AI Adoption & Trends
Most Small Businesses Use AI Every Day. Almost None Have Written Rules for It.
New data from Intuit shows 77% of small businesses use AI daily, but most have no written policy for it. With EU transparency rules effective August 2 and 49% of employees using unapproved tools, the gap between adoption and governance is now a real business risk.
July 19, 2026 · 4 min read
What changed
Intuit published its 2026 AI Impact Report in May, drawing on surveys from more than 34,000 small and midsize business owners across the US, Canada, the UK, and Australia. The headline number is striking: 77% of US small businesses now use AI regularly, up from 48% in July 2024. Usage has nearly doubled in less than two years, and 78% of those businesses report a productivity improvement. That is the optimistic part of the picture. The part that got less attention at the time resurfaced in a Forbes piece published July 19, 2026, which highlighted what the same data reveals about governance. Most of those businesses adopted AI one subscription at a time, with no written rules and no review of what their employees were actually using. According to the report, 49% of employees use AI tools that were never approved by their employer, and 58% of those tools are free versions without strong data controls.
The honest nuance
The governance gap would be easy to dismiss as a large-company problem, but the timing makes it urgent for small businesses too. The EU AI Act's transparency provisions go into effect August 2, 2026. Any business that interacts with EU users will need to disclose when customers are talking to an AI system and may need to label AI-generated or altered content. The FTC has a proposed federal accuracy standard in comment review, with a deadline of July 31. Meanwhile, 47 US states have enacted some form of AI-generated media legislation, with conflicting standards across them. None of this is aimed specifically at small businesses, but the rules do not make an exception for them either. The more immediate issue is simpler: if nearly half your employees are using AI tools you did not choose and did not vet, you have no control over what client data is being pasted into which systems.
Why it matters
For a solo operator or small team, the risk profile here is different from what a legal team at a midsize company would worry about. It is not primarily about regulatory fines, at least not yet. It is about client trust and consistency. A freelancer who pastes a client's confidential brief into a free AI tool with a training-data opt-in is breaking that client's trust even if the client never finds out. A small business whose team uses four different AI writing tools will produce inconsistent output, sometimes with factual errors, sometimes with the wrong tone, without a clear explanation of why. A one-page policy does not have to be a legal document. It can be a short, plain list: which tools are approved, what kinds of information should never go into any AI tool, what requires a human review before it goes to a client, and who to ask when a new tool comes up. That list takes less than an hour to write. It closes a real gap that the data says most small businesses are quietly ignoring.
What to actually do
Write your AI policy this week. Keep it to one page. Cover five things: which AI tools your business approves, what categories of information never go into an AI tool (client data, passwords, unreleased work), when a human review is required before AI output goes anywhere external, how to handle a client or customer who asks whether you used AI, and who to contact when a new tool looks useful. If you are a solo operator, this policy is for you, as a reminder when you are working fast. If you have even one other person, share it with them before the end of the week. You do not need legal review to start. You need a short, honest list that everyone on your team actually reads.
From Kindloom Labs
The free Quick Read What Not to Paste Into AI covers the five categories of information that should never go into an AI tool, with safer alternatives for each. It is a useful starting point for writing the data-handling section of an AI policy.
Sources
Keep reading
Stay in the loop
Get notified about new releases, content, and blog updates from Kindloom. No spam, unsubscribe anytime.