Strategy for the AI Era
AI Risk for Small Businesses: Questions and Answers
AI Risk for Small Businesses: Questions and Answers
Plain answers to the questions small business owners ask about AI and their insurance, their intellectual property, their employees' use of AI, and AI tools that can be tricked. Every answer credits its source, and each section ends with how one of Strategy for the AI Era's four AI risk review agents can help.
AI and Business Insurance
-
Small business insurance doesn't reliably cover AI mistakes today: errors and omissions and cyber policies depend on their wording and on how you use AI (Gallagher Small Business, 2026). Errors and omissions insurance pays when a client claims your advice or work was wrong.
How our AI Insurance Review can help you: It asks which coverage you hold, and rates your exposure from that and from how you use AI. It says plainly whether you can sort this out yourself or need a broker.
-
They are three standard exclusions, written by the Insurance Services Office and in effect from January 1, 2026, that let insurers take AI-related claims out of commercial general liability policies (AI Policy Desk, June 2026). CG 40 47 is the broad one, and CG 40 48 removes advertising-injury coverage only. Most 2026 renewal packets include the new language with no announcement from the insurer (USA Business Insurance Services, June 2026).
How our AI Insurance Review can help you: It looks at what your business does with AI and tells you how exposed that leaves you. It gives you the exact questions to ask your broker about your own renewal.
-
HSB AI Liability Insurance, launched March 18, 2026 for small and mid-size businesses, covers injury, property damage, and personal and advertising injury claims arising from a business's use of AI (HSB, March 18, 2026). It is sold through partner insurers, not directly. It does not list advice that turns out to be wrong, which sits on errors and omissions insurance.
How our AI Insurance Review can help you: It names where to find a broker, and what this product does and does not cover. It gives cost ranges where a published figure exists, and says so plainly where none does.
AI and Your Intellectual Property
-
Yes, it can: in January 2026 a federal court in California held that giving trade secrets to a consumer AI service, whose terms imposed no duty of confidentiality, defeated the protection (Trinidad v. OpenAI; Ropes & Gray, July 22, 2026). The risk falls when the tool is used under business terms that forbid training on your data and require confidentiality.
How our IP Review can help you: It asks what your most valuable know-how is and how you keep it secret. It separates what you can do yourself from what needs an attorney.
-
You can copyright only the part a person contributed: the US Copyright Office concluded that purely AI-generated material is not protected, and that prompts alone don't make you the author (U.S. Copyright Office, January 2025). Your own expression, and your creative choices in selecting and arranging the output, can be protected.
How our IP Review can help you: It sorts what is likely yours from what may not be. It gives you the specific question to take to an attorney.
-
The freelancer or contractor owns it, unless there is a signed work-for-hire agreement, for nine kinds of work the law lists, or a signed transfer of ownership (U.S. Copyright Office, Circular 30). Paying for the work does not by itself make your business the owner.
How our IP Review can help you: It shows what your agreements with freelancers and contractors need to say. It gives typical attorney fees for that work, credited to their source.
Team AI Use Review: What Your People Are Doing
-
Probably: Salesforce's 2026 Workforce AI Survey found 67% of employees use AI tools at work, while only 18% of organizations have any formal AI security policy (Panda Technology, June 2026). Staff using tools the business hasn't approved is called shadow AI.
How our Team AI Use Review can help you: It gives you a ten-question AI audit to send everyone who works with you. The answers tell you what your people actually use and what goes into it.
-
The main risk is that business information typed into an unapproved tool passes through a company you don't control, under terms nobody at your business reviewed (Tech Times, June 2026). In May 2026 a bank reported a serious cybersecurity incident to the Securities and Exchange Commission after customer information went through an unauthorized AI tool (McCarter & English).
How our Team AI Use Review can help you: It rates how exposed your business is from what you tell it. It names the one step worth taking first.
-
No, a ban is not the recommended fix for a small business (Tech Times, June 2026). The fix is three things: find out what your people already use, write a clear rule on approved tools, and offer an approved tool they'll actually choose.
How our Team AI Use Review can help you: It says plainly that this is the area you can most often handle yourself. Where AI touches hiring, reviews or letting people go, it tells you what to ask an employment attorney.
Malicious AI Embeds Review: When AI Tools Get Tricked
-
A prompt injection attack hides instructions in an email, a document or a web page, so an AI tool that reads it follows the attacker's instructions instead of yours. The tool can't reliably tell your request from an instruction hidden in what it reads. The OWASP Foundation, which publishes the most widely used list of security risks for AI applications, lists it first (OWASP, 2025).
How our Malicious AI Embeds Review can help you: It asks which of your tools read things from outside the business. It then looks at what those tools can do without your approval.
-
Yes, researchers have shown it: a single email could make Microsoft 365 Copilot send internal information out, with no click needed, until Microsoft fixed it in May 2025 (The George Washington University, September 2025). None of the documented cases reports a business losing money.
How our Malicious AI Embeds Review can help you: It rates your exposure from what your tools can read and do. It names each case for what it is, so you get the risk without the alarm.
-
You protect them mostly through settings and habits: give each tool only the access its job needs, and give it specific instructions rather than open-ended ones. Have a person approve anything that sends money, sends messages or deletes things (OpenAI, November 2025; OWASP, 2025).
How our Malicious AI Embeds Review can help you: It names the step to take this week. It also says when an IT adviser is worth the cost, and where to get free advice.