AI Security Basics for Small Businesses: What to Ask Before You Say Yes
Most small business owners do not think of themselves as making a security decision when they sign up for a new AI tool. They think of it as trying something that might save time. But every AI tool you connect to your business, whether it drafts emails, screens candidates, or answers customer questions, gets access to some of your data. That makes it a security decision whether you treat it like one or not.
This is not a call to be afraid of AI. It is a call to ask a short list of sensible questions before you hand any tool access to client information, financial records, or staff data. The businesses that get burned are rarely the ones that asked too many questions. They are the ones that asked none.
Why this is an operations question, not just an IT question
In a business with five to fifty people, there is usually no dedicated security team. The decision to adopt a new tool often sits with whoever is closest to the problem: an office manager choosing a scheduling assistant, a sales lead trying an AI note-taker, a founder testing a chatbot over a weekend. None of that is wrong. But it means security questions need to be answerable by a non-technical person, not buried in a document only an engineer would read.
That is the same discipline behind everything Claro Builds does. You do not fix a process by bolting on a tool and hoping for the best, and you do not adopt a tool safely by skipping the questions that protect your business. Security basics belong in the same conversation as "does this actually fix the problem," not a separate one that happens later, if at all.
The questions worth asking before you adopt any AI tool
You do not need to understand encryption standards to ask good questions. You need to know what to ask and what a reasonable answer sounds like. Before connecting an AI tool to anything sensitive, ask the vendor:
- Where does our data actually live? Some tools store data locally, some store it in the vendor's own servers, and some pass it through a third-party AI model provider as well. You are entitled to a straight answer.
- Does the tool train its underlying model on our data? Some AI products use customer data to improve their models for other customers unless you specifically opt out. For anything involving client information, you generally want this switched off.
- Who inside our business can see what? A tool with one shared login for the whole team removes any ability to know who accessed what, or to remove access when someone leaves.
- How long is our data kept, and can we delete it? A vendor that cannot answer this, or cannot explain how to delete your data on request, is telling you something about how seriously they treat it.
- What happens if the vendor is breached? Ask whether they carry a written incident response process and whether they are contractually obliged to tell you if something goes wrong.
- Is there a signed data processing agreement? If a vendor cannot produce one, that alone is worth pausing over before you connect client data.
None of these questions require you to be technical. They require you to expect a straight answer and to notice when you do not get one. For a deeper look at spotting an overconfident pitch in the first place, see the warning signs that a vendor is overselling what their tool can do.
Client data and staff data need different rules
It is tempting to treat all data the same way, but client data and internal staff data carry different obligations and different risks if something goes wrong. Client data often comes with a duty of confidentiality, sometimes a contractual one, and mishandling it can cost you the relationship even if nothing technically illegal happened. Staff data, particularly anything to do with performance, health, or personal circumstances, deserves the same caution you would apply to any HR record, AI tool or not.
A useful habit is to ask, before connecting any tool: what is the worst reasonable outcome if this data ended up somewhere it should not be, and could we explain that outcome to the client or employee affected. If the answer makes you uncomfortable, that discomfort is doing its job. This is covered in more depth in the questions to ask before you trust an AI tool with client data.
What a good answer actually sounds like
A vendor that takes security seriously will usually be able to answer these questions quickly, in writing, without you having to chase them. They will have a plain-language privacy policy, not just a lengthy terms of service document nobody reads. They will be able to name where data is hosted and confirm, specifically, whether your data trains their model. They will not treat the question as an inconvenience.
A vendor that hesitates, redirects, or answers a different question than the one you asked is telling you something too. It does not automatically mean the tool is unsafe. It means you have not yet had your questions properly answered, and that is reason enough to slow down before rolling the tool out across the business.
Security basics belong in the assessment, not an afterthought
The Claro Build Framework starts with Assess for exactly this reason. Before anything gets designed or built, we look at what data a process touches, who needs access to it, and what a new tool would actually be able to see. Security is not a separate checklist bolted onto the end of a project. It is part of understanding the process itself, which is the whole point of assessing before building anything.
If your team is already experimenting with AI tools without anyone having asked these questions first, that is common, and it is fixable. It does not require ripping everything out. It requires a short, honest look at what is connected to what, and a plain answer to each of the questions above. For more on general AI questions, see AI Explained Simply. If you want a second opinion on what has already been connected, or you are about to adopt something new, that is a conversation worth having before the tool is embedded in how your team works, not after.
A short habit worth building: review access every time your team changes
Most businesses set up an AI tool once, grant access to whoever needs it at the time, and never look at that list again. Six months later, someone who left the business two months ago can technically still open a tool connected to client records, because removing access was never anyone's specific job. This is not a dramatic failure. It is an ordinary oversight, and it is one of the easiest security gaps to close.
A simple habit fixes most of this: whenever someone joins or leaves a role that touches a given AI tool, that is the trigger to update access, not a quarterly reminder that gets pushed back repeatedly. Pairing this with a short list of who currently has access to what, kept somewhere the whole team can check, turns a vague sense of "we should probably look at that" into something that actually happens.
What this looks like for a business with no dedicated IT person
Owners sometimes assume that proper AI security requires hiring someone technical, or paying for an expensive audit before adopting anything. For most small and mid-sized service businesses, that is not the case. The questions in this article can be asked and understood by anyone running the business, and the habits that follow, reviewing access, checking retention policies, confirming a data processing agreement exists, do not require specialist knowledge to maintain.
What they do require is treating security as a normal part of choosing and running a tool, rather than a box to tick once at the start and then forget about. A business that builds this habit early tends to avoid the far more expensive version of this problem: discovering a gap only after a client asks a direct question you cannot answer confidently.
Frequently Asked Questions
Do I need a technical background to ask AI security questions?+
No. The questions that matter most, such as where data is stored, who can access it, and whether it is used to train the vendor's model, do not require technical knowledge to ask or to evaluate the answer.
Is it safe to use AI tools with client information at all?+
Many AI tools can be used safely with client information, provided the vendor gives clear answers about storage, access, retention, and deletion, and you have a data processing agreement in place where appropriate.
What is the biggest red flag when asking a vendor about security?+
A vendor that cannot give a direct answer about where your data is stored or whether it trains their model on your data is the clearest warning sign, regardless of how polished the rest of their pitch sounds.
Should client data and staff data be treated the same way?+
No. Client data often carries confidentiality obligations that can affect the relationship if mishandled, while staff data deserves the same care as any HR record. Both need clear rules, but the rules are not identical.
Where does security fit into a proper automation project?+
It belongs in the assessment stage, before anything is designed or built, so that data handling is understood as part of the process rather than added on afterwards.

Lerato Kgonoti
Founder and Director, Claro Builds
Lerato Kgonoti is the founder and director of Claro Builds, an operations and AI consultancy helping small and medium-sized service businesses implement automation, integrate AI into their daily operations and equip their teams with the practical skills to keep up with an increasingly automated world. Lerato founded Claro Builds on the belief that AI should be accessible, practical and human, not a privilege reserved for large enterprises, but a genuine advantage available to every service business ready to use it. Through builds, audits and private workshops, Claro Builds closes the gap between where small businesses operate today and where they need to be.
Related Articles
AI Explained Simply: What Small Business Owners Actually Need to Know (and What to Ignore)
Most small business owners are not behind on AI. They are behind on a clear explanation of what AI actually does and how to tell a genuine capability from a sales pitch. This guide gives you both.
Is Your Business Too Small for AI? Here's How to Actually Tell
Business size has nothing to do with whether automation is worth it. What matters is whether a specific task happens often enough, follows a defined process, and costs you something real to keep doing by hand. Here is how to tell which side of that line your business is on.
Why Telling Your Team to "Just Use ChatGPT" Is Not an AI Strategy
Handing staff a ChatGPT login and telling them to "use AI" feels like progress. Six months later, nothing has actually changed in how the business runs. Here is why an individual tool in individual hands rarely moves the needle, and what a real AI strategy looks like instead.
