AI for small business
How a Small Business Should Start With AI
Where a 2–20 person business should begin, which decisions stay human, how to prove a saving, and what the rules ask before AI talks to customers.
A small business uses AI well when it hands over one measured job at a time, keeps consequential decisions human, and proves each saving against a baseline.
What current AI can do, job by job, with the dial setting and the evidence for each.Read the capability register →
What can AI do for a small business today?
Current AI can take a real share of front-desk, back-office, and growth work: answering calls and booking into open slots, drafting replies from order and policy records, reading invoices and forms into fields, preparing the books for review, drafting marketing from real outcomes, capturing meetings, and running research on a schedule. Browser agents can now work portals that have no integration, and connectors let assistants read and act in the systems a business already uses.
It still cannot be trusted with the consequential call: moving money, hiring, credit, legal or medical judgment, and anything irreversible done in a customer's name. The capability register keeps a dated, sourced record of each job, how far to trust it today, and the human gate it needs.
Where should a small business start with AI?
Start with one recurring job that happens often, ends clearly, and already costs someone real hours: missed calls, repeated email answers, invoice entry, month-end matching. Time five representative cases before touching a tool, because that workload is the baseline every later claim will be measured against.
Then check what the software you already pay for includes. Office suites, accounting systems, CRMs, and phone platforms increasingly bundle drafting, summaries, and agents. Run the first test in shadow mode on completed cases, keep it draft-only, and widen permission only after the measured result holds.
Which work should stay human?
Keep the decisions that carry legal duties, a person's livelihood, or money that cannot be recovered: hiring and pay, credit and insurance eligibility, medical, legal, and tax judgment, money movement, bank-detail changes, and anything irreversible done in a customer's name. AI can prepare the scheduling, documents, reminders, and summaries around those decisions.
Also keep the first send. Until a measured run shows a job's drafts need no correction, a person approves what reaches a customer, a record, or a payment. The gate moves with evidence, one job at a time.
How do you know whether AI actually saved time?
Measure the same things before and after: frequency, active handling time, review and correction minutes, errors, and one quality measure such as reopened tickets or missed callbacks. The saving is the difference between those measurements, not the workload that existed before the test.
Do not import a vendor's number or trust how fast the work feels. Help-desk resolution counts can include customers who simply left, and a 2025 randomized trial found experienced developers took longer with AI tools while believing they were faster. Price the result per accepted job, including review time and retries.
What does AI cost a small business?
The visible costs are seat subscriptions, usage credits, and outcome pricing: help desks now charge per resolved conversation, phone agents per minute or per call, and model providers per token. The larger costs are often setup, supervision, correction, and the occasional expensive mistake.
Compare the cost per accepted job with the current cost of the same job, review minutes included. A cheap tool that needs heavy correction can cost more than the manual process it replaced, and an expensive one that removes a whole class of rework can pay for itself quickly. Neither is knowable before a shadow test.
Is it safe to connect AI to email, calendars, and payments?
It can be, with the controls you would give a new hire plus one more: no current AI system is immune to prompt injection, where instructions hidden in an email, page, or document try to steer it. Give each agent its own account, the least access that finishes the job, read before write, and a named owner who can stop it.
Keep sends, payments, deletions, and bank-detail changes behind a person, and keep a log of what the agent did. Joint guidance from CISA and its Five Eyes partners in 2026 asks for the same: least privilege, human approval at decision points, and readable records of every tool use.
Do customers have to be told they are talking to AI?
Increasingly, yes, and it is the safe default everywhere. California and Maine prohibit bots that pass as human with consumers, Utah requires disclosure when a customer asks, more state laws take effect in 2027, and the EU has required disclosure for its residents since August 2, 2026. Outbound AI-voice calls count as artificial-voice calls under federal telemarketing rules, so they need prior consent.
Calls add recording rules: many states require every party's consent. The simple policy is to say in the first sentence that the customer is speaking with an AI assistant and, when it applies, that the call is recorded—and to keep a quick route to a person. This is orientation, not legal advice; check the rules for your states and your industry.
Should a small business build its own AI tools or buy them?
Buy the general capability—drafting, notes, answering, extraction—and own the part that is yours: the procedure, the examples, the quality bar, the approved answers, and the records. That part is what makes any tool perform like your business, and it belongs in your own documents, not only inside a product.
AI products launch, merge, and close within a year; in 2026 a major AI company retired its general agent and its browser about a year after launch. Write the method around the job, keep exports of your data, and build small internal tools only where a real gap remains, with customer data and payments kept out until someone has reviewed the security.
Field notes for this topic
Read the archive →The Q3 2026 Operating Index
The quarter agents became ordinary software: what improved, what failed, and which operating beliefs the evidence changed.
September 29, 2026Start With the AI You Already Pay For
Before buying another AI subscription, inventory the assistants already bundled into your suite, books, CRM, and phone system—then test one job in draft mode.
September 29, 2026The Machine Customer Is Calling
For most small businesses, the first machine customer is not an autonomous shopper with a wallet. It is an AI assistant calling to ask your price.
July 16, 2026Build the Minimum Viable Loop
Do not begin with the agent that runs the whole company. Begin with one recurring job, one external score, one safe action, and one hard boundary. The purpose of the first loop is to earn the next permission.
July 16, 2026The Inbox Is Not the Control Plane
OpenAI's July 15 red-team report showed a live vending agent changing prices, ordering loss-making stock, and canceling another customer's order. The operating rule is plain: external content may describe work. It does not authorize it.