Even heads of state don’t have an AI plan yet
On September 22, 2026, Greek Prime Minister Kyriakos Mitsotakis sat down with TechCrunch at an event in San Francisco and said something most politicians won’t say out loud: “Sometimes I feel that we’re already fighting yesterday’s battle.” He was talking about how fast AI is moving relative to any government’s ability to respond. He also said flatly that job displacement “is going to happen” and that “no government and no society is prepared for the speed with which it will happen.”
If you run a small or mid-size business in New Jersey or New York, that means you probably can’t wait for clear regulation before making decisions about AI tools. You’re going to have to make calls now, with incomplete information, the same way the rest of the world is.
What the “yesterday’s battle” problem looks like at the business level
The pattern Mitsotakis described, where a policy gets written for the last version of a problem and not the current one, shows up constantly in business IT. Your acceptable-use policy for company devices was probably written before your employees started using AI writing tools or AI-powered browser extensions. Your data handling agreements almost certainly don’t address what happens when an employee pastes a customer record into a chatbot to summarize it. These aren’t hypotheticals. They’re happening right now in most offices, with or without anyone’s approval.
AI tools can genuinely reduce busywork. They can also quietly erode the judgment and institutional knowledge your team builds by doing things the slower, harder way. That tradeoff deserves a deliberate decision, not a default.
The regulation gap is your risk, not someone else’s
Mitsotakis called “some form of smart regulation” inevitable, and said the U.S. will largely determine what it looks like. That means the rules are still being written. Businesses that treat “no clear regulation yet” as permission to do nothing are taking on real risk. Data you expose to a third-party AI tool today may be governed by rules that don’t exist yet but will exist in 18 months. If your IT setup isn’t documented and auditable, you won’t be able to demonstrate compliance after the fact.
If you want to think about AI readiness more concretely, understanding what AI-assisted tools actually do to your IT environment is a reasonable starting point. And because AI tools are increasingly being used to find security vulnerabilities, keeping your patch cycle tight matters more than it used to.
What to actually do about this
You don’t need a comprehensive AI strategy document. You need a few concrete decisions made now.
- Write a one-page policy on which AI tools employees can use with company data, and which they can’t. Review it every six months.
- Audit what data your team is putting into external AI tools. Start with your most sensitive categories: customer records, financial data, employee information.
- Make sure your Microsoft 365 tenant settings reflect your actual intentions around data sharing and third-party app access.
- Know where your backups are and test restoring from them. AI-generated errors and AI-assisted attacks both create recovery scenarios.
The companies that handle this well won’t be the ones who waited for perfect guidance. They’ll be the ones who made deliberate, documented decisions with what they knew at the time. If you’re not sure where your current setup stands, booking an IT assessment is a low-effort way to find out before something forces the question.
FAQ
Should my small business have an AI policy even if I only have a few employees?
Yes. Even a short written policy clarifies expectations and protects you if something goes wrong. It needs to answer which tools are allowed, what data can be used with them, and who decides when exceptions apply. Five employees can cause a data incident just as easily as fifty.
Is AI regulation coming that will affect how my business uses these tools?
Almost certainly. As of September 2026, senior government officials including national leaders are publicly saying regulation is inevitable and the U.S. will shape it. Businesses that have documented their AI usage and data handling now will have a much easier time demonstrating compliance once specific rules land.
How do I know if my employees are using AI tools with company data?
In most Microsoft 365 environments you can review third-party app permissions and browser activity through Intune and Defender for Endpoint. Without active monitoring, you genuinely don’t know. That’s the gap most small businesses are sitting in right now, and it’s worth closing before it becomes a problem.
Can AI tools actually create security risks for a small business?
Yes. Employees pasting sensitive data into external AI tools can expose that data to the tool’s provider and potentially to others. AI is also being used to find software vulnerabilities faster, which means unpatched systems face more exposure than they did even a year ago.