
Or perhaps you run a café.
Someone asks AI to create a food description and it invents an ingredient or makes an unsupported claim about allergens.
Or you’re a retailer and ask AI to rewrite product information. It quietly changes one of the specifications.
None of these examples requires a sophisticated AI system.
They’re ordinary uses of AI by ordinary businesses.
And that’s the point.
The biggest AI risks for small businesses often aren’t dramatic futuristic scenarios. They’re everyday mistakes that happen because someone didn’t realise what could go wrong.
The Information Commissioner’s Office says AI can exacerbate existing risks, introduce new ones and make some risks harder to assess and manage. It recommends taking a proportionate, risk-based approach rather than treating every AI use in exactly the same way.
You don’t need to become an AI expert.
You need to know where the danger points are.
1. Data and security risks
For most small businesses, this is the first place to start.
What happens when an employee copies something into an AI tool?
The answer depends on the tool, the account, the settings and the information being entered. That’s why “Is ChatGPT safe?” or “Is this AI tool secure?” is often the wrong question.
The better question is:
“What happens to this particular information when I put it into this particular tool?”
Think about the information your business holds:
- Customer names and contact details
- Addresses
- Employee information
- Invoices
- Supplier contracts
- Pricing
- Business plans
- Passwords and security information
- Confidential customer correspondence
- Photographs
- Financial information
- Information covered by a confidentiality agreement
Not all of this should automatically be entered into an AI system.
The ICO’s guidance stresses security and data minimisation when personal information is processed using AI. In simple terms, don’t collect, share or expose more information than you actually need.
The problem with shadow AI
You might have approved Microsoft 365 Copilot for the business.
But that doesn’t mean your staff aren’t also using other AI tools.
Someone might have a personal ChatGPT account. Someone else might use Gemini. Another employee might find an AI tool online that promises to turn PDFs into summaries.
You may never know.
This is sometimes called “shadow AI”.
The problem isn’t necessarily that the tools are bad.
It’s that you don’t know what information is being put into them or what their terms and settings are.
A simple business rule helps:
“Only use AI tools we’ve approved for business information.”
That doesn’t mean staff can’t experiment with AI.
It means they shouldn’t experiment with customer or company data.
Prompt injection is a newer security risk
If you’re building an AI system that can read emails, websites, documents or other untrusted information, there’s another risk to understand.
Prompt injection is where malicious instructions are hidden in information an AI system reads, potentially causing it to behave in an unintended way.
The UK’s National Cyber Security Centre warns that prompt injection can potentially cause AI systems to reveal confidential information or trigger unintended actions.
You don’t need to know how to defend an AI model against this yourself.
The practical lesson for a small business is simpler:
Don’t give an AI system more access or authority than it needs.
If an AI tool can read your entire customer database and send emails automatically, the consequences of a mistake or attack are much greater than if it can simply draft an email for you to review.
The more an AI system can access or do, the more carefully you need to control it.
Don’t assume a familiar supplier removes all risk
You may trust Microsoft, Google, your accountant or your marketing agency.
That’s sensible.
But you still need to understand how AI is being used with your information.
Ask suppliers:
- Do you use AI when providing services to us?
- What information is sent to the AI system?
- Which AI provider is being used?
- Is our data used to train models?
- Where is the information processed?
- How long is it retained?
- Can we opt out?
- Does our contract cover this use?
You don’t need a 20-page questionnaire.
A few direct questions can reveal a lot.
2. Legal and data protection risks
This is where AI can get complicated quickly.
You don’t need to understand every part of UK data protection law.
But you do need to understand one basic principle.
If your business uses AI to process personal information, your existing legal responsibilities don’t disappear.
The ICO’s AI guidance covers lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability.
“The AI tool is responsible” isn’t a complete answer
Imagine your marketing agency uses AI to write customer emails using information from your customer database.
If something goes wrong, you can’t simply assume:
“The agency used the AI, so it’s their problem.”
Your relationship with the supplier matters.
Your contract matters.
The information being processed matters.
And your own responsibilities as a business matter.
This is why AI should be added to the questions you already ask about suppliers handling customer information.
What about AI training on your data?
This is an area where old AI advice can become misleading.
Not every AI tool treats your information in the same way.
Some business services provide stronger data protections than consumer services. Some let you control whether information is used for model improvement. Others have different terms.
So don’t use a blanket rule such as:
“AI always trains on everything you enter.”
It doesn’t.
But don’t assume the opposite either.
Check the provider’s current terms and privacy documentation for the actual service you’re using.
International data transfers
Your AI provider may process information in different countries.
That doesn’t automatically mean you can’t use the service.
But if you’re processing personal information, international transfers can create additional data protection considerations.
For a small business, the practical approach is to check what the supplier says about where data is processed and what safeguards are used.
If you’re dealing with particularly sensitive information, get appropriate advice rather than guessing.
UK rules are changing
UK data protection law has changed.
The Data (Use and Access) Act 2025 introduced changes in stages, with the ICO confirming on 19 June 2026 that all its data protection provisions were in force.
This is one reason old blog posts about “AI law in the UK” can be unreliable.
Don’t base an important business decision on an article written two years ago.
Check the current ICO guidance.
The ICO’s AI guidance is also being updated following the changes to data protection law.
3. AI can cost you money
AI is supposed to save money.
Sometimes it does.
Sometimes it creates another job for you.
Imagine asking AI to analyse your sales spreadsheet.
It produces a neat summary and tells you that one product category is performing badly.
You change your buying strategy.
Later you discover that the AI misunderstood one column.
The problem wasn’t the cost of the AI subscription.
The problem was the business decision based on an unchecked answer.
AI can create financial risk through:
- Incorrect calculations
- Incorrect financial summaries
- Wrong pricing information
- Invented market statistics
- Incorrect tax information
- Bad forecasts
- Duplicate or incorrect invoices
- Unchecked automated refunds
- Poor purchasing decisions
- Paying for tools nobody actually uses
- Time spent correcting AI-generated work
AI hallucinations
An AI hallucination is simply an answer that sounds convincing but contains incorrect or invented information.
The NCSC specifically warns that generative AI can get things wrong and present incorrect statements as facts.
That matters because good writing can hide a bad fact.
If AI writes:
“Our delivery charge is £8.95.”
It sounds fine.
But perhaps your actual charge is £7.95.
If that appears on your website, you’ve created a problem.
The more expensive the mistake, the more checking you need
A useful rule is:
Low cost of error = light checking.
High cost of error = serious checking.
You don’t need to verify every idea AI gives you.
But you should check important numbers, names, dates, prices, legal claims, technical information and anything that could cost you money.
Never let “AI said so” become an excuse
If AI writes an incorrect invoice, the customer doesn’t care that the chatbot made the mistake.
If AI gives you the wrong tax information, HMRC isn’t going to accept “the AI told me”.
If an AI-generated product description is misleading, your customer isn’t responsible for checking whether you wrote it yourself.
You remain responsible for what your business sends, publishes and does.
4. Operational and quality risks
AI can make work faster.
It can also make bad work faster.
That’s an important distinction.
If you use AI to create a first draft, a human can improve it.
If you allow AI output to flow straight into your website, customer emails, stock system or accounts without checking it, a small error can spread quickly.
This is sometimes called a compounding error.
One mistake becomes ten.
Ten becomes a hundred.
AI hallucinations aren’t the only quality problem
AI can also:
- Misunderstand instructions
- Leave out important information
- Change the meaning of text
- Invent details
- Give inconsistent answers
- Produce generic content
- Repeat outdated information
- Make calculations incorrectly
- Misinterpret a customer’s request
- Sound certain when it’s uncertain
This is why “human in the loop” sounds complicated but really isn’t.
It simply means a person checks important AI work before it becomes a real business action.
For example:
AI drafts the customer email.
You read it.
Then you press Send.
That’s human oversight.
Skills can also disappear
There’s another risk that’s easy to overlook.
If people use AI for everything, they can become less confident at doing the underlying job themselves.
A junior member of staff who always asks AI to write customer responses may never learn how to handle difficult customers.
Someone who always asks AI to analyse figures may become less comfortable spotting an obvious error.
The answer isn’t to ban AI.
Teach people the job first, then use AI to help them do it better.
Skills England’s 2026 research highlights the need for workers to develop the skills to use AI effectively, safely and responsibly.
5. Customers, staff and reputation
Your customers don’t necessarily care whether you use AI.
They care about whether you do a good job.
That’s the useful test.
If AI helps you answer an email faster and the answer is accurate and helpful, most customers probably won’t care.
If an AI chatbot gives someone the wrong answer about a refund, an allergy or a service they’ve paid for, they’ll care very quickly.
Don’t hide important AI use
You don’t need to put “This email was written by AI” at the bottom of every message.
But if AI is interacting directly with customers or helping make decisions about them, transparency becomes much more important.
For example, if a customer is dealing with an AI chatbot, don’t make it unnecessarily difficult for them to understand that they’re talking to an automated system.
And give them a sensible way to reach a person when the AI can’t deal with the problem.
Be especially careful with employees
AI can be useful for recruitment, staff training and administrative work.
But decisions about people carry greater risks.
Suppose you ask AI to rank ten CVs.
It produces a list.
You hire the person at the top.
What if the system has picked up patterns that unfairly disadvantage certain candidates?
UK government guidance on responsible AI in recruitment highlights risks including bias, discrimination and digital exclusion.
For a small business, the safest approach is simple:
Use AI to help you assess information.
Don’t let it quietly become the person making the decision.
The same applies to performance reviews, disciplinary matters and other decisions affecting employees.
6. Strategic, supplier and competitive risks
AI risk isn’t just about data and legal problems.
There’s also the risk of making poor business decisions.
Buying AI because everyone else is
You see another business using AI.
You subscribe to three tools.
Then another two.
Six months later you’re paying £150 a month for software nobody really uses.
That’s not an AI strategy.
It’s a collection of subscriptions.
Before buying an AI tool, ask:
- What problem will this solve?
- How much time will it save?
- Who will use it?
- What will it cost?
- What information will it need?
- What happens if we stop using it?
- Can we export our information?
- What happens if the supplier changes its prices?
- What happens if the service goes offline?
Vendor lock-in
If you build a major part of your business around one AI provider, moving away later may be difficult.
For a small business, you don’t need to worry about this every time you use an AI writing tool.
But if you’re building your customer service, sales process or internal systems around one provider, think ahead.
Keep copies of important business information in formats you control.
Don’t build your entire business around a tool you could lose access to tomorrow.
AI can make competitors look more alike
There’s another strategic problem.
If every café uses AI to write its website.
Every plumber uses AI to write the same type of service page.
Every retailer uses AI to produce the same product descriptions.
Everything starts to sound the same.
AI can make your business more efficient.
Your experience, judgement, personality and knowledge are still what make it different.
Use AI to help express those things.
Don’t let it replace them.
7. Your suppliers can create AI risks too
You might have decided not to use AI.
That doesn’t mean AI isn’t being used with your information.
Your accountant might use it.
Your marketing agency might use it.
Your website company might use it.
Your recruitment provider might use it.
Your customer service supplier might use it.
Your software provider might introduce an AI feature without you actively asking for it.
This is why AI should become part of your normal supplier checks.
Ask:
“Do you use AI to process information we provide?”
That’s a perfectly reasonable business question.
Then ask:
“What information does it process and which AI service do you use?”
You don’t need to distrust your suppliers.
You need to know what’s happening to your information.
This matters particularly as more businesses start using AI agents that can take actions rather than simply generate text. The Competition and Markets Authority’s 2026 guidance makes clear that businesses remain responsible for complying with consumer law when they use AI agents.
A simple AI risk policy for a small business
You don’t need a huge document.
You could start with one page.
Your rules might say:
Staff may use approved AI tools for:
- Brainstorming
- Drafting
- Rewriting
- Summarising non-sensitive information
- Creating ideas
- Researching low-risk subjects
- Routine administrative work
Staff must not enter:
- Passwords
- Security codes
- Private encryption keys
- Unnecessary personal information
- Confidential information into unapproved AI tools
- Information covered by a confidentiality agreement unless the approved tool and process allow it
Staff must check:
- Customer-facing information
- Prices
- Numbers
- Dates
- Legal claims
- Tax information
- Safety information
- Product specifications
- Anything that could cause financial or reputational harm if wrong
Staff must not allow AI to make important decisions on its own about:
- Customers
- Employees
- Job applicants
- Refunds
- Complaints
- Contracts
- Financial commitments
- Safety
That is already a much better starting point than having no rules at all.
A 30-minute AI risk check for your business
You can do this without an IT department.
Step 1 — List the AI tools
Write down every AI tool currently being used.
Don’t just list the ones you bought.
Ask staff what they use.
Step 2 — List the information
What information goes into those tools?
Customer information?
Employee information?
Pricing?
Documents?
Emails?
Images?
Step 3 — Identify your biggest risks
Ask:
“What is the worst realistic thing that could happen?”
Don’t imagine a Hollywood cyber attack.
Think about ordinary mistakes.
A customer receives the wrong information.
A confidential document is shared.
A supplier’s AI produces incorrect work.
A member of staff relies on a false answer.
Step 4 — Decide what needs checking
Not everything needs the same level of control.
A social media idea is different from a payroll decision.
A product description is different from a safety instruction.
Step 5 — Write down five rules
Keep them simple enough that staff will actually follow them.
Step 6 — Review the list every few months
AI changes quickly.
New tools appear.
Existing software adds AI features.
Your business changes too.
Don’t write a policy once and forget about it.
The five rules I would start with
If you’re a very small business and all of this feels like too much, start here.
- Don’t put confidential information into an AI tool unless you’ve checked that the tool is suitable for it.
- Only use AI tools you’ve approved for business use.
- Check important AI output before you rely on it.
- Don’t let AI make important decisions about customers or staff without proper human judgement.
- Ask suppliers whether they’re using AI with your information.
Those five rules won’t eliminate every risk.
Nothing will.
But they’ll prevent a surprising number of avoidable problems.
Do you actually need AI?
There’s one final risk worth mentioning.
Using AI simply because you feel you should.
You don’t have to use AI.
If you’re a self-employed electrician and AI saves you 20 minutes a week writing emails, that’s useful.
If it takes you longer to check its work than it would have taken to write the email yourself, perhaps don’t use it.
If you’re a small café and a simple spreadsheet does everything you need, you don’t need an AI system analysing your sales every morning.
If you’re a retailer and your product descriptions already work well, you don’t need to replace them just because an AI tool can rewrite them.
The goal isn’t maximum AI use.
It’s better business.
And sometimes the best decision you can make is not to use AI for a particular job.
AI FAQs
Questions people ask about AI risks in small businesses
These are the practical questions UK business owners are asking about managing AI risks.
What are the main risks of AI for small businesses?
The main risks include exposing confidential or personal information, inaccurate AI-generated information, cyber security problems, poor business decisions, legal and data protection problems, financial losses, reputational damage and over-reliance on suppliers or AI tools.
You don’t need to treat every risk equally. Focus first on the uses of AI that could cause the most harm if something goes wrong.
Is ChatGPT safe to use for my small business?
It depends on which ChatGPT service and account you’re using, what information you put into it and your organisation’s requirements.
Don’t use a blanket rule such as “ChatGPT is safe” or “ChatGPT is unsafe”. Check the current terms and privacy arrangements for the specific service you’re using, and don’t enter confidential or personal information unless you’ve established that the service is suitable for that purpose.
Do I need an AI policy for my small business?
You don’t necessarily need a complicated formal policy.
But if more than one person uses AI for work, having a short set of written rules is a very good idea.
It should explain which AI tools staff can use, what information they mustn’t enter, what needs checking and when a human must make the final decision.
Can AI cause a data breach?
Yes.
AI can create or increase security risks, particularly when it is given access to sensitive information or connected to other systems.
The NCSC warns that prompt injection can potentially cause AI systems to reveal confidential information or take unintended actions.
Good access controls, limited permissions and sensible security practices still matter.
Can my accountant or marketing agency use AI with my data?
They may be doing so already.
Ask them.
Find out whether they use AI, what information is processed, which provider is involved and what contractual and security arrangements apply.
Don’t assume that a supplier’s use of AI automatically makes it your problem, but don’t assume it automatically isn’t your problem either.
Your responsibilities will depend on the relationship, the data involved and what your contracts say.
Does UK GDPR apply to AI?
Yes. Where AI is used to process personal information, UK data protection law can apply.
The ICO’s AI guidance covers issues including lawfulness, fairness, transparency, data minimisation, accuracy, security and accountability.
UK data protection law has also changed. The ICO confirmed that all data protection provisions of the Data (Use and Access) Act 2025 were in force from 19 June 2026.
Because the rules and guidance are changing, check current ICO guidance rather than relying on old AI articles.
Can AI make decisions about my employees or customers?
AI can assist with decisions, but you should be very careful about allowing it to make important decisions on its own.
Recruitment, employee management and decisions affecting customers can raise fairness, discrimination, privacy and other legal issues.
The UK government’s responsible AI recruitment guidance highlights risks including bias, discrimination and digital exclusion.
Sources
-
Information Commissioner’s Office — Artificial intelligence
★★★★★
UK regulator
The ICO’s central AI guidance explains how data protection law applies to AI and provides practical resources for organisations. -
Information Commissioner’s Office — AI and data protection guidance
★★★★★
UK regulator
Covers lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security and accountability. The ICO describes a risk-based approach to managing AI-related risks. -
Information Commissioner’s Office — AI and data protection risk toolkit
★★★★★
UK regulator
A practical toolkit designed to help organisations assess and reduce risks to people’s rights and freedoms arising from AI systems. The ICO currently notes that this guidance is under review following changes made by the Data (Use and Access) Act. -
Information Commissioner’s Office — Data (Use and Access) Act 2025
★★★★★
UK regulator
The ICO’s latest information confirms that all data protection provisions of the Data (Use and Access) Act 2025 were in force from 19 June 2026. -
National Cyber Security Centre — AI and cyber security: what you need to know
★★★★★
UK cyber security authority
Explains risks including hallucinations, bias, prompt injection and data poisoning, and is specifically written for small and medium-sized organisations as well as larger organisations. -
National Cyber Security Centre — Prompt injection is not SQL injection
★★★★★
UK cyber security authority
Explains why prompt injection is a distinctive risk in generative AI systems and why businesses should focus on reducing the likelihood and impact of attacks rather than assuming they can be completely eliminated. -
Competition and Markets Authority — Using AI agents: complying with consumer law
★★★★★
UK regulator
Provides UK guidance for businesses using AI agents, including the point that businesses remain responsible for meeting consumer law obligations when using AI agents. -
UK Government / Department for Science, Innovation and Technology — Responsible AI in Recruitment
★★★★★
UK government guidance
Explains risks associated with AI in recruitment, including bias, discrimination and digital exclusion, and provides practical guidance for organisations with limited technical expertise. -
Skills England — Skills for AI: What works for AI upskilling in the UK
★★★★☆
UK business and workforce research
Published in 2026, this research looks at how organisations can build the skills needed to use AI effectively, safely and responsibly. -
UK Government / Intellectual Property Office — Copyright and Artificial Intelligence
★★★★★
UK government / intellectual property guidance
The UK’s copyright and AI position continues to develop. The government published a report and impact assessment in March 2026 covering copyright works and AI development, showing why businesses shouldn’t rely on outdated claims about AI and copyright. -
Venkit et al. — An Audit on the Perspectives and Challenges of Hallucinations in NLP
★★★★½
Peer-reviewed academic research
A review of 103 publications on hallucinations in natural language processing, highlighting both the scale of research into the problem and the lack of complete agreement over how hallucination should be defined.
⚠️ Evidence note: Some statements about AI risk are facts about how particular systems or laws work. Others are practical recommendations based on risk management rather than legal requirements.
For example, “don’t put passwords into an AI tool” is straightforward security advice. It isn’t a special AI law. Likewise, recommending that a person checks an AI-generated customer email is a sensible control, not a universal legal requirement.
The ICO takes a risk-based approach to AI and makes a distinction between what organisations must do to comply with data protection law and what it recommends as good practice.
The legal position around AI continues to develop, including data protection and copyright. This article is therefore intended as practical guidance for small businesses, not legal advice. Where an AI use could have significant legal, financial, employment or safety consequences, check the current official guidance or obtain appropriate professional advice.
Start with five simple rules
You don’t need to become an AI expert to manage AI risk. List the tools you’re using, decide what information can go into them, check important results and make sure a person remains responsible for important decisions.
Explore more practical guidance →