Our team will be out of office on Friday, May 1, 2026. We’ll be back and ready to assist you starting Monday, May 4th.

How Worried Should a Small Business Owner Be About AI Security Threats?

Contents

The headlines say AI can now find unknown software flaws and write working exploits without human help. This article answers the question underneath that headline: does any of it change what you should actually do on Monday morning?

The best cyber weapon built this year got locked in a drawer

On September 1, OpenAI published a page saying its forthcoming model, Astra, can find previously unknown security flaws and build ways to exploit them across many well protected systems, without a person guiding each step. It is the first model the company has ever placed at the Critical threshold of its own Preparedness Framework. Access to the most advanced cyber capabilities goes to a small group of testers first, then to vetted partners through a program called Daybreak Blue.

I read that on a Tuesday morning in Alabama with a cup of coffee going cold next to me. My first thought was not about my own business. It was about the bookkeepers, contractors, and coaches I talk to every week who already feel one step behind and now feel two.

So let me give you the direct answer before anything else.

You should be moderately concerned, and almost none of that concern belongs on Astra. Nobody is pointing a frontier zero-day research model at your seven person agency. Your real exposure is the six AI tools somebody on your team signed up for last quarter without telling you, sitting on top of a password that also unlocks your email.

That is not a comfortable answer. It is a better one, because it is a problem you can actually fix this week without a security budget.

Here is the thing about the current news cycle. The same week OpenAI gated Astra and Google put Gemini 3.8 Flash Cyber behind a trusted defender program called Fairwind, a Palo Alto startup called Abliteration.ai released a stripped down version of an open weight model advertising twice the cyber exploitation capability of its predecessor, available to whoever wants it. Defense is being rationed. Offense is being published.

That feels like a rigged game. It mostly is not, because the organizations getting hurt are not being beaten by frontier models. They are being beaten by ungoverned deployments and stolen passwords.

Key Takeaways

  • Frontier AI cyber models are being restricted to vetted partners, but that restriction is not what determines whether your small business gets breached.
  • IBM found that organizations with high levels of shadow AI paid an average of $670,000 more per breach than those with little or none.
  • Verizon's 2025 data shows ransomware was present in 88 percent of small business breaches, and stolen credentials remain the single most common way in.
  • UpGuard's survey found roughly 8 in 10 employees use AI tools their employer never approved, and senior leaders do it more than anyone.
  • Multi-factor authentication and a written AI tool inventory cost almost nothing and remove most of your realistic risk.

The problem is not the model. It is the sprawl.

Let me describe what I actually see when I work with a small team.

The owner uses ChatGPT. The marketing person prefers Claude and also has a Canva AI plan. Somebody in operations found a meeting notetaker that joins calls automatically. Someone else is running a free transcription tool nobody has heard of. The bookkeeper pastes a client statement into a summarizer to save twenty minutes. Six tools. Zero of them appear on any list. All of them touch real customer data.

Nobody did anything wrong here. Every one of those people was trying to do their job faster. That is the part most security advice gets backwards. It treats the employee as the threat. The employee is the customer.

I have spent a good part of my life on the wrong side of systems that were not built to handle reality. I went to prison. I went through bankruptcy. What both taught me is that when a system does not account for how people actually behave, people route around it, and the routing around is where the damage happens. That lesson applies directly here.

The U.S. Chamber of Commerce found that 58 percent of small businesses said they use generative AI in 2025, up from 40 percent in 2024 and 23 percent in 2023. In my home state, 57 percent of Alabama small businesses report using an AI platform. Adoption is not the problem. Adoption is happening whether or not anyone writes it down.

The problem is that adoption ran ahead of anyone deciding what data those tools are allowed to see.

And I want to be honest about the difficulty, because a lot of people write about this as if the fix is obvious. It is not obvious when you are the owner, the sales team, and the person who unclogs the sink. Security feels like a large company sport. You cannot hire a CISO. You cannot join the Daybreak coalition. Nobody is giving you a trusted defender model.

You do not need one. You need a list and a password policy. Let me show you the data that convinced me of that.

What the research actually says

1. Ungoverned AI is expensive, and the number is specific.

IBM's 2025 Cost of a Data Breach Report, researched independently by the Ponemon Institute across 600 organizations, found that a high level of shadow AI, defined as workers downloading or using unapproved internet based AI tools, added an extra $670,000 to the global average breach cost. The global average breach itself came in at $4.44 million, which is down 9 percent from the prior year. Note what that means. Breach costs went down overall. The shadow AI penalty went up.

The same report found that 63 percent of breached organizations had no AI governance policies in place at all, and 97 percent of organizations that suffered an AI related incident lacked proper AI access controls.

2. Almost everybody is doing it, including the people who should know better.

UpGuard's State of Shadow AI report, released in November 2025, surveyed 1,020 employees in the US and UK plus 542 security leaders. Roughly 8 in 10 employees reported using unauthorized AI tools. Among security leaders, 68 percent admitted the same, and 90 percent reported using unapproved AI tools at work. Seventy percent knew of sensitive data being shared with AI tools at their workplace. Twenty three percent of CISOs knew passwords and credentials were being shared with AI tools inside their own company.

The finding that stopped me: employees who had received AI safety training used unapproved tools more, not less. Greg Pollock, who leads research at UpGuard, put it plainly, saying increased training does not curtail shadow AI usage and in fact increases it.

Blocking does not work either. Forty one percent of employees said they find a way around the block.

3. Small businesses get breached by boring things.

Verizon's 2025 Data Breach Investigations Report analyzed 22,052 security incidents and 12,195 confirmed breaches. The Small and Medium Business Snapshot is the part every owner should read.

Ransomware showed up in 88 percent of small business breaches, compared to 39 percent at large organizations. Ninety nine percent of small business breaches were financially motivated, and 98 percent came from external actors. Three patterns accounted for 96 percent of them: system intrusion, social engineering, and basic web application attacks.

The primary hacking method was the use of stolen credentials, at 33 percent for SMBs. Exploitation of unpatched vulnerabilities reached 20 percent of known initial access vectors. Verizon also found that only about 54 percent of known edge device and VPN vulnerabilities were fully remediated during the year, taking a median of 32 days.

Not one of those numbers involves a frontier model.

4. Verizon caught the shadow AI problem in the raw telemetry.

Buried in the same report: 15 percent of employees were routinely accessing generative AI systems on corporate devices, at least once every fifteen days. Of those, 72 percent were using non-corporate email addresses as their account identifiers, and another 17 percent used corporate email without integrated authentication. That is roughly nine out of ten sessions happening outside any policy the company could see or enforce.

5. The cheapest control is still the best one.

Microsoft's research team, publishing on a study of Azure Active Directory commercial accounts, found that multi-factor authentication reduced the risk of compromise by 99.22 percent across the population and by 98.56 percent even when credentials had already leaked. Over 99.99 percent of MFA enabled accounts stayed secure during the study period. They also found SMS codes were 40.8 percent less effective than a dedicated authenticator app.

Stolen credentials are how most small businesses get breached. MFA stops almost all of it. That is the whole trade.

The system I use: govern the inventory, not the intelligence

When I hit a problem like this, I stop thinking about rules and start thinking about the system that makes the rule unnecessary.

Here is the reframe that changed how I advise people. You are not trying to control AI. You are trying to answer one question at any moment: what tools have access to my customer data, and who put them there?

That is an inventory problem. Inventory problems are solvable by non-technical people with a spreadsheet. Model capability problems are not.

I call it the Open Door approach, and it has three parts.

Make the approved path the easy path. UpGuard's data is unambiguous that restriction fails. Forty one percent route around blocks. So do not lead with a ban. Pay for one good business tier tool, put everyone on it, and make it the fastest option in the building. ChatGPT Business and Claude Team both carry commitments that your business data is not used to train models by default, which the free consumer tiers historically did not. That single move converts most shadow usage into governed usage without a single confrontation.

Run an amnesty, not an audit. The first time I asked a team to list every AI tool they were using, I framed it as a review. I got three tools. I re-ran it a week later framed as "I am buying licenses, tell me what you actually use so I can pay for it," and got eleven. Same people. Same week. The framing did all the work. If your people think the list gets them in trouble, the list will be a lie, and a lie is worse than no list.

Separate the data tiers before you separate the tools. Most owners try to categorize software. Categorize data instead. Green is public marketing material, blog drafts, and generic research, so use anything. Yellow is internal operations, financials, and strategy, so use approved business tier tools only. Red is customer records, health information, payment data, credentials, and anything under contract or regulation, so nothing goes in without a signed agreement. Three colors. Everyone remembers three colors. Nobody remembers a fourteen page policy.

The rest is basic hygiene that has nothing to do with AI. Turn on MFA everywhere, use an authenticator app instead of texts, and patch your gateway and VPN devices on a schedule. That is the 99 percent.

Six steps to do this week

  1. Run the amnesty inventory. Send one message: "I am budgeting for AI tools. Reply with every AI tool you have used for work in the last ninety days, including free ones. Nobody is in trouble. I just need the list." Give a two day deadline. Expect the number to be higher than you think.

  2. Turn on multi-factor authentication on email first, then everything else. Microsoft's research puts the risk reduction at 99.22 percent. Use an authenticator app, not SMS. Email first, because email is the reset mechanism for every other account you own.

  3. Buy one business tier AI seat per person who needs it. Cheaper than a single incident by an enormous margin, and it gives you an actual account you control, with the ability to revoke access when someone leaves.

  4. Write the three color data rule on one page. Green, yellow, red, with five real examples from your business under each. Send it. Do not write more than one page. A policy nobody reads is not a policy.

  5. Use AI to write your own policy. Paste this into whichever assistant you use:

    [The Job] Draft a one page AI use policy for my business that a non-technical team will actually follow.
    [The Background] We are a [number] person [industry] business. Our team currently uses these AI tools: [list from your inventory]. The customer data we handle includes [list types]. We are subject to [any regulations, or "none that I know of"].
    [The Deliverable] One page, plain English, at a ninth grade reading level. Organize it around three data tiers: green for public information, yellow for internal information, red for customer and regulated data. Give five concrete examples under each tier drawn from my business. End with two sentences on what to do if someone makes a mistake.
    [The Questions] Ask me any questions you have.

  6. Set a ninety day recurring calendar reminder to re-run the inventory. Tool sprawl is not a one time cleanup. It is a tide. Put it on the calendar or it will not happen.

Frequently Asked Questions

What is shadow AI in simple terms?
Shadow AI is any AI tool your employees use for work that leadership never approved or does not know about. IBM defines it as workers downloading or using unapproved internet based AI tools. It is not malicious. It is usually someone trying to finish a task faster with a free tool they found.

Can hackers really use AI to break into a small business?
Not in the way headlines suggest. Verizon's 2025 report found that as of early 2025, generative AI had not meaningfully changed attacker methods, though synthetically generated text in malicious emails had doubled over two years. Small businesses are still breached by stolen passwords, phishing, and unpatched systems.

Should I just ban AI tools at my company?
No. UpGuard found that 41 percent of employees find a way around blocks, and that employees with more security training used unapproved tools more often, not less. Banning pushes usage into places you cannot see. Provide one good approved tool and make it the easiest option available.

Is the free version of ChatGPT safe for business data?
Treat free consumer tiers as unsuitable for customer records, financial data, or anything under a confidentiality agreement. Business and enterprise tiers carry contractual commitments about data handling and training that consumer tiers do not. For public marketing content, free tiers are fine.

What is the single highest value security step for a small business?
Multi-factor authentication on email, using an authenticator app rather than SMS codes. Microsoft's research measured a 99.22 percent reduction in compromise risk, including 98.56 percent protection when passwords had already leaked. It costs nothing and takes about ten minutes per account.

You are not locked out of the thing that matters

Go back to where we started. OpenAI locked its most capable cyber model behind a coalition you will never be invited to. Google did the same with Fairwind. Meanwhile an unrestricted model advertising double the exploitation capability is available to anyone with a credit card.

I understand why that reads as helplessness. The people with the good tools are protecting the people with the good tools, and you are standing outside the fence.

Candidly, that fence protects a different kind of target than yours. Frontier zero-day research is aimed at hardened operating systems, browsers, and critical infrastructure. Your business does not get attacked that way. Your business gets attacked because a password showed up in a credential dump, or because a spreadsheet full of customer data got pasted into a tool nobody approved, or because a firewall went unpatched for four months.

Every one of those is inside your control. Not a vendor's control. Yours.

The gap between businesses that get hurt and businesses that do not is almost never budget. IBM measured the gap at $670,000 and named the cause: no governance, no access controls, no idea what tools were in the building. That is not a spending problem. That is a knowing problem.

So make the list. Turn on MFA. Buy the business tier. Write the one page. You will be ahead of most companies ten times your size, and it will cost you an afternoon.

You cannot control what gets built in San Francisco. You can absolutely control what walks in your front door.


About the author

Jonathan Mast is the founder of White Beard Strategies, where he teaches non-technical entrepreneurs to use AI to amplify the skill and experience they already have. He runs the AI Insiders membership, leads live AI trainings, and speaks on AI for business owners. He runs the same tool inventory on his own team every ninety days, and it has never once come back with the number he expected.

Sources

About the Author