
Know what's running.
3 SIGNALS · 1 LESSON · 1 ACTION · ABOUT 5 MINUTES
Small businesses have crossed the AI-access threshold. The advantage now comes from redesigning work around useful outcomes, then proving that the tools and controls behave as intended.
SIGNAL 01
Small businesses solved AI access. The operating problem is next.
What happened. The U.S. Chamber of Commerce's fourth Empowering Small Business report, a Teneo Research survey of 3,870 businesses with fewer than 250 employees, puts small business AI use at 58%, up from 40% in 2024 and 23% in 2023. Generative AI now ranks among the top three technologies small businesses use, behind search engines. And it is new: 86% of AI-using businesses adopted generative AI within the past two years, and 55% have used it for a year or less. The workforce section shows how thin that readiness can be. Asked how they make workers AI-ready, the most common answer, at 41%, was providing AI tools and hoping employees learn to use them. Hope outpolled on-the-job training (39%), outside training (36%), and hiring for AI skills (36%). Meanwhile, 63% of AI-using businesses rely mostly or entirely on tools built by other companies; only 8% primarily build their own.
Why it matters. Adoption and capability are different things, and the survey measures the first. A business can truthfully answer "we use AI" the day it hands employees ChatGPT or Copilot. That answer says nothing about whether anyone has identified the workflows where AI creates value, whether outputs get checked, what data flows into the tools, or whether ten employees are quietly inventing ten conflicting ways of working. The report does not measure those things; nobody's survey does yet. Most small businesses have crossed the access threshold, but access arrived years ahead of the operating discipline. "We use AI" is on its way to meaning about as much as "we use email." The more useful divide in 2026 is between businesses that have operationalized AI against specific workflows and those that merely have it.
I recently explored the security and workforce implications of these findings in a LinkedIn article, “Small Businesses Are Moving Fast on AI. Security and Skills Need to Keep Up.”
What to do. Retire "do we use AI?" from your vocabulary; at 58% and climbing, it is table stakes. Ask instead: in which three workflows does AI touch our business today, what outcome is each supposed to improve, and would we know if it did? If nobody can answer, the work of operationalizing AI has not started.
SIGNAL 02
Start with the work, not the tool
What happened. A July 8 McKinsey study of 750 employees and leaders found a wide gap between individual AI readiness and organizational readiness. Seventy percent of respondents felt personally prepared to use AI, but only 27% of leaders believed their organizations were prepared to make the changes required. Among organizations in the study's earliest adoption stage, leaders were 5.3 times more likely to report enterprise value when workflows had been redesigned rather than left unchanged.
Why it matters. Buying an AI assistant selects a technology. Value comes from deciding how a customer request should move from intake to resolution, where judgment belongs, what can be automated, and which result matters. Those choices determine the return on investment and where security belongs. If you add AI before mapping the work, data and decisions can start moving through a process nobody has deliberately designed.
That finding echoes my dissertation research on AI adoption in maritime cybersecurity education. Participants saw value in the technology, but successful adoption depended on human oversight, quality source material, and coordinated support at the individual, organizational, and cross-sector levels.
What to do. Pick one recurring workflow with a visible bottleneck. Map the current steps, handoffs, information used, decisions made, and baseline result. Redesign that workflow first. Only then choose the AI capability that fits the job and define how you will measure the result.
SIGNAL 03
You don't need a rogue agent to have a security incident
What happened. Anthropic's August Risk Report describes an employee giving an agent an open-ended task on a computing cluster containing sensitive resources. The employee's AI use was neither logged nor covered by automated offline monitoring. Legacy instructions led the main agents to spawn additional agents using --dangerously-skip-permissions, bypassing normal permission checks. Those agents were also unmonitored, and one deleted a large number of jobs.
Anthropic believes the agent was deleting jobs it had created, not acting maliciously, but the monitoring gap prevented the company from confirming that explanation. Anthropic added blocking controls that it believes would likely prevent this specific behavior. Its offline monitoring still does not cover every employee or every use of clusters containing highly sensitive resources.
Why it matters. A capable agent pursuing a legitimate objective can cause damage when it has broad permissions, sensitive access, and too little monitoring. Hostile intent is not required. As organizations connect agents to email, cloud infrastructure, source code, customer systems, APIs, and internal databases, security depends increasingly on what the agent can do after receiving a task.
Manipulating a model's input or output is a prompt-security problem. Giving a model tools and permission to act introduces a different problem: controlling what the agent is allowed to do. Prompt injection becomes far more consequential when the prompt has permissions, but ordinary mistakes are reason enough to control agent actions.
What to do. Give each agent its own identity. Limit its tools and permissions, log its actions, and require human approval for destructive or high-consequence changes. Prefer reversible actions and test the boundaries before production use.
Ask one question: If one of our AI agents made a mistake tomorrow, which systems could it change before a human noticed? If the answer is unclear, the agent has more freedom than the organization can govern.
Source: Anthropic, Risk Report (August 2026)
THE LESSON
Access is what you buy. Capability is what you build.
The three signals describe three different layers of AI adoption.
The first is access: people have accounts and can use the tool. That layer is becoming ordinary. The second is workflow: the business has decided where AI belongs, how the work should change, and what result should improve. The third is authority and assurance: the organization has decided what the AI may read, change, approve, or trigger, and can show that those boundaries work in practice.
These layers must be designed together. A company that starts with a product demo tends to fit the tool into whatever work already exists. That may save an employee a few minutes, but it rarely changes the economics of the process. Worse, it can quietly add new data flows, permissions, and decision points before anyone has assigned responsibility for them.
Start with a business outcome: reduce the time required to respond to a qualified lead without lowering response quality. Then map the workflow, identify the delay, and decide which parts require human judgment. The technical question becomes narrower and more useful: can an approved tool draft a response from approved data, route it for review, and cut turnaround time by 30%? Now you have something to test. You also know which data, permissions, review steps, and logs matter.
AI capability is a repeatable way of working that produces a measurable result inside boundaries you can verify. Organizational support makes the workflow usable; action security keeps its authority proportionate to the job.
DO THIS WEEK
Map one workflow and its authority
Choose one recurring workflow and put it on a page. Record its business outcome, current baseline, major steps, data used, decision owner, and one place AI could help. Then add the authority layer: which systems the AI may access, what it may read or change, which actions require human approval, what gets logged, and how a mistaken action can be reversed. Finish with the metric you will check after 30 days. If you cannot answer those questions, do not give the AI broader access yet.
THE ROUNDTABLE
Leading when AI makes the calls
The operating system around AI is exactly what I want to explore next.
On September 9, I'm hosting a small executive roundtable on Operational AI Leadership: how do you lead an organization when AI is increasingly making, recommending, or influencing decisions once reserved for people?
I'll start with a 25-minute walkthrough of the framework I've been developing, including where AI should decide and where people should remain involved, how accountability changes as AI moves into everyday operations, and what it takes to turn scattered AI experiments into a durable organizational capability.
Then we'll open it up.
The framework is still in the research phase, deliberately. I'm less interested in presenting a finished model than in pressure-testing it with executives, board members, and senior leaders dealing with these questions in real organizations.
Wednesday, September 9 at 10:00 a.m. Pacific.
See you next week.
— Chris Simpson
Hackademic Solutions
The Hackademic Briefing · Know what's running.