Five AI Decisions Every Small and Medium Business Should Make This Quarter


Your team already made the AI decisions you have been putting off. They picked the tools, chose the accounts, and decided what client data goes into them, one paste at a time, without a single meeting. Getting back in charge is not a transformation project. It is five specific decisions, and most of them take one meeting each.
We spent the last three weeks in the details: nine industries' worth of rules that already reach AI, then the tools themselves, tier by tier. This piece is the other altitude. If you run the business, these are the calls only you can make, and the order matters.
Decision 1: Which accounts your business sanctions
The most consequential AI fact in your company is not which tools your staff use. It is which login they use, because the login decides the terms. On the personal tiers of the major AI assistants, what gets pasted in can be used for training, reviewed by people, or kept for years; on the business tiers, training is off by default and a data processing agreement is available. We laid the terms side by side, from the vendors' own pages, and the difference is close to opposite.
The scale of the problem is measured: Verizon's 2026 Data Breach Investigations Report found 67 percent of users accessing AI services on corporate devices were using non-corporate accounts, and 45 percent of employees are now regular users of AI on their work devices, up from 15 percent a year earlier. Those are cross-industry figures, and they mean the default state of a small business is AI on personal terms.
The decision: your business sanctions business accounts, and pays for them where the tool has earned its place. It usually costs less per seat than the phone bill, and it is the one move that does the most to flip the terms in your favor.
Decision 2: What goes on the approved list, and the one rule
You cannot approve or ban tools you have not found, so this decision starts with an inventory: every AI tool, browser extension, and agent on machines that touch sensitive work, and which account each runs under. IBM's 2026 Cost of a Data Breach study found shadow AI involved in 43 percent of the security incidents it examined, up from 20 percent the year before, which is what unmanaged adoption looks like at scale.
With the inventory in hand, the decision is a short approved list plus one rule that removes the judgment call for staff: sensitive client, patient, financial, or employee information goes only into tools on the list, and summarizing or rewriting counts as going in. Nine industries of rules, from HIPAA to trade secret law to the contracts you signed, all land on that same rule. Everything else your staff want to try can stay fair game with non-sensitive data, which keeps the list short and the policy livable.
Decision 3: Whether your data needs a contract, not just a tier
If your business touches regulated or contractually protected data, a paid business tier is the floor, not the ceiling. Patient information wants a Business Associate Agreement, and the vendors' own pages are specific about which offerings can carry one and which never do; our BAA comparison walks through them. Client-confidential work may be governed by the AI clauses now appearing in real services agreements, which prohibit AI use or client data in AI tools without prior written consent. Financial, tax, and donor data each have their own layer from the series.
The decision here is really a question you take to counsel, and it is a cheap question: given the data we hold, which tools need a BAA, a data processing agreement, or a client's written consent before they touch it? What makes the question answerable is the inventory from decision 2. What makes it urgent is that clients and carriers have started asking it.
Decision 4: Your recording policy
Meetings deserve their own decision because the tools capture other people's words, not just yours. An AI notetaker joins under one participant's terms, some notetakers train on de-identified recordings, some auto-share the transcript with everyone on the invite, and recording-consent law has always applied: under state law, Virginia is one-party and Maryland requires everyone's consent, and the class actions have started. The notetaker piece has the vendor-by-vendor detail.
The decision: client and confidential calls are recorded only with notice to everyone on the call, and only into an approved tool, which for most small businesses means the meeting platform's own assistant on the business account you already control. One sentence in your meeting invites ("this call may be summarized by our meeting assistant") does most of the work.
Decision 5: Who owns AI in your business
Every decision above decays without an owner. Vendor terms move with weeks of notice, new tools show up on staff machines monthly, and the survey data says most organizations are behind their own adoption: Vanta's 2025 State of Trust research, a survey of 3,500 business and IT leaders, found nearly two-thirds saying their use of agentic AI outpaces their grasp of it, and fewer than half with a framework for granting or limiting AI autonomy.
The decision is a name, not a committee: one person, in most small businesses the owner or the operations lead, who approves additions to the list, re-checks the terms of approved tools quarterly, and reviews the inventory when it refreshes. Give that person one recurring hour a month. That is enough governance for a 10-to-50-person business to start with.
The honest part
None of this makes you compliant with anything by itself, and a policy document nobody enforces is worth exactly what the transcript incidents, the questionnaires, and the class actions say it is worth: nothing. The five decisions work because they are small, sequenced, and enforceable, not because they are written down. And the first two, the accounts and the list, do most of the work: they are the difference between AI use your business can defend and AI use it discovers later.
Where we fit, and where we do not
We are not lawyers or compliance consultants, and decisions 3 and 4 end at your counsel's door. We also do not make these decisions for you; they are yours for a reason.
What we run is the layer under decisions 1, 2, and 5. Our Managed AI Security service starts with a free AI Discovery: a light install, about a week of quiet observation, then a report of the AI tools, extensions, and agents found in use across your machines, including which are signed into personal accounts, risk ranked in plain English. That report is decision 2's inventory, delivered instead of assembled. From there we enforce the approved list you set and keep watching as new tools show up, which is most of the owner's recurring hour handled. It supports the decisions above; it does not replace the ones only you can make.
The question worth asking this week
Not "do we need an AI strategy." Ask the five-for-five question: of the five decisions above, how many has your business actually made, and how many did your staff make for you?
We work with small and medium businesses nationwide from our home base in McLean, Virginia. If you are in Washington DC, Northern Virginia, Maryland, or anywhere in the country and you want to start with the inventory that makes the other four decisions possible, book a free 15-minute call. The discovery is free, and the decisions stay yours.
Comments