Whether or not your business has made any decision about AI, your team is almost certainly already using it. Someone is summarising meeting notes in a free chatbot. Someone is polishing customer emails. Someone has pasted a supplier contract in and asked what it means. None of this is malicious, and most of it is helpful. But it means the real security question is not “should we allow AI” but “what is already happening, and which parts need rules”.
Before consulting, I spent 13 years as CTO of a security software company used by police forces and government organisations, and I hold a certified penetration testing background, so this is the lens I naturally bring to AI. The good news is that securing AI use in a small team is mostly not technical. It is a handful of habits and one page of rules.
The biggest risk is quiet, not dramatic
The largest AI security problem in most small businesses is not hackers. It is well-meaning staff using free, personal AI accounts for work, sometimes called shadow AI.
The distinction that matters is between personal accounts and business ones. Free personal accounts generally offer weaker data controls, may use what you type to improve the service, and give the business no visibility and no admin settings. Business plans exist precisely to fix this: they come with commitments not to train on your content, and controls an owner can actually manage.
The wrong response is a ban. Bans do not stop the behaviour; they push it underground, onto personal phones, where you have even less visibility. The right response is to give people an approved route that is genuinely good, and a short set of rules that travel with it.
What should never go into an AI tool
The rules themselves are not complicated. Customer personal data, staff records, financial details, passwords and anything commercially sensitive should never go into an unapproved or personal AI tool. If in doubt, swap real names and figures for placeholders; the tools work almost as well with “Customer A” as with the real name.
I keep a fuller set of ground rules, free to copy, in the resource library on this site, along with a prompt that acts as a quick self-check before you hand any task to AI. If your business has nothing written down yet, those two links are a sensible first afternoon’s work.
The new tricks aimed at your team
AI has also changed what attacks look like, and your team should know about three patterns in particular.
Phishing has lost its accent. The old advice to look for clumsy wording is dead, because attackers now write with the same tools you do. The tell is no longer the language; it is the request. Anything that asks for credentials, payments or urgency needs verifying through a known channel, however well written it is.
Voices and faces can be cloned. There is a now well-documented pattern of fraud in which a “director” phones or video-calls a member of staff to authorise an urgent payment, using cloned audio or video. The defence is procedural, not technical: agree in advance that no payment or bank-detail change ever happens on the say-so of a call alone, and always verify through a second, known route, such as phoning the person back on the number you already hold. A rule like this costs nothing and closes the door.
Agents need narrower access than chatbots. As I covered in my piece on the main AI providers, the newest tools are agents: you give them a whole task and access to files or an inbox, and they work through it themselves. That access is exactly why they deserve more care. An agent that reads documents can be misled by instructions hidden inside a document, an email or a web page it processes, which security people call prompt injection. The plain-English rule: give an agent access the way you would give a brand-new temp access. Only the folders it needs, nothing it must not see, and the consequential decisions, payments, sending, deleting, stay with a person.
The AI already switching itself on around you
Not all AI arrives because you chose it. Meeting tools now offer recording and transcription, CRMs ship “AI assistants”, inboxes offer summaries. Each of these is a decision about where your data flows, and each one deserves an owner. Someone in the business should be able to answer: which tools have AI features turned on, what data do they see, and where does it go? When a supplier announces a shiny new AI feature, that is a settings review, not just good news.
Five moves that cover most of it
Pulling this together, five moves give a small team most of the protection that matters. Choose one approved AI tool and put it on a business plan, so the data protections actually apply. Write the rules on one page, in plain English, covering what never goes in, personal versus business accounts, and checking output before it is used. Train the team once, properly, with real examples from your own work, because a rule nobody has seen demonstrated is a rule nobody follows. Agree the verification habit for money and credentials, the phone-back rule above, and make it culture rather than paperwork. And review quarterly what has crept in: new tools, new AI features, new habits.
If you want to go deeper, the two best free UK starting points are the National Cyber Security Centre, which publishes clear guidance on using AI securely, including the newer agent-style tools, and the Information Commissioner’s Office, whose guidance covers AI and personal data. Both are written for organisations, not specialists.
Where this fits
Everything above is what AI governance means in practice for a small business. Not a binder on a shelf, but an approved tool, one page of rules, a trained team and a couple of habits that close the expensive doors. It is genuinely achievable in a few weeks.
If you would like help putting it in place, that is exactly what my AI governance work covers, and the training side, getting your whole team using AI well and safely, is what AI training and workshops are for. Or, if you would rather start with a conversation, book an AI discovery call and we will talk through where your business actually stands.