5 AI Cybersecurity Checks for the Person Who Runs IT
So You're the Company's AI Person Now...
In a lot of the businesses we support, the person running AI doesn't have IT in their title.
They're the office manager, the controller, the operations lead, or the person who was good with computers when the last IT person left. They reset passwords, call the internet provider, and approve new software. Now they're also expected to have a plan for AI.
The title rarely comes with it. The moment you put a C or a VP in front of a job title, the pay is supposed to double, so the AI hat usually gets handed over without the letters.
If that's you, this post is for you. The same checklist also works if you just took over a business, were recently promoted, or inherited someone else's systems.
AI moves faster than the approval process
Most of the AI in your company probably arrived without a formal decision. An employee signed up for a free tool. A vendor switched on an AI feature in software you already pay for. Someone connected an assistant to the company's email or files because it saved them an hour.
The research says this is common and risky:
- IBM's 2026 Cost of a Data Breach Report found that 92% of organizations that had an AI-related security incident lacked proper AI access controls when it happened.
- A 2026 Cybersecurity Insiders survey of 1,253 security professionals found that 53% of organizations give AI tools write access to collaboration platforms without preventive controls.
AI tools are getting the keys to shared files and inboxes before anyone decides what they're allowed to do there.
You don't need a big budget to get ahead of this. You need five AI safety checks, done in order.
Check 1: Find out who uses which AI, for what, and on whose account
Start by asking, "Are you using AI? How are you using it? What are you using?"
Make it a conversation. People will tell you more when they know nobody's in trouble. Then confirm with your IT provider, who can usually see which AI services your devices connect to and how often, even if they can't see what people typed.
Write the answers in one shared list: tool, team, purpose, and whether the account is personal or company-owned.
Check 2: List the AI you're already paying for
The follow-up question matters just as much: "Which AI tools are already built into the software you pay for?"
Microsoft 365, your CRM, your accounting platform, and your video meeting software may all include AI features now. Some vendors switched them on through a terms update nobody read. We wrote about that in Nobody Reads the Terms and Conditions.
These built-in tools are often your safest starting point, because they already sit inside systems you secure and manage.
Check 3: Review every connection into your business data
This check matters the most. Connectors, plugins, agents, and integrations let an AI tool read or change data in other systems.
For each one, write down three things:
-
What can it read?
-
What can it change?
-
Who approved it?
If nobody can answer the last question, that goes to the top of your list.
We saw this with a client recently. They were big fans of a popular AI assistant and wanted it connected directly into their Microsoft 365 data, with no plan for where that data would go or how anyone would trace it if something went wrong.
We suggested a different route: use the same kind of AI inside Microsoft 365 Copilot, where the data stays within their existing security perimeter, and Microsoft Purview gives us audit and governance tools.
The AI itself was fine. The missing perimeter was the risk.
Check 4: Find the personal accounts and shared logins
Personal AI accounts are where company work quietly leaves the company. Consumer plans may train on conversations by default, and the work stays with the employee when they go.
Look for shared logins too. One paid account used by five people means five people's work is tangled together, and nobody can remove access for just one of them.
We covered what this can cost in When an Employee Leaves, Their AI Account Can Take Your Workflow With It.
Check 5: Write the rules on one page
Keep it short enough that people will read it:
- The approved AI tools, and which account to use
- What must never be entered: client data, employee records, financials, passwords, proprietary methods
- Who approves new AI tools and new connections
- Who reviews AI output before it goes to clients
- Who to tell if something goes wrong, with a promise that nobody gets in trouble for raising their hand
Our AI Baby Steps Guide has a starting template for owners who are just getting going.
If you think something already leaked
Our approach is the same one we use for any IT problem: stop the bleeding, analyze the problem, build a solution.
- Stop the bleeding. Pause the tool or connection involved and change any credentials that may have been exposed.
- Analyze the problem. Who used which tool, what data went in, and was that use allowed?
- Build the solution. Fix the access, update the rules, and tell the people affected what changed.
Call your IT provider early in step one. Please don't be embarrassed. We'd much rather investigate a false alarm than clean up an exposure that sat quietly for weeks.
Bring the business owner your evidence
Your checklist is also your case for support. Owners respond to specifics: which tools, which data, which connections nobody approved, and what it would take to fix them.
That's why we tell clients to bring IT in before signing the contract, whether the purchase is an HR platform or an AI assistant. We explained why in Why You Must Involve IT in the Planning Stages of Your Next Project.
Where Solve iT fits in
Co-managed IT is reinforcement. You keep the decisions, the relationships, and the knowledge of how your business runs. We take on the work that buries one person: patching, monitoring, alert triage, backup verification, overflow support, and visibility into which AI tools are actually in use.
If you're carrying IT, and now AI, on top of your actual job, compare your workload and coverage against a co-managed model with Solve iT. You'll get a plain-English view of what you keep, what we can take off your plate, and where the gaps are. Talk to us about co-managed IT
Quick Answers
What should I check first when securing AI at a small business? Start with an inventory of which AI tools people use, for what, and on whose account. You can't secure tools you don't know about.
What is an AI connector, and why is it risky? A connector lets an AI tool read or change data in another system, such as email, files, or a CRM. It's risky when nobody reviewed what it can access or who approved it.
What should an AI policy for a small business include? Approved tools, prohibited data, who approves new tools and connections, who reviews output, and how to report a problem.
What should I do if an employee put sensitive data into an AI tool? Pause the tool, change any exposed credentials, work out what data was involved, and contact your IT provider early.
Is co-managed IT a good fit for someone who runs IT without an IT title? Often, yes. You keep decision-making and business knowledge while a provider handles monitoring, patching, and overflow work.