The signal in Anthropic's small‑business push
Anthropic's recent Claude for Small Business announcement is a useful signal, not just another product launch. It is a public admission that most small organisations are still under‑using AI, even when it already sits inside their existing systems.
For a CEO or MD, the message is blunt: the constraint is no longer access. The constraint is how clearly your organisation has decided where AI is allowed to operate, what data it can see and what "good" looks like for your team's use of it.
This is the real work of AI adoption. It sits well beyond turning on a feature in a SaaS product. It is about what you ask your people to trust, how you protect the information they touch and what you are prepared to automate in your own name.
From "playing with prompts" to defined workflows
Most organisations begin in the same place: a handful of curious people experimenting with prompts in public tools. That phase is useful, but it does not add up to an adoption strategy.
If you stay there, you end up with important work happening in unmanaged systems, scattered copies of sensitive documents and no clear way to explain to your board how AI is actually being used.
A more mature pattern looks different:
- Specific workflows are identified where AI can reliably help - summarising long documents, drafting routine emails, preparing first‑pass analysis.
- Teams agree the boundaries: where humans stay firmly in the loop, what AI is not allowed to decide and which systems remain strictly human‑only.
- Output quality is monitored over time so you can adjust prompts, guardrails and training, instead of relying on gut feel.
The tools matter, but only in service of these decisions. Your choice of model provider is less important than the clarity of the workflows you are willing to automate and audit.
Why your data posture now matters more than your model choice
As AI becomes part of everyday work, the risk profile shifts from "what model are we using?" to "where does our data actually live when AI touches it?".
If staff are pasting customer information into unmanaged tools, you already have a shadow AI environment that sits outside your usual controls. This is the gap regulators, customers and acquirers are starting to look for.
A practical stance is to treat AI like any other system that handles important information:
- It should run in an environment you control, with the same identity, logging and access controls as your other core systems.
- Data used for prompts and context should stay in your own tenancy, under your existing contracts and policies, not scattered across consumer tools.
- You should be able to show, in plain language, how a particular answer was produced and what information it could see at the time.
Model choice still matters for capability and safety. But for most small and mid‑market organisations, the bigger differentiator is whether AI runs inside your environment and under your governance or outside it.
What this means for your team
For your team, "AI adoption" will not feel like one big switch being turned on. It will feel like a gradual shift in how work is done. Some patterns we see:
- Individuals move from writing everything from scratch to editing AI‑generated drafts.
- Subject‑matter experts spend more time reviewing and less time searching, as AI brings relevant documents and prior work into view.
- New joiners ramp faster because operational knowledge is captured in prompts, examples and playbooks, instead of only in people's heads.
This change needs clear leadership. People want to know what is encouraged, what is forbidden and how their own judgment fits alongside AI tools. Without that clarity, they either over‑trust the system or avoid it entirely.
A useful way to frame it: AI should make your best people more effective at the work only they can do. It should not become an unaccountable decision‑maker, or a backdoor for sensitive data to leak out of your environment.
Questions to ask inside your business
If you are responsible for AI direction, a few questions can help test where you are:
- Can we list the core workflows today where AI is allowed to help?
- Do we know which systems our people are actually using for AI, including unofficial tools?
- If a regulator, customer or acquirer asked how AI touches their data, could we answer confidently?
- Are we choosing tools because they are easy to turn on, or because they fit our data posture and governance?
Clear answers here do more for your risk and competitiveness than chasing the latest feature announcement. Tools will keep changing; your approach to team behaviour and data control is what needs to be durable.
A simple principle can guide you: once AI touches meaningful business information, it should live in an environment you can govern as confidently as your other core systems.
