Your Employees Are Already Using AI
A practical SMB leader's guide to human AI risk, data exposure, agent boundaries, and safe adoption.
The problem this report solves
The risk isn't that your people are bad at AI. It's that normal people are using powerful tools inside unclear workflows, and no one owns the data, prompts, outputs, approvals, and mistakes until something goes wrong.
Abstract
SMB CEOs and owners, COOs, CFOs, and IT/security leaders managing AI adoption and risk.
AI is no longer a future project for small and medium businesses. Employees are already using it to write emails, summarize meetings, build spreadsheets, answer customers, create reports, and speed up admin work. The exposure is already in the workflow, even at companies that have never approved a single AI tool.
Based on a Cybernomics episode with Dr. Nikki Robinson and Jennifer Baca, this report reframes the tired "humans are the problem" idea. People get tired, rush, and avoid speaking up when they fear blame. The fix is not more training alone; it is designing tools and work so that careful is the default, the same way cars use seat belts, mirrors, and alerts instead of trusting drivers to remember every rule.
Rather than a sprawling AI policy, the report gives leaders a focused operating model: the five human touchpoints of AI risk, the seven risks most likely to appear before a formal AI program, concrete SMB failure scenarios with first controls, and a short list of practical controls that work without creating an AI bureaucracy.
Key findings
- 88% of organizations now use AI in at least one business function (McKinsey 2025), yet 97% of those with AI-related security incidents lacked proper AI access controls (IBM 2025).
- 63% of breached organizations lacked or were still developing AI governance policies (IBM 2025), confirming adoption is outrunning governance.
- Most SMB AI risk is not one dramatic event; it is a chain of small, unclear choices that nobody owns until something breaks.
- Don't remove people from the loop, put them in the right loop: let agents read and draft, but require human approval before they send, delete, update, or buy anything important.
What's inside the full report
- The Cybernomics framework: the five human touchpoints of AI risk, data, prompts, outputs, approvals, and mistakes.
- The seven AI risks SMBs should watch first, from shadow AI and data leakage to agent overreach, tool sprawl, and silent failures.
- Real SMB scenarios showing what could happen, the business impact, and the first control to put in place.
- Seven practical controls that keep the business moving, including approved tool lists, plain data rules, review levels, and agent permission tiers.
- A leadership lens on accountability: who owns tool approval, data rules, review points, agent permissions, and incident reporting.
- Guidance on reviewing vendor terms, training data use, log retention, and where AI tool data is stored.
Download the full report, free.
The complete Your Employees Are Already Using AI PDF is free to download, no email or sign-up required. If it sparks a question about your own operation, let's talk.
Ready to grow your firm before you hire?
Find Your Firm’s Capacity starts with a focused conversation about the accounting work creating pressure to add people — and how your existing team may be able to support more clients.
