- The historical moment: nobody has the map yet
- The numbers that downplay risk perception
- Why the Google case changes the strategic perspective
- The three most overlooked risk areas in SMBs
- The still open construction site: regulation and standards under development
- Operational implications for those managing digital infrastructures
- What nobody tells you: the competitive advantage of caution
In May 2026, TechCrunch documented how even Google is tackling security challenges related to artificial intelligence in real time, without consolidated protocols. No player—not even the biggest one—has a definitive map yet. Therefore, the sector is in an open and unpredictable transition phase.
For Italian SMEs, this scenario has real implications. In fact, many companies are integrating AI tools into their workflows, often without proper security governance. As a result, the risks are not just about big tech players: they affect anyone using APIs, language models, or AI-driven automations. Plus, the speed of adoption outpaces regulations, creating tricky grey areas that are hard to monitor.
We at SHM Studio we are keeping an eye on this trend to help our small and medium business clients build smart digital strategies. Basically, the main takeaway is simple: AI safety isn't a problem for tomorrow to be left to the big players. It's a hands-on priority right now, and it calls for smart choices starting today.
The historical moment: nobody has the map yet
We are right in the middle of a massive tech shift. Artificial intelligence has made its way into business operations so fast that building solid safety frameworks just couldn't keep up. Because of this, even the most prepared companies are flying blind.
In May 2026, TechCrunch published a significant analysis : even Google tackles AI safety challenges in real time. There is no pre-written manual. No player — not even the most capitalized one — has definitive answers yet. Therefore, the entire ecosystem is in a phase of collective learning.
This isn't a sign of isolated weakness. Instead, it’s a snapshot of an industry evolving faster than its own control mechanisms. For Italian SMEs, understanding this context is the first step to avoiding being caught unprepared.
The numbers that downplay risk perception
SMEs often perceive AI security as a big-player problem. The data tells a different story. According to the Gartner AI Trends Report , by 2027 over 40% of security incidents in organizations will involve AI components. Furthermore, most of these incidents won't come from sophisticated attacks. They'll come from misconfigurations, ungoverned access, and rushed integrations.
In parallel, the McKinsey State of AI 2025 had already pointed out that last year fewer than 30% of companies using AI had an official framework for managing its specific risks. So, the gap between adopting AI and managing it is real and easy to measure. For small businesses, this gap means they are wide open to risks.
Besides, the issue isn't just about cybersecurity in the strict sense. It's about input data quality, managing third-party APIs, and the traceability of automated decisions. In particular, these last aspects are often overlooked in the early stages of implementation.
Why the Google case changes the strategic perspective
The fact that Google navigates AI safety in real time has both symbolic and practical value. On one hand, it scales back the idea that ready-made, turn-key solutions already exist. On the other hand, it confirms that the complexity of the problem is systemic, not corporate.
However, there is a major difference between Google and an Italian SME. Google has dedicated teams, unlimited budgets, and direct access to the models it uses. An SME, on the other hand, works with third-party tools—often with no visibility into the underlying architectural choices. Consequently, the level of control is structurally lower, but the level of operational responsibility stays the same.
Therefore, the right strategic takeaway isn't "if Google struggles, there's nothing we can do." It's the opposite: "if Google struggles with massive resources, we need to be even more methodical with the resources we have." Scarcity calls for discipline, not resignation.
The three most overlooked risk areas in SMBs
In the experience of SHM Studio with Italian SMEs, three critical areas emerge that are systematically underestimated during the adoption phase of AI tools.
- Management of access to AI APIs. Many integrations are set up with shared API keys or without regular rotation. Plus, permissions are often wider than necessary. This creates attack surfaces that can be avoided with basic policies.
- Quality and governance of input data. AI models produce outputs proportional to the quality of the data they receive. In fact, unvalidated, duplicated, or sensitive data entered into corporate prompts generate both security and GDPR compliance risks. In particular, this applies to automated customer service systems.
- Traceability of automated decisions. When an AI system influences a business decision — an offer, a segmentation, a customer response — who is responsible for it? Although this is a seemingly simple question, most SMEs still do not have a documented answer.
Each of these areas calls for specific actions. Still, none of them are technically complex. They take method, not huge budgets.
The still open construction site: regulation and standards under development
The European AI Act has entered into force, but its practical application is still being defined for many categories of systems. Therefore, SMEs find themselves in a partially gray regulatory zone. This does not mean an absence of obligations: it means that the obligations are still taking shape.
At the same time, technical standards — like those from NIST or ISO for AI system safety — are always changing. Because of that, sticking to just one fixed framework today would be a mistake. The right move is to stay flexible: keep an eye on new rules, use the best tips out there, and check in on your choices every so often.
Plus, the tech supply chain is pretty huge. SMEs use tools built on third-party foundation models. So, security doesn't just depend on your own choices, but on your vendors' too. Checking out AI vendor security policies has become a must-have part of tech due diligence.
Operational implications for those managing digital infrastructures
For SMBs that have already started paths of AI integration in their processes, some operational actions are a priority in the short term.
First of all, you need to map all touchpoints between company systems and AI tools. This includes integrations in the workflows of Digital marketing , in CRM systems, in the tools of SEO and content generation. Then, for every single touchpoint, you should pinpoint the data passing through and the access policies applied.
Beyond that, it's helpful to name an internal point person — even an informal one — for AI decisions. This doesn't mean hiring someone full-time for the role. It just means having someone keep an eye on how the tools you use are changing and keeping track of the choices you've made. So, even in smaller teams, this responsibility needs to be clearly assigned.
Lastly, training your team is a total must-do investment. AI tools change fast. Still, basic digital hygiene rules — managing passwords, checking inputs, double-checking outputs — stay the same. Investing in these basics pays off big time, no matter what specific tools you end up using.
What nobody tells you: the competitive advantage of caution
There is a dominant narrative that links the rapid adoption of AI to an automatic competitive advantage. This narrative is partly true. However, it leaves out an important variable: speed without governance creates technical and security debt that you pay for over time.
SMEs that are building AI processes with an eye on security and traceability are building up a less visible but much more solid advantage. In fact, when regulation settles down—and it will—those who already have their governance in order won't have to stop to catch up. Those who rushed ahead without looking around will.
Therefore, methodical caution isn't a brake on innovation. It's a medium-term investment. In this sense, the Google case—navigating AI security in real time despite all its resources—is a useful reminder for everyone: complexity isn't solved with speed, it's managed with method.
To learn more about how to structure a digital strategy that integrates AI safely and measurably, the team at SHM Studio is available for a consultation . Furthermore, on our Blog we regularly publish analyses on web development , SEO copywriting , google ads campaigns and LinkedIn campaigns tailored for Italian SMBs.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.