The headlines worry about AI agents acting autonomously and causing harm. For most small and mid-sized businesses, that is not where the danger lives. The danger is already on your team’s screens, in a browser tab, right now.
It’s called shadow AI: staff using personal accounts on unapproved AI tools to get their work done. It is not malice. It is people being resourceful. But roughly 80% of AI use at smaller firms is staff bringing their own tools, and a good share of those chats involve sensitive data leaving your control. That is the number-one AI risk for a small and mid business, and it is mundane, not cinematic.
Why banning tools makes it worse
The instinct is to lock everything down. That reliably backfires: when the approved path is slower than the personal ChatGPT tab, people quietly take the faster path, and now you have the same exposure with none of the visibility. Banning tools produces shadow AI; it doesn’t prevent it.
The cheapest control that actually works
A one-page AI policy is the highest-value control a small business has, per the Hekima IQ benchmark. It’s a short list of approved tools and a short list of data rules, not a 40-page governance manual. One page that answers two questions:
- Which tools are approved? Name them. Set up at least one to keep zero copies of your data.
- What data must never go into them? Name it plainly: customer personal data, anything under contract or regulation, passwords and logins.
Pair that with a single human check on anything a customer sees. That’s the lesson of the Air Canada chatbot case, where an unreviewed AI answer became a binding promise. A few hours of work closes the most common failure mode.
That’s the pattern across everything in the benchmark: the controls that protect a small and mid business are cheap, fast, and decided rather than bought.