Small-business owners tend to hear two stories about artificial intelligence. In one, AI runs the company while everyone else watches. In the other, it is a toy with no place in serious work. Neither story helps you decide what to do on Monday.
A smaller starting point works better: give AI one defined job that prepares work for a person to finish.
This guide covers five of those jobs. Each comes with an example from a small service business, what to check before anything goes out, and what to keep out of the prompt.
The U.S. Small Business Administration gives similar advice. Start small, have a person review what AI produces, and try not to feed it sensitive or proprietary information. You do not need an “AI strategy” for that. You need one repeatable task and an honest look at whether it helped.
The short answer
Use AI first on work that is:
- Repetitive enough to be annoying
- Low-risk, so a mistake gets caught before it reaches a customer
- Easy for someone who knows the business to check
- Built from information you are allowed to share with the tool
- Measurable, so you can tell whether it saved time
A useful rule: AI can propose, organize, and question. A person approves anything that speaks for the business, affects a customer, moves money, changes access, or carries legal consequences.
What “a person approves” means
“Keep a human in the loop” is easy to say and easy to skip. Make it a routine with four parts.
- One named person. The reviewer is whoever would answer for the result if it turned out to be wrong. In most small businesses that is the owner or the person who did the job.
- Check against the source. Put the draft beside your notes, not beside your memory. Compare every number, name, date, price, and promise.
- Look for what was added. AI tools fill gaps with detail that sounds right. Anything in the draft that is not in your notes gets confirmed or deleted.
- Send it yourself. The tool writes into a document. A person moves the words into the email, the estimate, or the website and sends from their own account.
The fourth step is the one that keeps control. If nothing reaches a customer unless a person puts it there, a bad draft costs you a few minutes instead of a client.
The companies that make these tools say the same about their own products. OpenAI’s help center says ChatGPT can sound confident when it is wrong and can produce made-up quotes and citations. Microsoft says Copilot’s responses are not guaranteed to be factual and tells users to review them before sending them to anyone else.
Before you paste anything, check the account
Whether an AI company may use what you type to train its models depends on the kind of account you have, not only on the brand. Here is what each company’s own pages said at the time of writing, in October 2026. These policies change often, so read the current page before you rely on any of this.
- ChatGPT. Personal plans have a setting called “Improve the model for everyone” under Settings, then Data controls. With it off, OpenAI says new conversations are not used for training. OpenAI says it does not train on ChatGPT Business, Enterprise, or Edu workspaces by default.
- Claude. Anthropic says it uses chats on its consumer plans (Free, Pro, and Max) for training if you choose to allow it, with an exception for conversations flagged for safety review. It says it does not train on its commercial products, such as Claude for Work, by default.
- Gemini. In the consumer Gemini app, Google says that when the Keep Activity setting is on, chats can be used to train its models and some are read by human reviewers. Google asks users not to enter confidential information there. For Google Workspace business accounts, Google says customer data is not used to train models without the customer’s permission.
- Copilot. Microsoft says it uses consumer Copilot conversations for AI training unless you opt out, and that it does not train on people signed in with an organizational (work) account.
Three things follow from that list.
A business plan is usually the safer place for business information. A personal account can be made safer by changing a setting, but every employee has to change it on their own account.
Feedback buttons can undo your setting. OpenAI and Anthropic both say that when you rate a response with a thumbs up or thumbs down, the whole conversation may be used for training. Tell staff not to rate conversations that contain business details.
“Not used for training” does not mean “not stored.” OpenAI says temporary chats may be kept for up to 30 days. Google says chats are kept for 72 hours even with Keep Activity off, and that chats read by reviewers can be kept for up to three years.
So some things stay out of the prompt whatever plan you are on:
- Passwords, login codes, and security answers
- Card numbers and bank details
- Social Security numbers and ID documents
- Employee records
- Anything a client gave you in confidence or under a contract
- Health information about a patient or client
On the last item: if your practice is covered by HIPAA, HHS guidance says a cloud service that handles electronic protected health information on your behalf is a business associate, and you need a business associate agreement (BAA) with it. A paid plan is not a BAA. OpenAI, for example, says it does not offer one for ChatGPT Business at the time of writing. Talk to your compliance advisor before any patient detail goes into an AI tool. Nothing in this article is legal advice.
In 2024, Federal Trade Commission staff told AI companies to keep their privacy and confidentiality promises, and noted that business customers may hand these services sensitive material such as internal documents. Holding vendors to their word is the FTC’s job. Deciding what your staff may paste is yours. Write the list down before people start using the tools.
1. Turn rough notes into a first draft
Example. A plumber finishes a site visit with four lines of notes on his phone: the water heater is 14 years old, the replacement is $2,150 installed, the permit is included, and he can start Thursday. He pastes the notes with this request:
Turn these notes into a short, friendly follow-up email to a homeowner. Keep every price and date exactly as written. Do not add guarantees, discounts, or services I did not mention. After the draft, list anything that is missing.
Editing a draft is often faster than starting from an empty screen. To keep it sounding like you, paste in two emails you have already sent and liked, and ask the tool to match them.
Check before sending. The price, the start date, what is included, and the customer’s name. Delete any sentence that promises something your notes did not, such as a guarantee or a deadline. Read it aloud once. If it does not sound like you, change it.
Keep out of the prompt. The customer’s full name, address, and phone number. The tool does not need them. Write “the homeowner” and add the name when you send. Gate codes, alarm codes, and card details never go in.
Not worth it for a two-line reply. Typing it is faster than explaining it.
2. Summarize a long thread and find the next step
Example. The owner of a landscaping company comes back from a week away to a 40-message email thread between her office manager, a client, and a paver supplier about a delayed patio. She asks the tool to separate:
- Decisions already made
- Open questions
- Who owes what to whom, and by when
- Statements that need to be verified
Check before acting. Read the original message behind every date and commitment in the summary. Summaries drop conditions (“if the pavers arrive by Friday”) and can mix up who said what. Before you order materials or promise the client a date, find the line in the thread.
Keep out of the prompt. Threads that include payment details, a client’s health, finances, or family circumstances, or anything about an employee. Leave out attachments covered by a confidentiality agreement.
One related caution. AI note-takers that record and transcribe calls are convenient, and the rules on recording conversations differ from state to state. Tell everyone on the call, get their agreement, and ask your attorney if you are unsure what your state requires.
3. Repurpose material you have already approved
Example. A house-cleaning company has a page about move-out cleans that the owner wrote and checked. She asks the tool to turn it into a short email to past customers, three social posts, and five questions and answers for the person who picks up the phone. She tells it which lines must stay word for word: the starting price, what is included, and the re-clean policy.
Check before publishing. Make sure the qualifiers survived. “From $280” should not have become “$280,” and “most homes” should not have become “all homes.” Confirm that prices and dates are current, that the link or phone number is right, and that no new claim appeared. If the page never said “eco-friendly” or “licensed and insured,” the email should not either.
Keep out of the prompt. Customer names, photos, and reviews you do not have permission to reuse. Do not ask AI to write reviews or testimonials. An FTC rule announced in August 2024 prohibits fake reviews and testimonials, including AI-generated ones, and the agency said later that year that existing law has no exemption for AI.
Not worth it for “a month of posts” from one sentence. Nobody reviews thirty posts carefully, and unreviewed volume is how a wrong claim ends up under your name.
This job has a side benefit. If the tool cannot turn your page into a clear email without guessing, the page is probably leaving visitors guessing too. That is one common reason a site gets traffic but no inquiries. Fix the source and every later version improves.
4. Prepare checklists and templates
Example. At a small bookkeeping firm, the senior bookkeeper onboards every new client from memory. She spends ten minutes dictating how she does it, exceptions included. Then she asks the tool to organize the steps in order, flag anything ambiguous, and list the assumptions it made.
Check before adopting. The person who does the work runs the checklist against the next real client and marks missing steps, wrong order, and exceptions it does not handle. Only after it survives a real job does the owner sign off on it, with a date and a name on it.
Keep out of the prompt. Real client files. Describe the process, not the client. Leave out the logins for bank and accounting software, even if they are part of how the job gets done.
Do not automate a broken process. If nobody can say who owns a task or what “done” means, a checklist will not fix it and more software will make the confusion move faster. Settle the process first.
5. Ask AI to review the work, not make the decision
Example. An electrician is about to send a proposal for a panel upgrade. He removes the customer’s details and pastes the proposal along with his own required-items list: scope, exclusions, permit, payment schedule, warranty wording, and expiration date. Then he asks:
Compare this proposal with the required-items list. Rewrite nothing. List what is missing, and any place a first-time customer could misunderstand the price or the scope.
“Rewrite nothing” is a useful instruction. The tool points at the uncertain parts and the person who is accountable decides what to do about them.
Check before relying on it. Treat each item as a question, not a finding. A clean report does not mean the proposal is right. The tool cannot know whether your price is correct, what the local code requires, or whether the panel is specified properly.
Keep out of the prompt. Contracts covered by confidentiality terms, and anything your attorney or accountant should be reading instead. An AI review does not replace legal, financial, medical, or safety review.
Some tools can search the web and show links to their sources. That helps, and it is still not proof. OpenAI’s own help page says search results and citations can be incomplete, outdated, or incorrect. Open the link and read it before you repeat the fact.
The NIST AI Risk Management Framework, a voluntary guide from the federal standards agency, lists reliability, accountability, and privacy among the characteristics of trustworthy AI. For a small business, that comes down to three decisions: who checks the work, what they check, and who answers for the result.
Where AI is not worth it
Some work is faster or safer without it.
- Messages you can write in two minutes. Just write them.
- Facts the tool cannot know. Your prices, your schedule, your service area, local permit rules. If you did not supply it, the tool guessed.
- An apology or a hard conversation. An upset or grieving customer should hear from you in your own words.
- Decisions about a person. Hiring, firing, discipline, credit, or eligibility.
- Legal, tax, medical, and safety questions. Ask the professional.
- Money and access. Payments, refunds, bank details, password resets, and account permissions.
- Anything where checking takes longer than doing.
AI may still help you organize your thoughts before some of these. The action and the judgment stay with a person.
Run one small experiment
Choose one recurring task that takes 20 to 60 minutes and involves nothing on the keep-out list.
For the next three times that task comes up:
- Save the source material you normally use.
- Give the tool a structured request: the source to use, the job, what must not change, and what to flag for review.
- Review the result against the source.
- Write down the time spent, the edits required, and any factual mistakes.
- Decide whether to keep, revise, or stop.
A fast first draft is not a success if reviewing and repairing it takes longer than doing the work the usual way. Measure the whole task, from blank page to approved and sent.
If the experiment works, write down the prompt, the source material, the review steps, and the name of the reviewer. That turns one person’s trick into a process the business can repeat.
The goal is useful help, not maximum automation
You do not need to automate everything to benefit from AI. You need the few jobs where a quick draft, a clean summary, or a second set of questions helps a capable person get more done.
That is how Superhero Technologies uses it. AI does the production work, and a person reviews the preview and approves it before anything goes live. You can see the steps in how it works, and our website pricing guide explains what that does to the cost of a professional site.
The tools will change. Knowing your business well enough to supply the facts, spot a weak answer, and make the final call will not.
Start with one job and measure the whole task. If you want to talk through where AI fits in your own website work, talk to a human.
Sources and further reading
Vendor policy pages were read on October 1, 2026. They change often.
- U.S. Small Business Administration: AI for small businesses
- OpenAI Help Center: Data controls in ChatGPT
- OpenAI Help Center: Does ChatGPT tell the truth?
- OpenAI Help Center: Searching the web with ChatGPT
- OpenAI Help Center: How can I get a Business Associate Agreement (BAA) with OpenAI?
- Anthropic Privacy Center: Is my data used for model training? (consumer plans)
- Anthropic Privacy Center: Is my data used for model training? (commercial products)
- Google: Gemini Apps Privacy Hub
- Google: Generative AI in Google Workspace Privacy Hub
- Microsoft: Privacy FAQ for Microsoft Copilot
- Microsoft Learn: Data, privacy, and security for Microsoft Copilot
- HHS: Guidance on HIPAA and cloud computing
- FTC: AI companies: Uphold your privacy and confidentiality commitments (January 2024)
- FTC: Final rule banning fake reviews and testimonials (August 2024)
- FTC: Crackdown on deceptive AI claims and schemes (September 2024)
- NIST: AI Risk Management Framework
- NIST: AI RMF, characteristics of trustworthy AI