
The real AI risk to your business isn’t the one making headlines.
If you’ve seen a headline this year about AI “autonomously” hacking into companies or discovering software flaws on its own, you’d be forgiven for picturing a machine quietly working its way through your firewall while you sleep. Read past the headline and the claim holds up. It just applies to your business differently to how it sounds.
The computers and services your business runs on haven’t changed. The techniques that compromise a small or medium Tasmanian business (a stolen password, a convincing fake invoice, a personal phone with no security controls) work exactly the way they did before generative AI existed. The fundamentals of securing a business haven’t moved. What’s changed sits closer to home, inside your own business, not in some external AI threat.
The Fundamentals Haven’t Moved. The Deception Has.
AI is a text prediction engine. It isn’t self-aware and it doesn’t decide to attack anyone. People build the tools and give the instructions, and AI carries them out at a speed no person could. The techniques are the same ones attackers have used for twenty-five years. The easiest way to picture it: every attacker is now a hundred attackers who never sleep. A poor one becomes a hundred poor ones. A good one becomes a hundred good ones.
That’s why the fundamentals still hold. Patching, backups, multi-factor authentication and phishing protection do the same job they always did. If your phishing protection is solid, it still protects you, now at a hundred times the volume. If you have none, the odds have moved against you. What AI really changes is the barrier to entry. It makes weaknesses worth exploiting that used to be too much effort to bother with, and it has lifted the quality and speed of the deception.
AI Is Already Inside Your Business. The Question Is Whether Anyone’s Managing It.
Over the past 18 months, AI tools have gone from something the marketing team experimented with to part of daily operations: drafting client emails, summarising meetings, analysing spreadsheets. Useful, and in most small businesses we work with, completely ungoverned. Staff are pasting client details, financials and contracts into AI tools with no visibility into where that data goes or whether it trains a model a competitor might later query. Nobody’s doing this maliciously. They’re trying to get the job done faster, the same way people always have. Much of that data ends up with US-based AI companies, often without customers being properly told it’s happening.
AI has improved the attacker’s side too, mainly through better social engineering rather than autonomous hacking. Attackers who couldn’t write convincingly, or couldn’t sound local, can now feed real emails into an AI tool, learn how a person writes, and impersonate them. The clumsy email with broken English is largely gone. In its place are fluent messages that reference real projects, real colleagues and real suppliers. Voice cloning has followed the same curve: a short public recording is now enough to convincingly fake a phone call from “the boss” asking for an urgent payment.
Better written phishing doesn’t beat good training. It beats bad training. Teaching staff to look for typos was always the wrong lesson. What works is context. Does this person normally email me about this? Is the request in character? Is there a genuine reason the bank details changed?
You Don’t Need to Have “Adopted” AI for This to Apply to You
If anyone on your team uses ChatGPT, Copilot inside Microsoft 365, an AI meeting note-taker, or an AI feature bundled into your accounting or CRM software, AI is already part of how your business runs, whether or not that was ever a formal decision. That’s not unusual. It’s now the default for most of the small businesses we work with. The risk isn’t the tool itself. It’s that nobody has mapped what’s flowing through it. A staff member summarising a client contract in a note-taker, or pasting a supplier’s financial details into a chatbot to tidy up an email, is making a judgement call about your business’s data that the business itself never got to make.
The Fix Is a Habit, Not a Ban
A blanket ban on AI tools is tempting and rarely holds. Staff who lose access at work tend to keep using personal accounts on personal devices to get the same benefit, which moves the activity further from your visibility, not closer to it. What actually works is smaller and more durable: a simple written policy on what information can and can’t go into AI tools, a half-day exercise rather than a project, paired with one non-negotiable verification step for anything unusual involving money or credentials, even, especially, when it sounds exactly like the right person asking. A callback on a number you already had, not the number in the email or the voice on the phone, is worth more than any amount of suspicion. This year’s theme for Cyber Security Action Month, “Take a second. Stay secure.”, describes that habit well.
The Pritech Approach
At Pritech, we help Tasmanian businesses work out where AI already sits inside their operations and close the governance gap before it becomes an incident, not after. We partner with Microsoft, and much of the AI use we see in small businesses now arrives through Microsoft 365 itself, via Copilot and AI features switched on inside tools the business already pays for. That makes it the natural place to start setting sensible limits on what those tools can see.
Talk to Pritech about what’s actually flowing through your business’s AI tools. Get in touch today.



