Answer in brief
A small company starts with AI by choosing one frequent, text-heavy task with a result it can count, not by buying a system. Check what the provider does with your data, run a thirty-day pilot with a baseline and one responsible person, then decide: extend, adjust or stop. A contractor is needed when the tool has to be connected to your own systems and files.
What bringing AI into a small company means in practice
Owners who ask how to use AI in business usually picture a large project: a robot at the front desk, a system that runs the company. In practice it is smaller and more useful. A few recurring tasks, most of them made of text, get done faster because a language model prepares the draft and a person checks it. Nothing has to be rebuilt; what changes is the order of work in two or three places.
How many companies already do this depends on who is counting. Eurostat’s survey says that in 2025, 19.95% of EU enterprises with ten or more employees and self-employed persons used at least one AI technology; among small enterprises the share was 17%, among large ones 55.03%. Stanford’s AI Index counts differently: its 2025 report said 78% of organisations reported using AI in 2024, up from 55% the year before, and its 2026 report puts organisational adoption at 88%. The two sources measure different groups, so read each number with its source and year, and plan from your own working week.
Choosing the first processes: frequent, text-heavy, measurable
The first candidate is a task that repeats every day or every week, consists mostly of reading and writing, and has a result you can count. Answering the same ten customer questions. Turning a call into a written summary. Writing product cards from a supplier’s spreadsheet. Each takes minutes and happens constantly. That is why it is a good place to begin: a mistake is cheap, and a month is enough to see whether anything was saved.
What companies actually do points the same way. In the Eurostat data the most used technology in 2025 was the analysis of written language, at 11.75% of enterprises. Among enterprises that already use AI, 34.70% apply it to marketing or sales and 31.05% to business administration or management. Text comes first. A task that needs judgement about money, health or a person’s rights is a poor first choice: leave it until the team knows how the tool fails.
Four families of tasks where a language model helps from day one
The first family is text and content: product descriptions, posts, job adverts, letters. The U.S. Small Business Administration (SBA), in its page on AI for small businesses, lists exactly this kind of work, from job postings and blogs to product descriptions for an online shop. The model writes the draft; the facts, the prices and the tone remain yours to check. The second family is answers to customers: the same page suggests a website chatbot that can answer common questions or complete an order.
The third family is documents: pulling the supplier, the amount and the date out of an invoice, comparing two versions of a contract, summarising a recorded meeting. It saves the most typing and needs the strictest checking, because a wrong digit in an invoice looks exactly like a right one. The fourth family is search over your own files: price lists, instructions, contracts, old answers to customers. An assistant answers from them and shows the passage it found; if the price list exists in five versions, it will quote any of the five, so order in the folders comes first.
Data and confidentiality: what stays out of a public chat
Before anyone pastes a contract into a chat window, read what the provider says it does with the text. Google’s Gemini Apps Privacy Hub states that a subset of chats is read by human reviewers and asks users not to enter confidential information they would not want a reviewer to see. The SBA gives small firms the same rule in one line: try not to feed AI tools any sensitive data or proprietary information. In practice that means no customer names and phone numbers, no card details, no passwords and no unpublished finances in a public chat. Where personal data is involved, the law of your country applies as well, and that is a question for a lawyer.
Business products come with their own terms, and those are not alike either. Anthropic’s Privacy Center says that by default the company does not use inputs or outputs from its commercial products, such as Claude for Work and the API, to train its models. Yandex writes in the AI Studio documentation that by default the models save all request data, and shows how to switch that logging off when requests carry personal or confidential data. So look for three things: who may read the text, whether it trains the model, how long it is kept. The answers change, so read the page itself on the day you decide.
A thirty-day pilot: one task, one number, one person in charge
A pilot is a small test with a date on it. Take one task, for example replies to typical customer questions, and measure it for a week before changing anything: how many requests arrive, how long an answer takes, how many answers have to be corrected. That is the baseline; without it there will be only impressions a month later. The SBA gives the same advice in two words, start small, and adds that tools are worth testing to see whether they add value to your business.
Then one person, by name, runs the test. For three weeks the tool prepares drafts and that person sends, corrects or rejects each one and keeps a short log of what had to be fixed. In the last week the same three numbers are compared with the baseline. The result is a decision, not a presentation: keep and extend, rewrite the instruction and repeat, or stop. Stopping is a normal outcome and costs one month.
People: who owns the tool and what changes in the job
The tool is the easy part; somebody has to learn it and somebody has to answer for it. In Eurostat’s 2025 data the most common reason for not using AI, among EU enterprises that had considered it, was a lack of relevant expertise, named by 70.89%. In the EU, training is written into the rules: the European Commission’s questions and answers on AI literacy, updated in July 2026, say that Article 4 of the AI Act asks providers and deployers of AI systems to take measures to support the AI literacy of their staff, with no certificate needed. Whether that article concerns your company is something to check with a specialist.
In practice it comes down to three decisions. One person owns the tool: keeps the instructions, knows the account settings, answers colleagues’ questions. The team learns on its own material, an hour with real letters and invoices rather than a general lecture, and writes down the instructions that worked. And the job shifts from writing to checking, which is a different skill. The SBA says it directly: if you use free AI tools, have another person review everything they produce, and make sure a person assesses the messages and outreach campaigns that AI generates.
Why pilots stall: no owner, no baseline, a broken process
Three causes come up again and again. The first is a pilot that belongs to everyone: the director paid for a subscription, five people tried it for a week, nobody decided anything. The second is a missing baseline: after a month the team cannot say whether replies got faster. The third is automating a process that was already broken. If requests get lost because nobody is responsible for the inbox, a model will lose them faster and more politely.
For those who want a structure, NIST’s AI Risk Management Framework offers a ready one. NIST released it on January 26, 2023, describes it as intended for voluntary use, and notes on its page that version 1.0 is being revised. Its core has four functions: govern, map, measure and manage. Translated for a small firm: decide who is responsible, describe where the tool is used and what can go wrong there, test it before launch and regularly afterwards, and act on what the tests show. For a company of twenty people, a page of notes under those four words is enough.
When a contractor is worth it and what to prepare first
A chat subscription and a careful employee cover the first family of tasks without outside help. A contractor becomes worth it when the tool has to be connected to something: the CRM, the shop, the messenger, the document archive; or when answers must rest on the company’s own files and access rights matter. The same is true when nobody inside has the hours to run the pilot properly. A studio such as VITON13 does this kind of work: it picks the process with you, connects the model to your systems, sets up the checks and hands over the instructions.
So prepare before you write to anyone. Describe one process in ten lines: what comes in, who does what, what goes out, how often. Add the baseline numbers from your pilot, or at least an honest estimate. List the systems involved and the data that may not leave the company, and name the person on your side who will own the result. With that page, the talk about how to use AI in business turns into an estimate with a scope and a date, and you can compare two offers instead of two promises.
Practical checklist
- List the tasks your team repeats every week and mark the ones that are mostly reading and writing.
- Pick one task and record three numbers for a week: volume, time per item, share corrected.
- Read the provider’s data-use page for the exact plan you will use and note the date you read it.
- Name one owner of the tool and set the day on which the thirty-day test ends.
- Write a one-page rule: which data never goes into a chat and who checks every result.
Questions and answers
How many small companies already use AI?
Eurostat reports that in 2025 17% of small EU enterprises, those with 10 to 49 people, used at least one AI technology, against 55.03% of large ones. Firms with fewer than ten people are outside the survey. Stanford’s AI Index gives far higher figures for organisations in general, so always look at who was asked.
Which task should a small business hand to AI first?
One that comes up often, is made mainly of text and has a result you can count: answers to typical questions, call summaries, product descriptions, sorting of incoming requests. Do not begin with decisions about money, health or people’s rights.
Is it safe to paste customer data into an AI chatbot?
Not into a public chat by default. Google’s notice for the Gemini apps asks users not to enter confidential information, and the SBA advises small firms against feeding AI tools sensitive or proprietary data. Business plans often carry other terms; read them, and take personal-data questions to a lawyer.
How long should a first AI pilot in a company last?
About thirty days is enough for one task: a week to record the baseline, three weeks of work with a person checking every result, and a comparison at the end. A longer trial with no closing date usually stops being a trial.
Does a team of ten need an AI risk framework?
Not a formal one. NIST’s AI Risk Management Framework is voluntary, and its four functions fit on a page: who is responsible, where the tool is used, how it is tested, what is done with the findings. Writing that page is useful at any size.
