Cybersecurity expert Sergio Herce warns that the main risk posed by artificial intelligence to small and medium-sized businesses lies in the uncontrolled use of commercial tools and generative AI by employees using personal accounts (a phenomenon known as “shadow IT”), which can expose sensitive customer and financial data without the company’s knowledge. Furthermore, AI has democratized and drastically accelerated cyberattacks, enabling criminals to launch hyper-realistic, automated phishing campaigns on a large scale.
On the other hand, Herce points out that connecting AI agents directly to databases or internal systems without strict supervision and adequate access controls multiplies corporate vulnerabilities. Given this scenario, the key for small and medium-sized businesses is not to ban the technology, but to establish clear usage policies, train employees in cybersecurity, and equip themselves with intelligent defenses capable of stopping automated threats as quickly as they occur.