- A market in transition: the context nobody can ignore
- The numbers redefining how we see risk
- Why AI security is structurally different from classic cybersecurity
- What nobody is saying out loud: even vendors are flying blind
- Strategic reading: three levels of exposure for Italian SMEs
- Operational implications: building a minimal and scalable AI governance
- The work-in-progress site: where are we heading
In May 2026, TechCrunch highlighted an uncomfortable fact: even Google faces real-time security challenges related to artificial intelligence, without a definitive roadmap. No market player, however structured, currently has a fully consolidated AI security framework.
Therefore, Italian SMEs integrating AI tools into their processes are not at an absolute disadvantage compared to big tech. Instead, they are in a shared transition phase. However, this does not reduce operational risks; on the contrary, it makes them more insidious because they are less predictable. Vulnerabilities emerge non-linearly. Attack vectors evolve alongside the models themselves.
In this scenario, we at SHM Studio We believe the priority for SMEs isn't waiting for definitive standards. It's building minimal, scalable, and documented AI governance today. Finally, it's crucial to understand that AI security isn't just a technical issue: it involves processes, suppliers, data, and legal responsibilities. The following analysis offers a strategic reading of the phenomenon and concrete operational guidance.
A market in transition: the context nobody can ignore
In May 2026, TechCrunch published a significant analysis : even Google, one of the best-equipped players in the world for digital infrastructure, is navigating AI security challenges in real time. There is no definitive map yet. Everyone is learning as they build.
This data changes the perspective with which Italian SMEs should view the adoption of artificial intelligence. In fact, the dominant narrative tends to present big tech companies as holders of already mature solutions. In reality, the landscape is more fluid and, in some ways, more democratic than it seems.
However, the fast-changing context doesn't mean there's no risk. On the contrary, it makes risk harder to predict. SMEs that integrate AI into their daily workflows — from Digital marketing to document management — need to build a fresh mindset. Picking a certified tool isn't enough: you've got to keep an eye on how it changes over time.
The numbers redefining how we see risk
According to Gartner AI Hype Cycle 2025 , over 40% of organizations that have adopted generative AI solutions have already experienced at least one related security incident. Of these, the majority were not attributable to vulnerabilities in the model itself, but to integration and configuration errors.
Also, a report by McKinsey on the Global AI Survey highlights that less than 30% of mid-sized companies currently have a formal policy for the safe use of AI. This figure is especially relevant for the Italian market, where the fragmentation of SMEs makes distributed governance even more complex.
Basically, the problem isn't just about the tech giants. It affects every organization that uses third-party APIs, cloud models, and LLM-based automation tools. As a result, the risk perimeter has expanded well beyond the traditional boundaries of corporate cybersecurity.
Why AI security is structurally different from classic cybersecurity
Traditional cybersecurity operates on relatively stable surfaces. A firewall protects a defined perimeter. An antivirus recognizes known patterns. AI security, on the other hand, has to deal with systems that change their behavior based on data and context.
Therefore, the most relevant attack vectors are not always technical in the classic sense. The prompt injection , for example, exploits the linguistic nature of models to alter their output. The data poisoning compromises the quality of the upstream training set. These attacks do not necessarily require privileged access to systems.
For this reason, even a company with solid IT infrastructure can be vulnerable if it hasn't considered the specific traits of the AI layers it has integrated. Likewise, a tool from artificial intelligence applied to marketing can become a risk vector if not managed with proper policies.
On top of this, legal liability is still undergoing regulatory definition in Europe. The AI Act framework introduces gradual obligations, but their practical application to SMEs still requires operational clarification.
What nobody is saying out loud: even vendors are flying blind
The Google case, reported by TechCrunch, is emblematic. This is not an isolated failure, but a systemic condition. AI vendors — even the most robust ones — release updates that change model behavior in ways that are not always predictable. Consequently, the security of an AI system is not a fixed state: it is a continuous process.
This has direct implications for those who purchase or integrate third-party AI tools. SMEs tend to trust the vendor's reputation and not monitor release notes. However, a silent update can change data handling methods, retention policies, or model behavior in critical edge cases.
We at SHM Studio we see this happening in digital ad campaigns too. Ad automation tools — like the ones used for google ads campaigns or for LinkedIn campaigns — are packing in more and more AI features. Because of this, keeping these tools secure is now up to the people who set them up and watch over them.
Strategic reading: three levels of exposure for Italian SMEs
Not all SMEs have the same risk profile. It helps to break down exposure into three levels based on how deeply AI is built into business processes.
- Low level: use of SaaS tools with built-in AI (e.g. CRM with automatic suggestions, copywriting tools). In this case, the risk is mainly related to the management of data entered into the system and the vendor's policies.
- Medium level: API integration of LLM models into internal workflows (e.g. automated responses, document analysis). Here the risk increases: prompt management, data transmission, and system logs need to be monitored.
- High level: development or fine-tuning of proprietary models, or use of AI in critical decision-making processes (e.g., customer scoring, dynamic pricing). In this scenario, structured governance is necessary and, ideally, a dedicated AI security role.
So, the first move for any SME is to honestly map out their risk level. Only then can you make sure resources are spent wisely.
Operational implications: building a minimal and scalable AI governance
In the absence of definitive standards, the most effective response is not waiting. It is building a minimal, documented, and reviewable AI governance. This doesn't necessarily require massive resources. It requires method.
First of all, it's advisable to inventory all AI tools used in the company — including those informally adopted by individual teams. SMEs often discover they have greater exposure than they thought. Subsequently, it's necessary to define acceptable use policies, with particular attention to the management of sensitive data and customer data.
Furthermore, it is advisable to establish a process for periodically reviewing the AI vendors used. Terms of service change. Data policies evolve. A semi-annual check is the bare minimum. Finally, it is useful to train internal teams on the specific risks of AI, which differ from those of traditional cybersecurity.
From a digital presence standpoint, even the strategies SEO and of Digital marketing are increasingly incorporating AI components. The quality of content produced with AI support — for example through copywriting services — it also depends on the strength of the processes used to handle these tools. Unsupervised AI output can generate inaccurate, misleading, or non-compliant content according to editorial guidelines.
To dive deeper into the technical implications, it is also useful to consult the research by MIT Technology Review on AI and emerging risks , which offers an updated perspective on the systemic vulnerabilities of generative models.
The work-in-progress site: where are we heading
Projections for 2027-2028 indicate a progressive consolidation of AI security standards, driven by the application of the EU AI Act and the pressure from insurance markets, which are beginning to price AI risk into cyber policies. However, the path to mature standards will take years.
In the short term, it's reasonable to expect an increase in AI-related incidents, simply because more organizations are integrating these tools without adequate preparation. Consequently, SMEs that invest in governance and training today will be in a better competitive position—not only in terms of security but also in terms of customer trust.
The web infrastructure design safe and responsible management of AI tools are now an integral part of a mature digital strategy. Those who understand this now will have fewer problems to handle tomorrow. To chat with our team, you can contact SHM Studio or explore the resources available in the Blog .
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.