More small businesses are starting to use AI through cloud applications and websites including LLMs such as ChatGPT, Gemini, Claude and Microsoft Copilot. These tools can automate tasks, offer insights and improve the customer experience without a large upfront cost. Adoption in Australia is rising rapidly each year, before you rely on them, it's important to understand the cyber security risks and how to reduce them.
Data leaks and privacy breaches
AI tools can easily speed up work and support decision making. In doing so, they may require access to customer, staff or financial records. If that information is not managed well, it can create serious privacy and security problems. Uploading customer or staff details into a generative AI tool without anonymising them can expose private information.
Review how you manage, protect and govern data, and identify any sensitive or confidential information you need to secure. Create an internal AI Acceptable Use policy that says what can and can’t be uploaded. Ensure staff are familiar with the policy and update business processes where necessary. When you do use an AI tool, be sure to remove or change personal details so they cannot be inadvertently exposed.
Reliability and manipulation of AI outputs
While AI systems are powerful and provide access to tremendous amounts of information, they can also make things up. AI systems can ‘hallucinate’, meaning they provide outputs that sound correct, but they are not true.
Train staff to check AI answers for potential mistakes, biased language, and responses that are unethical or irrelevant. Keep a human in the loop when the work is high-stakes or involves sensitive information. Use trusted models that the vendor frequently updates and monitor system outputs for unusual patterns.
Supplier risks and vulnerabilities
Cloud or SaaS (Software as a Service) applications are often used by small businesses as they do not require infrastructure or maintenance. Such applications may include AI features such as chatbots, search tools or assistants. In many cases, these products depend on another company for the infrastructure, the AI model, data handling and day-to-day operations. A weakness in that supplier’s systems, infrastructure, data sources or model can affect your business too.
Check the vendor’s reputation and its commitment to cybersecurity and responsible use of AI, including any third-party tools it uses. Read the terms on data ownership, protection, use and storage. Know how the vendor will notify you of a cyber security incident, and where your data is located.
Key points
- Review your data practices and set a clear rule for what staff must not upload to an AI tool.
- Check AI answers, and keep a person involved in important or sensitive decisions.
- Assess the vendor’s security, data terms and incident notification process before you rely on the tool.
Need help applying this to your organisation? Talk to Cybervisory.
