Skip to content
RADIUSTECHNOLOGY
AI & Automation·Published 10 September 2026

How should a small business use AI safely?

In many small businesses AI is already present. Not as a programme. As a habit. Someone pastes a customer email into a public chatbot. Someone asks a tool to summarise a contract. Someone generates a first draft of a proposal and sends it with only a skim.

The gap is not “whether AI will change business”. The gap is between informal use and a business that has decided what is allowed, what is useful, and who is accountable for the output. Radius looks at that gap the same way it looks at any other technology: start with the process, not the tool.

Assume informal use until you have evidence otherwise

If you have not asked, you do not know. People use the tools that remove friction. Public AI products are easy, fast and outside the tenant. That does not make staff reckless. It makes the current process slow or unclear.

So begin with a calm inventory: where is AI already used, for what, and with which tools? Microsoft Copilot, other approved products, and public websites are different risk profiles. “Not sure” is a valid answer. It is also a reason to keep asking.

Approved tools are a decision, not a vibe

An approved tool is one the business has chosen, can administer, and can explain. An unapproved tool is everything else, however convenient.

Approval should consider where data goes, whether the vendor trains on prompts, how identity is handled, and whether you can turn it off. It should not be a logo on a slide.

Sometimes the approved answer is Microsoft 365 Copilot for a defined group. Sometimes it is a narrower tool for a single workflow. Sometimes it is “not yet”. AI and automation as Radius manages it starts there: discovery, then a proportionate choice.

What must not be pasted into a prompt

Staff need plain guidance, not a legal essay. The useful rule is: if you would not put it on a postcard, do not put it into a tool you do not control.

  • Passwords, keys, one-time codes and any credential.
  • Customer records, health or financial details, and anything you would treat as confidential in email.
  • Unreleased pricing, contracts, or advice that is still internal.
  • Other people’s personal data that the business holds because it has to.
  • Security incident details, network diagrams, or “just the error message” that includes internal hostnames and tokens.

Identity, privacy and security are part of the same conversation

If a tool is tied to a work identity, you can usually see who used it and revoke access. If it is a personal account on a phone, you cannot. That is an identity decision as much as an AI decision.

Privacy is about what the business has told customers and staff it will do with information — and what a public model vendor will do with a prompt. Do not claim a product “makes you compliant”. No chatbot does that automatically.

Cyber security still applies: phishing that uses AI-written language, over-permissioned add-ins, and staff who cannot tell a plausible answer from a correct one. The Radius Standard treats identity, data and improvement as connected areas, which is the right shape for this problem.

Governance that a small business will actually use

You do not need a 40-page AI policy before anyone is allowed to think. You do need a short acceptable-use note, a named owner, and a way to ask “is this a good use?” without being made to feel foolish.

  • Which tools are approved, and which are not.
  • What information must never be entered.
  • Who can enable new AI features in Microsoft 365 or other platforms.
  • How outputs are checked before they reach a customer, a regulator, or a decision that costs money.
  • How you will train people once, then remind them when the tools change.

Human oversight is the control that still works

AI can draft. It can classify. It can summarise. It cannot take responsibility. If a quote, a diagnosis, or a customer reply goes out, a person still owns it.

Checking outputs is a skill: numbers, names, legal-sounding sentences, and anything that cites a source you have not opened. The more fluent the writing, the easier it is to skip the check.

Start with the process. Sometimes do not use AI at all.

Ask what is slow, repetitive, or error-prone. Then ask whether the existing software already does it. Then ask whether a straightforward workflow — a template, a shared mailbox policy, a Power Automate flow, a better form — would remove the grind without introducing a model.

Ordinary automation is often the better first move. It is inspectable. It does the same thing on Tuesday as on Thursday. Automate your business is written that way on purpose.

Sometimes the right answer is not to automate. The volume is too low. The judgement is too high. The data is too sensitive. Saying no is a professional outcome, not a failure to be modern.

Value is measured in time saved, mistakes avoided, and work that actually ships — not in the number of AI features switched on.

A practical sequence

Find the informal use. Write the short rules. Pick one process where the benefit is obvious and the data is boring. Decide whether AI, ordinary automation, or a better manual method is the fit. Put a person on the output. Review after a month, not after a keynote.

If you want that conversation against the rest of the environment — identity, Microsoft 365, and how staff already work — use a Technology Review. It asks about AI without pretending a questionnaire is a guarantee.

If this is the conversation you need to have, start with a Technology Review.

Bring the environment as it is. Radius will use what you share to prepare for a useful first discussion — without a score or a script.

Get a Technology Review