AI in small businesses rarely runs into a technology problem. The tools are accessible, often for the price of a subscription. It runs into two questions managing directors rightly ask: what will it actually save, and what happens to the data put into it? The first often goes unanswered because people start with the tool; the second, because it is only asked afterwards.
European figures reflect this gap. According to Eurostat, 20% of EU businesses with at least ten employees used an artificial intelligence technology in 2025, but only 17% of small businesses, against 55% of large ones. Among businesses that had considered AI without adopting it, nearly half cited concerns about data protection and privacy, and more than half unclear legal consequences.
AI in small businesses: the uses that pay off quickly
The uses that produce a quick gain have three things in common: they concern a frequent task, they take time without requiring expert judgement, and their result is easy to check. In a small business they are almost always found in the same places.
- Drafting and rewording: replies to recurring requests, letters, product sheets, meeting notes.
- Summarising: a long email thread, a tender, a contract before its legal review.
- Extracting and classifying: the useful information from an invoice, an order form, a questionnaire, to feed a spreadsheet or software.
- Searching one’s own documents: procedures, contracts, technical files queried in plain language.
These uses have one more thing in common: they speed up a skill the team already has. That is the condition for a gain to be real — whoever delegates must be able to judge what comes back, as argued in AI accelerates a skill, it does not create one. A use that requires trusting an answer one cannot check is not a good first case.
Conversely, some uses do not make good first cases, however tempting: those touching decisions about people — recruitment, appraisal —, those producing legal or financial advice that commits the business, and those letting the tool act alone, without review. They are not forbidden in principle; they require a framework a business just starting out does not yet have.
Choosing a first case and measuring it
The approach has four stages, and the first has nothing technical about it.
- Choose a task. Just one, specific, that someone does often and that takes them time. “Answering incoming quote requests” is a case; “using AI in the sales department” is not.
- Measure before. How long does the task take today, and with what result? Without that baseline, no gain can be demonstrated.
- Try it for a few weeks. With an approved tool, on approved data, by the people who do the task.
- Measure after, and decide. Time saved, quality of the result, errors corrected. Then roll out, adjust or drop it.
Measurement need not be sophisticated. For a team answering quote requests, it is enough to record, for two weeks before the trial and then two weeks during it, the time spent per reply and the number of replies corrected before sending. The result fits in a four-column table. It is worth more than a general impression, because it withstands both the enthusiasm of the first days and the scepticism of those who have not tried.
That is also what the CNIL recommends for any generative AI deployment: start from a concrete need rather than a tool. Measurement has an advantage demonstrations lack: it allows you to say no. A use that saves nothing after a few weeks stops, and the business has learned something at little cost.
Protecting data from the start
Data rules are set before the first trial, not afterwards. Three decisions are enough to start.
- Which data may be entered. For a first case, the simplest approach is to exclude personal and confidential data, or anonymise it before entry.
- In which tool. A business account managed by the company, with a reviewed contract, rather than employees’ personal accounts — the differences between consumer and business offers are set out in ChatGPT and GDPR.
- Who validates the results. An answer produced by AI is reviewed by someone competent before it is sent or used.
When the most useful application involves precisely sensitive data — client files, health data, industrial secrets —, the question moves up a level. An environment is then needed in which the data does not leave, and that is the purpose of sovereign AI: a model run on controlled infrastructure, as Maeliom’s sovereign AI offer provides in early access.
From trial to everyday use
A successful trial does not become everyday use on its own. Three conditions help. First, write the rule: which tools, which uses, which data, in the IT usage policy or a simple note. Next, train the other teams from the experience of the first case, with its measured results rather than promises. Finally, appoint someone to follow usage, list new tools and review the rules when offers change — which happens often.
Scaling up can be calculated too. Extending a use to a whole team means multiplying subscriptions, training time and reviews. The gain measured on the first case makes it possible to do that calculation before committing, and to extend first where the gain is clearest rather than everywhere at once.
That last function is missing in most small businesses. It belongs to a technical leadership the business does not always have: it is one of the roles a part-time CTO can fill, arbitrating between tools, framing uses and checking what they deliver.
One point of vigilance remains that measuring time saved does not capture: what the use causes to be lost. A skill no longer exercised erodes, and the effect does not show in the first weeks — the argument of what AI costs does not show. Good use speeds up a team’s work without taking away what it needs to know how to do.
Common questions
Where should a small business start with generative AI?
With a specific, frequent task that is easy to check, whose time is measured before and after a trial of a few weeks. The choice of tool comes afterwards.
Is generative AI compatible with the GDPR?
Yes, provided what is entered is governed, a business offer bound by a processing contract is used, and, for sensitive data, an environment in which it does not leave is favoured.
Should employees be trained before being given access to AI?
Yes, briefly: what may and may not be entered, how to anonymise a request, and why each answer must be reviewed. An hour is often enough; it avoids most mistakes and makes the rule understandable.
How much does a first AI project cost a small business?
A first trial can be run with a business subscription and a few weeks of the people involved. The real cost lies mostly in that time, and in preparing documents when the use involves them.
Sources: Eurostat, use of artificial intelligence in enterprises (2025 data, extracted December 2025); CNIL, deploying generative AI (July 2024).