AI risk

The AI risk in your business is probably something somebody pasted

The AI risk in your business is probably something somebody pasted

A recruitment client asked me to build them a filter and pull a list of senior people in a particular industry, in a particular pay bracket, off LinkedIn.

So I did. It came back with about 150 people across seven companies, with the information you would need to contact all of them.

It worked exactly as asked. I came away from it thinking I probably should not have done that.

Around the same time I built something else. An app that scans a pile of loose Lego bricks and works out which sets they came from. It needed parts databases that other people had put together over years.

I emailed them all first and asked whether it was alright to use them.

Same person, same month, two completely different standards. The difference was not the technology. It was whether anybody stopped to ask.

Why capability arrives before judgement

This is the fourth of the four Ds in Anthropic's AI fluency work, which I teach and did not invent. Delegation, description, discernment, and then diligence.

Diligence is on the list precisely because the first three make you fast enough to do something you would not have done slowly.

Nobody was going to hand collect 150 profiles. The friction would have stopped them somewhere around the fourth one, and the friction was doing a job nobody had noticed it was doing.

Take the friction away and the question "should I" has to be asked deliberately, because it is no longer being asked for you.

What the risk actually looks like in a small business

Not a rogue system. Somebody pasting.

Research from MIT's Project NANDA found that around 90 per cent of the employees they surveyed use personal AI tools for work, while only around 40 per cent of their companies had bought official subscriptions. That study is small at 153 respondents and self labelled preliminary, so treat the number loosely.

The shape of it is right though, and DSIT says something similar: informal AI use is largely unmeasured, which means official adoption figures probably understate what is happening.

In practice that means somebody in your business has an account you do not know about, and has at some point pasted in something they should not have. A customer list. A contract. Somebody's medical details, if you are in healthcare.

They were not being reckless. They were trying to get a job done at half past four.

The three things worth doing

Say which tool. Not a policy document. One named tool that the business pays for, so people are not using their personal accounts on the free tier where the terms are different.

Say what never goes in. Customer personal data, anything covered by a confidentiality clause, anything from a client system. Three lines, and everyone can remember three lines.

Turn off training on your inputs. Every major tool has this setting on business plans, most people have never looked at it, and it takes about ninety seconds.

That is most of the risk dealt with. It is not exciting and it is not what an AI security consultant usually gets asked about, and it is where the actual exposure is for a business of ten or fifteen people.

What you could do on Monday

Ask your team, without any consequences attached, which AI tools they currently use for work.

You have to genuinely mean the no consequences part or you will get a room of blank faces and learn nothing.

The Federation of Small Businesses found 92 per cent of small business owners now report worries about AI related risks. Most of that worry is unspecific. Twenty minutes of asking turns it into a list, and a list is a thing you can actually deal with.

The honest limit

None of this makes you compliant with anything.

If you handle health data, or you are bound by a client's security requirements, you need somebody who does that properly, and that is not the same job as mine. I would rather say that than take the work.

And I would not read the LinkedIn story as an argument for banning things. The team that gets told no will use their phones instead, and then you have the same exposure with none of the visibility.

The useful version is a business where somebody can say "I was going to put this in, is that alright" and get an answer. That is a culture question more than a security one, and no consultant installs it for you.

Chris Matthews runs Altrincham AI, teaching small businesses across Greater Manchester and Cheshire how to use AI properly, and building the workflows that come out of it.

Based in Altrincham. Monday to Friday, 08:00 to 17:00. Call 0161 883 7818, or book a free 45 minute consultation.

More on this: AI consulting services.

Not sure where the easy win is in your business?

That is what the 45 minute diagnostic is for. No charge, and you get an honest answer even if the answer is not yet.

Book a consultation

More on this

AI in construction: what small firms get, and what they do not

AI in construction, for firms with twelve people rather than twelve sites. What the ONS numbers say, the job we tried to automate and stopped, and what works.

Read it →

AI sales training is mostly not about AI

AI sales training is mostly not about AI. What the BCG study shows about who gains most from these tools, and what sales teams actually need shown.

Read it →

What a business automation consultant should tell you not to automate

What a business automation consultant does, what it costs in the UK, when to hire one, and the jobs a good one will talk you out of automating.

Read it →