Most small businesses I talk to did not decide to start using AI. It arrived. The accounting software added a summarising feature, the email client started suggesting replies, somebody on the team began pasting things into ChatGPT because it was quicker, and at some point a supplier mentioned putting a chatbot on the website.
So the useful question is not whether to use AI. It is where to let it near, and on what terms. This is the guide I give people when they ask me that, and it links out to the longer pieces where a point deserves more room.
Start with what it touches, not what it does
Every AI feature pitch is about capability: what it can write, summarise, answer or generate. That is the least useful thing to evaluate first, because almost all of them can do the thing.
What actually separates a safe deployment from an awkward one is what the tool can reach. What data it can see. Whose data that is. Whether it can act, or only suggest. Whether anyone checks its output before it reaches a customer.
Before adopting anything, write down what it will be able to see and what it will be able to do. If you cannot answer either from the product page, that is your first question for the vendor, not a detail to sort out after go-live.
Where AI actually shows up in a small business
It helps to separate these, because they carry very different risk and very different fixes.
- Features added to software you already pay for. You did not choose these and you may not know they are switched on. They usually have access to whatever that system already holds, which for a CRM or an inbox is a great deal.
- Tools you or your team use directly. ChatGPT, Claude, Copilot and the rest. The risk here is almost entirely about what gets typed in.
- Anything you put in front of customers. A website chatbot, an automated reply, a booking assistant. This is the only category that speaks in your name to people you have never met.
The third is where I spend most of my time, because it is the one where a mistake is public and the business cannot see it happening.
What you type into it goes somewhere
Anything typed into a general AI tool leaves your business. Where it goes, how long it stays, and whether it is used to improve the model varies by product and by which tier you are on, and the answer on a free consumer account is frequently not the answer on a business one.
That matters most for the things people paste in without thinking: a customer's email thread, a supplier contract, a spreadsheet of names and numbers, a CV somebody sent in. None of that feels like a data transfer while you are doing it.
I have written that up separately, because the detail is worth having: what happens to what you type into an AI tool.
Anything public-facing needs limits written down
A bot on your website answers strangers, in your name, while nobody is watching. The line I hold to is that it can gather, but a person commits. It can collect everything needed for a quote. It should not send back a price, confirm a slot, or agree to a deadline without you in the loop.
The longer version of that argument, including what to ask whoever builds it, is here: what a chatbot should and should not be allowed to do.
You keep the time saving either way, because the tedious part is collecting the details, not the ten seconds it takes you to approve them. What the limit buys you is never being held to a number you did not agree.
It will be confidently wrong sometimes
Language models produce fluent text whether or not they have the facts. They do not signal uncertainty the way a person does, so a wrong answer arrives with exactly the same confidence as a right one.
This is not something you can configure away, and it is not a reason to avoid the technology. It is a reason to decide, per use, whether being occasionally wrong is survivable. Drafting a first version of a newsletter, it plainly is. Telling a customer what their warranty covers, it plainly is not.
Sort your intended uses into ones where a person reads the output before it matters, and ones where it goes straight out. Everything in the second group needs a much harder look, and some of it should move into the first group instead.
Someone will try to misuse anything you put in public
If you run a public-facing bot, people will try to talk it into behaving badly. Some are curious, some are bored, and a few want something they can screenshot. There is a specific technique for this, called prompt injection, and it is worth understanding in outline even if you never build anything yourself, because it is the right question to put to a supplier.
Explained without the jargon, here: what prompt injection is, and why it matters to your business.
Where personal data is involved, the rules do not change
Putting a process through an AI tool does not move it outside UK GDPR. If the process handled personal data before, it still does, and the same obligations apply: a lawful basis for it, only the data you actually need, a retention period, and the ability to find and delete someone's information if they ask.
Two practical points come up constantly. Your privacy notice should reflect what you now actually do, including any AI provider processing data on your behalf. And a chatbot that collects enquiries is collecting personal data, so those conversations need somewhere to live and a point at which they are deleted.
Anything more specific than that is a question for someone qualified to answer it. I build to these requirements. I am not the person to advise you on your particular obligations, and I would treat anyone in my position who told you otherwise with some caution.
The fuller version, including processor contracts, lawful basis, special category data and being able to honour a deletion request, is here: can I use AI on customer data.
If it goes wrong, it is generally your problem
Worth being direct about this. If something you deployed gets it wrong in public, the customer experienced your business getting it wrong, and most provider contracts have already placed the risk of a bad output on whoever deployed it rather than on the provider.
That is manageable rather than alarming, and it mostly comes down to the same rule as everywhere else on this page: let it gather, let a person commit. The full picture, including what your supplier's contract probably says and the insurance question almost everyone forgets to ask, is in who is responsible when an AI gets it wrong.
A short checklist
If you take nothing else from this, these are the questions worth asking of any AI tool before it goes near your business:
- What can it see, and whose information is that?
- Can it act, or only suggest? If it can act, what is the worst thing it can do unsupervised?
- Does anything it produces reach a customer without a person reading it first?
- Where does what we type in go, and is it used for training?
- If it is public-facing, what happens when someone tries to talk it into misbehaving?
- If personal data is involved, does our privacy notice still describe what we actually do?
None of these need a technical background to ask, and the quality of the answers tells you a lot about whether a tool was built by people who thought about this or people who shipped a feature.
Once you have your answers, the next job is turning them into something your team can follow without having to remember this page: how to write an AI policy your team will actually follow, with a one-page template you can lift.
If you would rather talk it through against your actual setup than work from a general guide, that is what I do. The AI Setup Package is this conversation with your own workflow in front of us, and Custom Business Bots covers the public-facing side.
