Most AI advice for small businesses is about getting started. Almost none of it is about what happens at 16:40 on a Thursday when you realise the proposal you sent a client that morning contains a statistic the AI invented, or that someone on your team pasted a customer list into a free chatbot to "tidy it up". Every business using AI will have one of these moments. The ones that handle it well have decided in advance what they will do.
This is a practical AI incident response plan for a business with between one and a hundred people — no compliance department, no legal team on retainer, and about forty-five minutes to spare. It is deliberately short, because a plan nobody reads is the same as no plan.
What counts as an AI incident in a small business
"Incident" sounds dramatic, which is part of why small businesses never write anything down. In practice, an AI incident is any case where an AI tool produced an outcome you would not have signed off on had you seen it first. Four kinds account for almost all of them:
- Fabricated content that reached someone. An invented figure, a case law citation that does not exist, a named "source" nobody can find, a product spec that is not true. This is the most common by a wide margin.
- Data that left the building. Customer records, salary data, a signed contract or an unreleased pricing sheet pasted into a consumer AI account with training enabled. Often done by a helpful employee with no idea it was a problem.
- Automation that acted. An AI agent that emailed the wrong segment, approved an invoice, booked over a fully booked calendar, or replied to a complaint in a tone that made it worse.
- Attribution and ownership trouble. AI-generated copy that reads suspiciously like a competitor's, an image you cannot prove you can licence, or a client asking "did a human write this?" after you implied one did.
Severity matters more than category. A hallucinated statistic in an internal Slack message is a shrug. The same statistic in a tender document is a different conversation. Grade every incident as internal only, reached a client, or involves personal or confidential data. That one line decides everything that follows.
Why small businesses need a plan more than big ones do
A 4,000-person company has a security team, a legal team and an insurer who all swing into action on your behalf. You have yourself, possibly on a Friday evening. Three things make the small-business version harder:
You find out late. There is no monitoring layer. In a large organisation an AI incident is usually flagged by a system; in a small one it is flagged by a client saying "where did this number come from?" — which means the clock started hours or days ago.
Reputation is concentrated. If you have thirty clients, one of them losing confidence is three per cent of your revenue and a meaningful share of your referral network. Large firms absorb that. You do not.
Nobody knows who decides. The single most expensive part of a small-business AI incident is not the error — it is the two hours spent working out who is allowed to ring the client and say so. Decide that now, in writing, and you have already captured most of the value of this article.
It is also worth knowing that under the EU AI Act, the obligations that bite for most SMBs are about transparency and record-keeping rather than incident reporting — but "we had no idea it happened" is a weak position in any regulatory conversation, and an identical one in a client dispute.
The four-stage response: contain, assess, correct, communicate
Run these in order. The order is the point — businesses that get this wrong almost always communicate before they have assessed, then have to correct the correction.
1. Contain (first 30 minutes)
Stop the thing from getting worse. Pause the automation or the sequence. Revoke the tool's access if data is involved. Tell the person who found it not to reply to the client yet. Do not delete anything — you will need the prompt, the output and the timestamps, and deleted evidence looks far worse than the original mistake.
2. Assess (same working day)
Answer four questions in writing, in a shared document, however roughly:
- What exactly did the AI produce, and what was the prompt or trigger?
- Who saw it — internal only, one client, a mailing list of 4,000?
- Was personal or confidential data involved, and whose?
- Is anything else built on top of this output — a report, an invoice, a decision already taken?
That last one catches the expensive cases. A hallucinated figure that also went into a quarterly summary and a board update is three corrections, not one.
3. Correct (within 24 hours)
Fix the artefact itself, with a human checking the fix. Then look one step wider: if a prompt produced a bad output once, it will produce another. Pull the prompt out of whatever template or saved workflow it lives in before you close the ticket.
4. Communicate (within 24 hours of assessing)
Covered properly in the next section, because this is where most businesses lose more than the error cost them.
What to tell the client — and when
The instinct is to quietly fix it and hope. That works until it does not, and when it does not, the damage is no longer about the mistake — it is about the concealment. A reasonable rule for an SMB:
- Internal only, no data: log it, fix it, no external communication.
- Reached a client, no consequence yet: tell them, plainly, within a working day. "We spotted an error in the figures on page 4 — here is the corrected version and here is how it happened."
- Reached a client and they acted on it: phone call, same day, before the corrected document arrives.
- Personal data involved: this may be a GDPR matter with a 72-hour notification clock to your supervisory authority if there is a risk to individuals. Treat it as a data breach first and an AI issue second.
What makes these conversations go well is specificity. "Our AI tool generated an incorrect benchmark figure, our review process did not catch it, and we have changed the review step so a named person signs off on every number before it leaves" lands far better than "there was an issue with our system." Clients are remarkably forgiving of a mistake with a named fix, and remarkably unforgiving of vagueness.
And resist the urge to blame the model. "ChatGPT made it up" is both true and irrelevant; you sent it. We go into the disclosure question in more depth in our guide on preventing AI hallucinations in client work.
Build the one-page plan in 45 minutes
Open a document. Give it six headings and fill them in. That is the whole exercise.
- Who to tell. One named person, with a mobile number, who is told about every incident regardless of size. In most SMBs this is the owner. Name a deputy for holidays.
- Who decides. Who is authorised to pause a tool, and who is authorised to contact a client. These can be two different people, but they must be named people, not roles.
- The severity ladder. The three grades above — internal, client-facing, data involved — and the response time attached to each.
- Where incidents get logged. A spreadsheet with six columns is enough: date, tool, what happened, severity, action taken, prevention change.
- Your tool inventory. Every AI tool in use, who owns the account, and whether it is on a business plan with training disabled. You cannot contain what you did not know existed.
- The 24-hour review. One short meeting after any client-facing incident. Not to assign blame — to change one thing.
If you want a starting draft, a prompt like this gets you to 80 per cent in a single pass:
"You are helping a [X]-person [industry] business write a one-page AI incident response plan. Our AI tools are [list]. Our main client-facing outputs are [list]. Produce the plan with: a three-level severity scale, named-role responsibilities, response time targets for each level, a client communication template for a client-facing error, and a six-column incident log structure. Keep it under one page of A4. Plain English, no jargon."
Then edit it yourself. The names, numbers and tool list are the parts that make it real, and they are exactly the parts an AI cannot supply.
Logging incidents so they stop repeating
The log is the part everyone skips and the only part that compounds. Six months of entries tells you something no vendor comparison can: which of your tools, and which of your workflows, actually fail in your business.
Typical patterns that emerge within a quarter: one particular saved prompt generates most of the fabrications, because it asks for statistics without giving the model a source. One team member accounts for most of the data exposures, because nobody ever showed them the business account exists. One automation fails every time a customer record has an empty field. None of those are discoverable from a single incident; all three are obvious from eight logged ones.
Review the log quarterly alongside your tool spend. If a tool has produced three incidents and €40 a month of value, that is a decision, not a debate. Our piece on auditing your AI tool stack covers that review in full, and writing an AI policy for your small business covers the preventative side — the rules that reduce how often you need any of this.
Where this fits in your AI strategy
Business owners tell us, in almost these words, that every article says "use AI" and nobody says how — and the gap is sharpest here. Adoption advice is abundant; what to do when it goes wrong is almost entirely missing, which is why so many SMBs quietly stop using AI for client work after one bad experience rather than fixing the process around it.
A response plan is not a sign you expect failure. It is what lets you use AI on work that matters, because the downside is bounded and known. The businesses pulling genuine advantage out of AI in 2026 are not the ones with the best tools — they are the ones confident enough to put AI near real client work, and that confidence comes from knowing exactly what happens on the bad Thursday.
Forty-five minutes. One page. Two named people. Do it before you need it.
Where does your business stand on AI?
Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.
Take the Free Quiz →