Treadstone Associates
Ask an Expert · 4 min read

Should a small business worry about AI security?

Headcount is an easy number to reach for. It's the wrong one for sizing up this particular risk.

Treadstone Associates · Updated 2026

Short answer

Yes — but the reason isn't size, it's what the business actually does. Canadian privacy law measures required safeguards against the sensitivity of the information a business holds, not against its headcount, and a five-person firm handling banking details, medical records or legal files carries more real exposure than a much larger business using AI only for public-facing marketing copy.

The legal standard doesn't mention size

PIPEDA’s safeguards principle ties the required level of protection to “the sensitivity of the information that has been collected, the amount, distribution, and format of the information, and the method of storage” (PIPEDA, Schedule 1, clause 4.7.2) — none of which is headcount. A small accounting practice or law office handling detailed financial or legal files for a modest number of clients is protecting information at least as sensitive as a much larger retailer processing routine purchase records at scale.

What actually attacks an AI system doesn't check payroll either

The three specific attacks on an AI system itself — data poisoning, adversarial examples, and model inversion or membership-inference queries, covered in full at can an AI system be hacked — target whatever data and model a business is running, not a specific company size. A small business using a shared vendor platform is exposed to exactly the same three mechanisms as a large one using the same platform; what changes the stakes is what that platform holds, not who’s paying for it.

Insurance underwriters already price it this way

The market for cyber liability coverage already prices risk on data, not headcount. A Treadstone Law answer on whether an Ontario business needs cyber liability insurance puts it directly: “Whether you specifically need this coverage depends on the volume and sensitivity of the customer data you hold and how it is secured” (Treadstone Law, on cyber liability insurance generally) — a general insurance principle, not one written for AI specifically, but the same logic applies to deciding how much AI-security effort a small business actually needs.

The practical takeaway

Instead of asking “am I big enough to be a target,” a small business is better served asking what the AI tool actually touches: client financial data, health information, legal files and similar categories justify real safeguards regardless of company size, while a tool used only for internal drafting or public content carries meaningfully less exposure — even at a much larger company.

Where this goes next

Matching the level of AI security effort to what the data actually is — rather than to company size — is an operations decision worth making deliberately, not by default.