Most small business AI adoption fails the same way: someone buys a tool, nobody changes how work is done, and six months later the subscription is cancelled. The businesses getting value start from a specific task that is expensive, repetitive and tolerant of imperfection, and work backwards.
Pick the task first
Good candidates share characteristics:
- High volume, low variation — drafting similar documents, categorising transactions, summarising incoming enquiries.
- A human reviews the output anyway, so an error is caught before it reaches a customer.
- Time-consuming rather than judgement-heavy — first drafts, meeting notes, data extraction from documents.
- Measurable, so you can tell whether it worked.
Poor candidates are the mirror image: low-volume tasks, anything where an error reaches a customer unreviewed, and anything requiring genuine professional judgement where you carry liability for the answer.
Where the data goes
This is the question to settle before anyone types anything sensitive into anything.
For each tool, establish:
- Whether your inputs are used to train the provider’s models, and whether you can opt out.
- Where data is stored and processed, and under what jurisdiction.
- Retention — how long inputs and outputs are kept, and whether you can delete them.
- Who at the provider can access your data.
- Whether the business or consumer tier applies — the terms frequently differ substantially, and the free tier usually has the weakest protections.
Under the Privacy Act 2020, putting customer personal information into a third-party tool is a disclosure, and you remain accountable for it. Where information goes offshore, additional obligations apply around ensuring comparable protections.
The practical rule most small businesses can live with: no customer personal information, no commercially sensitive contracts, and no credentials into any general-purpose AI tool unless you have specifically confirmed the terms support it.
Set a usable policy
Staff are already using these tools. A prohibition will be ignored and will simply remove your visibility. A short, practical policy works better:
- Which tools are approved, and which tier.
- What may never be entered — customer data, health information, credentials, unreleased financials, third-party confidential material.
- That output must be reviewed by a person before it is used externally.
- That AI-generated material must not be presented as professional advice.
- Who to ask when someone is unsure.
One page. Reviewed annually. Better than a policy nobody reads.
The legal exposure worth understanding
Accuracy. These systems produce confident, plausible, wrong answers. If you publish an AI-drafted claim about a product, the Fair Trading Act applies to you, not to the tool. Substantiation is still your obligation.
Confidentiality. Entering a client’s confidential information into a third-party service may breach your confidentiality obligations to them regardless of what the provider does with it.
Intellectual property. Ownership and licensing of AI outputs is unsettled in many respects. For anything you intend to rely on commercially — a logo, substantial code, published content — check the provider’s terms on ownership.
Employment decisions. Using AI to screen candidates or assess performance introduces discrimination risk and is an area where you should take advice before deploying.
Security
The National Cyber Security Centre has published guidance on AI security including agentic systems — tools that take actions rather than just producing text. Agentic tools connected to your email, files or systems expand your attack surface meaningfully, and the guidance is worth reading before granting any tool that kind of access.
Apply the same controls you would to any software: multi-factor authentication, least-privilege access, and removal when someone leaves.
Run a real trial
Pick one task, one team, six to eight weeks. Measure the time the task took before and after, and the error rate. Ask the people doing it whether it actually helped or whether they are now spending the saved time correcting output.
Be willing to conclude it did not work. A trial that ends in a clear no is a good outcome and costs a fraction of an unexamined subscription renewed for three years.
The NCSC publishes AI security guidance, the Office of the Privacy Commissioner publishes material on AI and privacy obligations, and business.govt.nz publishes practical technology guidance for small business — all free and none with a product to sell.








