AI Security Risks for Small Businesses: A Plain-English Guide for New Jersey Owners
Quick Summary for Business Owners
- Agents act with your access. An AI agent uses your accounts, so it can reach anything you can reach. Require approval before it sends, shares or deletes anything.
- Check your notetakers. Confirm where recordings are stored and who can open them. Turn off vendor AI training if the tool allows it.
- Fix sharing before Copilot. Copilot can surface any file a user has access to, so review Microsoft 365 permissions before rolling it out.
- Set an AI use policy. A one-page policy should list approved tools and what information never goes into them.
- Antivirus alone isn’t enough. It doesn’t cover hidden instructions, oversharing or AI-written scams. You need monitoring, email security, permission reviews and staff training working together.
Here’s a hypothetical example. A paralegal at a seven-person law office near Westfield connects a free AI notetaker to her calendar so she can stop typing up call notes. From then on, it joins every video call on her schedule, including client intake calls and settlement discussions. The recordings and transcripts sit on the vendor’s servers. Nobody at the firm has checked who can open them, or whether the vendor uses them to train its AI.
Nothing has gone wrong yet, which is why AI security risks for small businesses are easy to miss. AI tools arrive one at a time. Each one saves someone an hour a week, and nobody steps back to ask what the tool can see or where the information goes.
What AI Agents Are and Why They Change the Security Picture
Most people first used AI through a chatbot. You type a question, and it types an answer.
An AI agent goes further. It takes actions for you, using your accounts. Depending on how it’s set up, an agent can read your inbox and draft replies, book meetings, pull files from SharePoint, or join a video call and write up the notes. Microsoft, Google and many smaller vendors are building agents into software your team already uses.
Because an agent works with your access, it can reach whatever you can reach. If it can read your email, anything that lands in your email can reach it. If it can send email, a mistake or a trick can send something out under your name.
Security professionals are treating this as its own category of risk. In December 2025, OWASP, a nonprofit that publishes widely used security guidance, released a Top 10 list of risks specific to AI agents. Several entries describe agents being redirected by hidden instructions or acting with more access than they need.
Key Terms in Plain English
- AI agent: Software that uses AI to complete tasks on your behalf, using the accounts and permissions you give it.
- Prompt injection: Hidden or disguised instructions placed in an email, document or web page. An AI tool reads them and follows them as if they came from you.
- Shadow AI: AI tools your staff use for work without the business knowing or approving them.
- Permissions: The settings that decide who, or what, can open, edit or share a file, mailbox or system.
- Data loss prevention (DLP): Rules that watch for sensitive information, such as patient records or account numbers, and block, flag or encrypt it before it leaves your business.
AI Security Risks for Small Businesses in New Jersey
Many small businesses across Union County and Hunterdon County handle information that carries professional duties. Law firms and accounting practices hold confidential client records. Healthcare offices hold patient information. Nonprofits hold donor details. When an AI tool touches that information, the question of where it goes becomes a question about your obligations to clients.
Small teams also tend to add AI tools without a formal review. In a 15-person office near Cranford, the person who approves new software is often the office manager, who is also handling payroll, vendors and the front desk. Nobody’s job description includes “check the AI settings.”
Recording rules add another layer. New Jersey is a one-party consent state, which means a person on a call can generally record it without telling the others. Many New Jersey businesses work with clients and vendors in other states, and some of those states require every participant’s consent. When an AI notetaker records a call that includes someone in one of those states, New Jersey law alone may not answer the question. If this applies to your business, ask your attorney about your specific situation.
Healthcare offices have one more consideration. Any AI tool that handles patient information needs to fit within your HIPAA obligations. Your IT partner can help you review tool settings as part of your compliance efforts.
Five Ways AI Is Changing the Risks Your Business Faces
1. AI Assistants Can Be Tricked by Hidden Instructions
Here’s how prompt injection can play out. The office manager at a contracting company near Clark uses an AI assistant connected to her inbox. It summarizes her email each morning and drafts replies. One day, a message arrives that looks like a supplier newsletter. At the bottom, in white text on a white background, is an instruction telling the assistant to find recent invoices and forward them to an outside address. She never sees that text, but the assistant reads every word of the email. (This is a hypothetical example.)
If the assistant is allowed to send email without asking her first, the invoices can leave the business under her name. No virus was involved, so there was nothing for antivirus software to catch.
What reduces this risk:
- Set AI assistants to ask for your approval before they send, share or delete anything.
- Connect only the accounts a tool needs for its job.
- Use AI tools your IT partner has reviewed, especially any tool that connects to email or files.
- Ask your IT partner about data loss prevention (DLP) rules. DLP tools can block, flag or encrypt email that contains certain types of information, such as patient records or financial details, before it leaves your business. Some newer tools apply the same rules to AI assistants, so an assistant needs a person’s approval before it sends that information outside the business.
2. Meeting Notetakers Keep More Than Notes
AI notetakers join Zoom, Teams and Google Meet calls. They record the conversation, transcribe it and send a summary afterward. The convenience is real. But before your team relies on an AI meeting notetaker, get answers to these questions:
- Where are the recordings and transcripts stored, and for how long?
- Who at the vendor can access them?
- Does the vendor use your meetings to train its AI?
- Does the summary go automatically to everyone on the invite, including people outside your business?
Several AI notetaker companies now face class action lawsuits over these questions. The allegations include recording people who never agreed to it and, in some cases, using meeting content to train AI models. In August 2026, a federal judge allowed several core privacy claims against one vendor to move forward. None of the cases have reached a final decision on the merits. Until they are, assume the vendor keeps whatever your settings allow it to keep, and check those settings before the tool joins another call.
Think about what those recordings contain. For a law firm, that could be a settlement strategy. For a CPA, a conversation about a client’s audit. For a clinic, a patient intake call. The same applies to the video recordings Teams and Zoom save to the cloud. Many sit there indefinitely, shared by links nobody remembers creating.
Lifeline Tip: Four Notetaker Settings to Check This Week
- Which meetings it joins. Choose “only meetings I select” over “every meeting on my calendar.”
- Whether it announces itself. Participants should know it’s there when the call starts.
- Whether your content trains the vendor’s AI. Find the setting and turn it off if you can.
- How long recordings are kept, and who can open them. Set a retention period and limit access to the people who need it.
3. Copilot Can Surface Files You Forgot You Shared
Microsoft 365 Copilot uses the permissions your staff already have. If a person can open a file, Copilot can read it and use it in an answer.
For most businesses, the risk sits in the permissions themselves. Over the years, files get shared with “everyone in the company,” folders are opened for a project and never closed, and links get created for one outside recipient and forgotten. Before Copilot, finding one of those files meant knowing where to look. Now a staff member can ask a plain question, such as “what are our salary ranges?”, and get an answer drawn from a spreadsheet they were never meant to see.
Copilot can save your team real time. You can read more in our guide to practical Copilot use cases for New Jersey small businesses. The permissions review should come first.
Lifeline Tip: Where Old Sharing Links Tend to Hide
- “Anyone with the link” shares created years ago for a single outside contact
- SharePoint sites and Teams channels open to the whole company by default
- Folders still shared with former employees or old vendor accounts
- OneDrive files a staff member shared once and forgot about
4. Shadow AI: Your Team May Already Be Using AI Tools You Haven’t Approved
A staff member pastes a client email into a free chatbot to tidy up a reply. Another uploads a spreadsheet to get a quick summary. Both are trying to save time. Neither knows what the tool does with that information.
Many consumer AI tools keep what you type, and some use it to improve their models unless you change a setting. For professional services firms, this has legal weight. In February 2026, a federal judge in New York ruled that documents a criminal defendant created using a public AI chatbot were not protected by attorney-client privilege. Part of the reasoning was that the tool’s privacy policy allowed the company to collect user inputs for model training and disclose user data to third parties.
Client information typed into a consumer AI tool may lose protections you assume it has. If your firm handles privileged or confidential material, talk to your attorney about how that applies to you.
Lifeline Tip: What a One-Page AI Use Policy Should Cover
- Approved tools: Which AI tools staff can use for work, and which accounts to sign in with.
- What stays out: Information that never goes into an AI tool, such as client files, patient details, passwords and account numbers.
- Who to ask: Who staff check with before trying a new tool.
- Review date: When the policy will next be reviewed.
5. AI Makes Scams Harder to Spot
Phishing emails used to give themselves away with typos and strange phrasing. AI tools now let scammers write clean, personal messages. They can pull real names, job titles and project details from your website and LinkedIn. A fake invoice from a “supplier” can look exactly like the real one. Some scammers also use AI to imitate a familiar voice on the phone.
The target is usually money or login details. A request to update bank details before a large payment is one of the most common setups.
Lifeline Tip: The Call-Back Rule for Payment Changes
If anyone asks you to change bank details, pay a new account or rush a payment, call them back on a number you already have on file. Never use the number in the message. Write the rule into your payment process so staff don’t feel awkward following it.
Why Antivirus Alone Doesn’t Cover This
Traditional antivirus software compares files against a list of known threats and blocks the matches. It still has a place.
Look back at the five risks above, though. A hidden instruction in an email is text. A notetaker records with permission. Copilot reads files users can already open. A staff member pastes data into a website. A fake invoice contains no malware at all. Antivirus software isn’t built to catch any of these.
Covering these risks takes several protections working together:
- 24-hour monitoring that flags unusual activity on your devices and accounts
- Ransomware detection that watches for suspicious behavior on your devices
- Automated patching so security updates install on schedule
- Email security that inspects links and attachments before they reach your team
- Regular permission reviews in Microsoft 365
- Staff training so your team recognizes AI-written scams
At Lifeline Technology Solutions, these layers are built into our managed IT plans. Essentials includes 24-hour monitoring and alerts, automated patch management and ransomware detection. Enhanced adds bi-annual Microsoft 365 audits. Elite adds advanced email and endpoint security and full Microsoft 365 management. Security Awareness Training is available as an add-on across all plans. For a broader look at the basics, see Cybersecurity for Small Businesses in New Jersey: What Actually Protects You.
What to Do This Month
None of these steps mean giving up the AI tools your team relies on. They give you a clear list of what’s connected and a few ground rules.
- List every AI tool in use. Ask staff directly and without blame. Include browser extensions, phone apps and meeting notetakers.
- Check your notetaker settings. Use the four checks above.
- Review Microsoft 365 sharing before you roll Copilot out to more people.
- Write a one-page AI use policy and share it with your team.
- Limit what AI assistants can do on their own. Require approval before anything is sent, shared or deleted.
- Add the call-back rule to your payment process.
- Give staff a short training session on how AI-written scams look.
Lifeline Tip: A 15-Minute AI Check for Your Next Team Meeting
Ask your team four questions:
- Which AI tools did you use for work this month?
- Did any of them connect to your email, calendar or files?
- Did you paste or upload anything with client details?
- Has any tool asked for new permissions recently?
Write down the answers. That list is the start of your AI policy.
Common Misconceptions
“We’re too small to be a target.”
If your business has five employees and a Microsoft 365 account, you have email, client files and payment details worth stealing. Many attacks are automated and sent to thousands of businesses at once, whatever their size.
“If Microsoft built it, it’s secure by default.”
Microsoft provides strong security controls, but someone has to configure them. SharePoint‘s default sharing settings are more open than most small businesses would choose. Setting them to fit your business is your responsibility, or your IT partner’s.
“It’s the other person’s notetaker, so it’s not our problem.”
When a client’s or vendor’s notetaker joins your call, your side of the conversation is recorded too. You can ask for the notetaker to be removed, or save sensitive topics for a call without one.
When It’s Time to Talk to an IT Partner
It makes sense to get help if any of these sound familiar:
- You’re planning to give Copilot to more of your team.
- Your staff use AI tools, and you’re not sure which ones.
- You handle client or patient information and don’t know where your meeting recordings are stored.
- Nobody has reviewed your Microsoft 365 sharing settings in the past year.
If you’re already a Lifeline Technology Solutions client, AI questions fit into the work we do with you now. We review permissions and settings as part of your service where needed. Enhanced and Elite clients also get regular Microsoft 365 reviews. Give us a call and ask.
If you’re not a client yet, here’s what working with us looks like. You speak directly with named technicians based in Cranford and Clinton, with no call center in between. Our agreements are month-to-month. We’ve supported New Jersey businesses for more than two decades, and we explain what we find in plain English.
The Bottom Line
AI tools can save your team hours every week. Most of the risk comes from tools connected without anyone checking what they can reach or where the information goes. A short review of your tools, settings and Microsoft 365 permissions shows you where you stand and what to fix first.
If you’d like help with that review, our team can walk through it with you. We’ll look at what your AI tools can access and help you decide what to tighten first.
