There is a certain inevitability about how businesses adopt new technology. First comes the excitement. Then the overconfidence. Then, usually, the incident.
Artificial intelligence is no exception. In fact, it may be the fastest we’ve ever gone from “this will change everything” to “who exactly approved this?”
SMEs, understandably, are being told they must adopt AI or risk irrelevance. Fine, sensible, even. But what tends to get left out of the enthusiastic sales pitch is the small matter of what happens when your data, your customers, and occasionally your entire business logic are quietly handed over to a system you don’t fully understand.
Take Samsung. A company not typically associated with amateur mistakes. In 2023, employees helpfully uploaded sensitive internal code into ChatGPT to “improve” it. Which it probably did. Along with improving OpenAI’s understanding of Samsung’s intellectual property. Samsung’s response was swift, and well, elegant. Ban it. Entirely. The lesson is not subtle. If your staff are pasting confidential information into public AI tools, you do not have an AI strategy. You have a leak.
Then we have Sears Home Services. Not content with the usual levels of corporate misjudgement, they managed to expose millions of customer interactions. Chat logs. Audio recordings. Names, addresses, the lot. All sitting there, unsecured, like an MI5 briefcase left behind in a busy London train station. This was not some elite cyber-attack. No shadowy figures in hoodies. Just a database that wasn’t locked. The fix, incidentally, was not a revolutionary breakthrough in cybersecurity. It was basic competence.
And if those feel like outliers, they aren’t. One AI chat app leaked 300 million messages tied to 25 million users. Which is impressive in the same way a ship sinking on its maiden voyage is impressive.
Again, the cause was not some exotic flaw in artificial intelligence. It was the digital equivalent of leaving the front door open and putting a sign outside saying, “important things inside”.
Even the consultants, who are usually very good at explaining why other people’s problems are complex, have had their turn. A red-team experiment showed that an AI agent accessed millions of internal records via a chatbot system within hours.
Which raises an interesting point. We are not just using AI. We are now giving it access to things. Important things. The pattern in all of this is depressingly consistent. Nobody sets out to create a security disaster. They simply assume that because something is clever, it must also be safe. Which, of course, it isn’t.
For SMEs, this is where things become slightly uncomfortable. AI is marketed as plug-and-play. Turn it on, improve efficiency, and enjoy the future. What is less advertised is that you are also extending your risk surface, often without realising it.
The fixes are not complicated. Which makes them even easier to ignore. Do not put sensitive data into tools you do not control. Know where your data goes. Control who can use what. Assume that anything convenient is probably risky.
None of this is particularly exciting. There are no keynote speeches about access controls. No one wins awards for not leaking customer data. But it does tend to keep you out of the headlines. AI, we are told, is a competitive necessity. And it is. But so is not accidentally publishing your internal documents to the internet.
The uncomfortable truth is that AI has made powerful tools available to everyone. Including, very helpfully, the ability to make very large mistakes very quickly. And if the current trajectory is anything to go by, we are only just getting started.
By Peter Zanatta




