
AI use typically doesn’t start with a companywide rollout.
It starts with an employee opening a browser to draft an email, summarize a document, work through a problem, or to simply save some time.
That can happen before leadership has approved a tool, set rules for what information can be shared, or decided how AI-generated work should be reviewed.
Businesses may already have an AI problem they can’t fully see, or don’t even realize they have.At the same time, the conversation around AI safety is getting louder.
Former OpenAI and Anthropic researcher Jacob Coxon recently raised serious concerns about the direction of advanced AI development. Anthropic CEO Dario Amodei has also called for the industry to slow development so safety measures can catch up. OpenAI CEO Sam Altman said his company would commit to one of Amodei’s proposed safety measures.
Those are big questions for the AI industry. And, they’re all important conversations to be having now to anticipate future issues. However…
Business leaders need to be having a more immediate conversation with their IT providers:
How is AI being used inside our organization right now?
Netskope’s 2026 AI Report found that 30% of AI users use only personal AI apps, while another 14% use both personal and organization-managed apps.
That means employees may already be using tools that leadership and their IT teams haven’t reviewed.
The AI Risks Businesses Are Dealing with Today
The risks can show up in everyday work:
- Sensitive company or client information gets entered into an AI tool that hasn’t been approved.
- An employee trusts a confident-sounding AI answer without checking it.
- AI-generated phishing emails make familiar vendors, executives, or coworkers harder to spot.
- Employees choose their own AI tools without IT or leadership knowing, creating Shadow AI that the business can’t fully see or manage.
- AI agents get access to company systems or data before anyone has thought through what those agents can do.
Some of these risks are already showing up in cyberattacks.
Anthropic’s September 2026 threat intelligence report found criminals and state-linked groups using AI agents to gather information, find weaknesses, and steal data. In some cases, 1 person could use AI to do work that previously required a team.
Businesses don’t need to panic about AI. They do need to know how it’s being used.
Start with Clear Guardrails
A few questions can go a long way:
Which AI tools are approved?
What information can employees share with them?
When does AI-generated work need to be checked by a person?
Who is accountable for the final work?
If employees don’t know the answers, they’ll make those calls themselves.
Policies matter, but employees also need to understand how those rules apply when they’re using AI in real work.
That means training has to be part of the plan.
Guardrails Only Work if Employees Know How to Use Them
We’ve seen this with cybersecurity for years.
A phishing policy by itself doesn’t teach someone how to spot a convincing fake. Training, repetition, and practice do.
AI needs the same kind of attention.
Employees need guidance on what they can share, how to check AI-generated information, how to recognize AI-powered threats, and when human judgment still matters.
The tools will keep changing. Employee decisions will still matter.
BSN Has Been Building for This
At Breach Secure Now, we’ve been talking about responsible AI use, employee awareness, and guardrails for more than a year.
Our approach has always focused on helping employees use AI safely and effectively while giving businesses more structure around how AI shows up at work.
That includes AI awareness training, policies, ongoing education, and practical guidance employees can use in their day-to-day work.
For SMBs, the starting point is simple: get visibility into how AI is already being used, put clear guardrails in place, and make sure employees know how to work within them.
If you’re working with an MSP, this is a good conversation to have with them now.
And if you’re an MSP, it’s a chance to help clients get ahead of AI risk before Shadow AI, unsafe data sharing, or poor employee decisions create the conversation for them.
Learn More About the Risk to Adoption (R2A) Program
- No Credit Card Required
Start Your 30-Day Free Trial
No credit card. No contracts. Just a straightforward way to experience how Breach Secure Now helps MSPs educate, protect, and support the businesses they serve.