Skip to content

AI Use Jumped From 48% to 77%. The Rules Didn't Move.#

AI adoption sprinted. The rules never left the starting line.

Between mid-2024 and this January, the share of small businesses using AI regularly jumped from 48% to 77%, per Intuit's May report, built on surveys of more than 34,000 small and midsize business owners. I've watched that curve from the inside, on client engagements and in our own workshops.

Here's the question I've started asking owners: "Can you show me your AI policy?"

I'm setting the bar low here. A paragraph in the handbook counts. So does an email to the team, or a list of approved tools taped to the wall.

The answer, almost every time, is a pause. Then some version of "we've been meaning to."

Adoption sprinted. The rules never left the starting line. That gap is where the next round of expensive small business mistakes is going to come from, and closing it is cheaper than almost anyone expects.

And to be clear, this isn't me inventing a standard. The guidelines already exist. NIST put out an AI Risk Management Framework. State privacy laws keep stacking up. Your industry probably has its own handling rules for the data you touch every day. The frameworks are written. Most small businesses just haven't read them yet, and nobody's asking them to boil the ocean. The point is to acknowledge the guidelines exist and get one page down that respects them.

The Speed Was the Right Call#

Let me be clear about one thing first: adopting fast wasn't the mistake.

The same Intuit report says 43% of US businesses saw AI increase their revenue. Only 2% saw it go the other way. Owners who moved early are collecting real gains in marketing, customer service, and bookkeeping while their competitors schedule another meeting about it.

You moved fast because the tools worked and waiting had a cost. That instinct was right.

But speed built a habit: nobody writes anything down while the wins are coming. Every week AI touches more of your operation. Customer emails. Proposals. Financials. Meeting recordings. The stakes rose quietly while the paperwork stayed at zero.

What Never Got Written Down#

Your team didn't wait for permission either. 49% of employees admit to using AI tools their employer never sanctioned, and 60% say the security risk is worth it if it helps them hit a deadline. That's from BlackFog's January survey of 2,000 people at firms with 500+ employees, companies with IT departments and controls. Most small businesses have neither, so I'd treat those numbers as the floor, not the ceiling.

Read that 60% again. Your best people, the ones who care most about deadlines, are the most likely to paste something sensitive into a free tool on a personal account. Not out of malice. Out of hustle. The exact trait you hired them for.

And when it goes wrong, the pattern is consistent. Last July, IBM's Cost of a Data Breach report found that 63% of breached organizations had no AI governance policy at all, or were still writing one when the breach happened. IBM's sample skews bigger than your shop, but the pattern is the point: the companies that got hurt were the ones without rules.

Even if a breach never touches you, the gap now shows up in rooms where deals happen. Client security questionnaires ask for your AI policy. Cyber insurers are moving the same direction: Aon's risk-control lead says underwriters now ask, "Do you use AI? Do you police it? Do you have protocols in place?" A new hire asks what they're allowed to paste into ChatGPT, and the honest answer is a shrug. Each of those moments costs you something: a deal, a premium, or the deal-killing look of a company making it up as it goes.

What a Small Business AI Policy Looks Like#

Here's what nobody tells owners: at your size, this isn't a six-figure compliance project. The core of it fits on one page.

Three lines do most of the work:

  1. What never goes into an unauthorized AI tool. Customer lists, financials, employee records, anything covered by an NDA. The test we use with clients: if it would hurt on the front page of a newspaper, it stays out.
  2. What needs a yes first. New tools, client-facing output, anything touching regulated data. Name the person who gives the yes.
  3. What's fair game. Drafting, brainstorming, research, meeting notes. Say it out loud so your team stops guessing and stops hiding.

Add an approved tool list, because a paid business account with a data protection agreement is a different animal from a free consumer app that trains on your inputs. Those three lines plus the tool list are your acceptable use policy. That's the whole skeleton.

None of this contradicts the bigger frameworks. It's the small version of them. If a client hands you a questionnaire built on NIST language, a one-page policy that names what's off-limits, what needs approval, and what's fine is exactly the kind of answer they're looking for.

We built this with The Catholic Foundation in Dallas: data classification, a tool approval process, and scenario-based staff training built around situations their team was actually hitting. AI features switching on inside software they already used. Third parties joining calls with AI recorders running.

The core framework came together in weeks, and their board approved it with no revisions. A foundation managing donor data got this done without a dedicated AI team. And it didn't end with the policy: that same engagement is still growing this summer, because the one page gave everyone the confidence to build more.

What to Write Down This Week#

Skip the quarter-long initiative. Do this instead:

  1. Write the three lines above for your business. First draft, thirty minutes.
  2. List the AI tools your team actually uses. Ask them directly and promise amnesty. You'll learn more from that one conversation than from any audit.
  3. Pick the approved list and name the owner of the yes.

That one page won't make you compliant with every regulation on the horizon. It will put you ahead of most of the 77%, and it turns your next client questionnaire from a scramble into an attachment.

The speed got you here. The rules are how you keep it.

The one page is the start. When clients want the full framework, we build it in a structured 90-day rollout: AI privacy policy, data classification map, tool approval process, BYOD policy, and an incident response plan. The policy core comes together in weeks, same as it did for the foundation. The rest of the 90 days is rollout and training, so the policy changes behavior instead of sitting in a drawer. Schedule a discussion and we'll tell you which one your business actually needs.


Sources: