Lesson 1 of 6

Why this matters for a small business

Data and privacy risk is not just a big-corporate problem. What is actually at stake when a small business puts AI to work, and why it is manageable.

Every “data breach” headline features a household name: an airline, a bank, a retailer with millions of customers on file. It is easy to read those stories and quietly file the whole topic under “not my problem”. You run a forty-person manufacturing business, or a professional services firm working out of a shared inbox, or a distributor whose whole office depends on one spreadsheet. Nobody is coming for you.

That instinct is understandable. It is also the one thing this lesson wants to gently put right, because the size of your business has almost nothing to do with the size of the risk. What matters is not how big you are. It is what you hold.

What a small business actually holds

Look at what sits in an ordinary business on an ordinary Tuesday. An HR shared drive has staff addresses, dates of birth and sickness notes. A sales pipeline has named contacts at every client, what they pay and what they nearly cancelled over. A finance inbox has bank details, signed contracts and a spreadsheet of card payments somebody exported once and never deleted. A field service scheduler has a client’s site address, a note about who holds the keys and an out-of-hours number for when something fails at two in the morning.

None of that is exotic. It is completely normal, everyday information that keeps a small business running well. It is also exactly the kind of information that deserves care, whether you have five customers or five thousand.

Where AI actually enters the picture

Most owners’ AI use is not one dramatic event. It is a dozen small moments a week: drafting a reply to a customer, tidying up a quote, summarising a long email chain before a call. Each one is harmless on its own. The risk shows up when one of those ordinary moments involves pasting in something it should not, into a tool with the wrong settings.

That is the real shape of the risk, and it is worth saying plainly: it is not hackers breaking down a digital door. It is a normal, well-meaning person, in a hurry, pasting a customer’s full details into a free chat tool because it was the fastest way to get the job done. Nobody meant any harm. It still matters, because that customer trusted you with their information, not a stranger’s server they never agreed to.

Why this is good news, not bad news

Here is the reassuring part. Because the risk is mostly about a handful of habits rather than technical defences, it sits entirely within your control, and it does not take a specialist to get right. You do not need an IT department or a compliance officer. You need to know what to keep out of a chat window, which settings matter, and what a sensible policy looks like for a team your size.

That is the whole point of this course. Nothing in it is designed to make you nervous about using AI. If anything, the opposite: once you know where the real risks sit, you can stop half-worrying every time you open a chat tool, and just get on with using it well.

Next, the single most useful list in this course: exactly what should never go into a general AI chat tool, and why.

Want the fuller version of this? Our guide Is your data safe with AI? An honest answer goes deeper on what actually happens to what you type in.