AI Use in SMEs
AI tools are becoming part of everyday working life for many businesses. Tools like ChatGPT, Copilot, Gemini and Claude can help with drafting emails, summarising documents, analysing information and saving time on routine tasks.
Used well, they can be genuinely useful.
The challenge is that, in many businesses, these tools are already being used without any clear guidance around what staff should and should not enter into them. That can create unnecessary risk, particularly where sensitive business, client or employee information is involved.
Why this matters
If a member of staff enters confidential or commercially sensitive information into an AI tool without understanding how that tool stores, processes or uses that data, it can create issues around:
- data protection
- confidentiality
- client trust
- internal governance
- wider cybersecurity risk
There is also the issue of visibility. In many cases, business owners and managers simply do not know which AI tools are being used across the organisation, what data is being entered, or whether those tools have been reviewed from a security perspective.
This is often referred to as Shadow AI — the use of AI tools outside of an approved business process or policy.
It usually does not come from bad intent. Most people are simply trying to work more efficiently. But without guardrails in place, well-meaning use can still create real risk.
Where the risk can come from
AI-related risk is not just about the tool itself. It is also about the device being used and the environment around it.
For example, staff may access AI tools from personal laptops, home PCs or mobile phones that are not managed by your business. Those devices may not have the same protections, policies or visibility as your company-managed systems.
At that point, business information may be interacting with tools and devices that sit outside your normal IT controls.
That is why this is not just a technology issue — it is a policy, process and staff awareness issue too.
What we recommend
We are not suggesting that businesses should avoid AI altogether. In many cases, it can offer real value. The key is to make sure it is introduced in a controlled, sensible and secure way.
A good starting point would be:
1. Put an AI Acceptable Use Policy in place
This does not need to be overly complex, but it should clearly set out which tools are approved, what information can and cannot be entered, and who is responsible for oversight.
2. Train your team
Staff need clear, practical guidance on how to use AI tools safely. A short awareness session can go a long way in reducing the risk of data being shared inappropriately.
3. Review tools before they are adopted widely
Before rolling out any AI platform across the business, it is worth checking how it handles data, what controls are available, and whether it is suitable for the type of information your team works with.
How Novo IT can help
At Novo IT, we are already helping clients think through how AI fits into their business from a practical and security point of view.
That can include:
- reviewing current AI usage
- helping you create an acceptable use policy
- advising on safer setup and rollout
- supporting staff awareness and training
- helping ensure AI tools are introduced in a way that protects your business data
Next steps If you would like to have a quick conversation about how your business is currently using AI, or where the main gaps may be, we would be happy to help. Even a short discussion can help identify whether there are any obvious risks and what sensible next steps might look like.
Disclaimer: This article was created with the assistance of AI tools based on prompts and guidance provided by Novo IT Ltd.

Comments are closed