Generative artificial intelligence (GenAI) is no longer a future innovation; it is already embedded in day-to-day business operations. From drafting emails and summarizing documents to generating ideas and analyzing data, tools like ChatGPT, Gemini, Claude, and Copilot are being used across organizations of all sizes. For small and medium-sized businesses (SMBs), GenAI offers real efficiency gains. However, it also introduces real (and often overlooked) cybersecurity and data exposure risks.
That dichotomy is at the heart of a new guide from the Cyber Readiness Institute, “Secure Use of Generative Artificial Intelligence (GenAI) for Small & Medium-sized Businesses,” designed to help SMBs harness GenAI safely, responsibly, and with confidence.
Why GenAI Creates New Risk for SMBs
GenAI is not a single technology. It encompasses a broad range of systems, including large language models (LLMs) that incorporate text, images, code, and other content. While AI has been used in business for decades, GenAI introduces new risks because of how and where data is processed.
The most significant risk is also the simplest: employees may unknowingly expose confidential business or customer information by entering it into public GenAI tools. Anything entered into a public LLM should be treated as public disclosure, an especially serious concern for SMBs that may lack formal data governance or security policies.
There are key distinctions many organizations miss, such as the critical distinction between public and private GenAI systems, the difference between GenAI and Large Language Models (LLMs), and the difference between LLMs and GPT-based tools. Definitions matter because risk management begins with understanding how data flows and who can access it.
Practical Questions, Not Abstract Theory
The guide focuses on practical risk identification, including structured questions SMB leaders can use immediately, without requiring a technical degree, to understand how GenAI is being used inside their organizations and by the organizations that access or share their data.
The guide provides:
Ten questions to assess internal GenAI risk, including what tools employees are using (approved or not), what data may already have been shared, and whether employees know how to report mistakes.
Ten questions to ask vendors and third parties, recognizing that GenAI risk often enters through the supply chain.
Five targeted cybersecurity questions, aligned with the CRI’s Core Four: passwords and MFA, software updates, phishing, and secure data storage and sharing.
This approach helps SMBs move from “we think GenAI is being used” to “we understand where our real exposure lies.”
Governance That’s Realistic for SMBs
A key focus of the guide is on governance basics that SMBs can realistically implement. After all, GenAI use will only accelerate, and avoiding it altogether is not a strategy. Governance, not prohibition, is the key to using these tools safely. This includes a sample Acceptable Use Policy for GenAI that clearly distinguishes between permitted and prohibited uses of public and private tools; guidance on human accountability, emphasizing that GenAI assists but never replaces judgment; a ready-to-use employee acknowledgment form; and an FAQ that helps employees understand what is allowed, what is not, and what to do if something goes wrong.
This combination of policy and communication tools helps organizations move beyond “check-the-box” compliance toward real risk reduction.
A Starting Point, Not the Finish Line
The guide is not about eliminating risk; it is about reducing risk to an acceptable level through awareness, clear expectations, and basic controls. For SMBs that want to benefit from GenAI without unknowingly exposing data, violating contracts, or creating new cybersecurity gaps, the guide offers a practical and accessible starting point.
As GenAI becomes a standard workplace tool, organizations that act now, by understanding their risks and setting clear guardrails, will be far better positioned than those that wait for an incident to force the issue.
Read the complete guide, Secure Use of Generative Artificial Intelligence (GenAI) for Small & Medium-sized Businesses here. You can find additional CRI articles about cyber readiness and AI on our AI Resources Page.