Quantum Technologies — AI in a Box
AIOctober 5, 2026Nathan Drager3 min read

Is Your Business Training AI to Hack You? The AI Threats Worth Worrying About

Some AI risks are real for a small business today, and plenty can safely wait. Better phishing, cloned voices and your data in the wrong tool, and what to do about each.

Robot assisting a worried businessman working on a laptop at a desk in an office setting.

AI has made a lot of security headlines, and most of them are aimed at large companies. For a small business, a few AI risks are real today, and plenty can safely wait. Here is how to tell them apart. I'm genuinely excited about what AI can do for small businesses. I just want people using it with their eyes open.

Real today: phishing that reads perfectly

The old tell, bad spelling and odd grammar, is gone. Criminals use AI to write polished emails in the right tone, translated into flawless English, and to personalize them with details scraped from your website and LinkedIn. That makes the habits that don't depend on spotting mistakes more important: verify payment changes by phone, and use multi-factor sign-in so a stolen password isn't enough.

Real today: cloned voices

A few seconds of someone's voice from a video or voicemail is enough to imitate it. The scam is simple: a call or voice message that sounds like the owner, asking for an urgent transfer or a gift-card purchase. The rule I give every client: if a request involves money or passwords, confirm it by calling a number you already have, no matter whose voice it is.

Real today: your data in the wrong AI tool

This is the one where "training AI" comes in. When staff paste customer lists, contracts or financials into a free, consumer AI app, that information leaves your control. Depending on the app and its settings, it can be kept and used to improve future models.

The business versions are different. Business plans of ChatGPT and Microsoft 365 Copilot, used with a work account, don't use your data to train their models, and they keep it under your company's control. The fix is not banning AI. It's giving people an approved tool and a short written policy on what can go into it.

Worth watching: AI assistants that act on your behalf

AI tools that read your email or browse the web can be tricked by hidden instructions planted in a message or a page. This is called prompt injection. It matters most when an assistant can send email, move files or make purchases on its own. Give AI tools the least access they need, and keep a person in the loop for anything that moves money or data.

Safe to ignore for now

  • Movie-style AI that breaks into systems on its own. Attackers still mostly get in through stolen passwords, unpatched software and phishing.
  • Fear that every AI feature in your software is spying on you. Read the vendor's data terms, and turn off what you don't need.

What to do this month

  • Pick one approved AI tool on a business plan, and tell staff to use it instead of free apps.
  • Write a one-page AI acceptable use policy: what can and can't be pasted in.
  • Set a verify-by-phone rule for any request involving money or passwords.
  • Keep multi-factor sign-in on everything, because better phishing means more stolen passwords.

Our AI acceptable use policy template is a free download if you want a starting point.

Not sure where your business stands on this?

We’ll walk through how you handle it today and tell you straight whether it needs attention.

AIBusiness Technology

Let's talk about your technology.

A quick conversation about where you are, what's not working, and whether we're the right fit. No pressure, no jargon.

No obligation. No sales pressure. Just an honest conversation.

CallSchedule a Call