The AI gold rush has a security problem

Every week, a new AI tool promises to answer your phones, schedule your appointments, or draft your client communications. Some of them are genuinely good. But here’s what most AI vendors won’t tell you: when their tool mishandles your data, you’re the one holding the liability.

Not them. You.

A data breach costs a small business between $120,000 and $200,000 on average. That’s not a Fortune 500 number - that’s the bill for a 15-person dental office or a plumbing company with four trucks. It includes legal fees, notification costs, regulatory fines, and the revenue you lose when customers find out.

This isn’t about being afraid of AI. It’s about being smart about which AI you let into your business.

What’s at stake in your industry

Dental practices: HIPAA isn’t optional

Every AI tool that touches patient data - scheduling, insurance verification, call handling, treatment planning - falls under HIPAA. That means Business Associate Agreements, encrypted data storage, access controls, and audit trails.

The cautionary tale is already here. Heartland Dental faced legal action over AI-powered call recording that didn’t properly notify patients. The AI worked great. The compliance didn’t. And the practice paid for it.

Questions your AI vendor should be able to answer:

  • Where is patient data stored, and is it encrypted at rest and in transit?
  • Do they sign a Business Associate Agreement?
  • Can they produce audit logs showing who accessed what data and when?
  • What happens to patient data if you cancel the service?

If your vendor hesitates on any of these, that’s your answer.

HVAC, plumbing, and electrical: “We’re not regulated” is a myth

You may not have HIPAA, but you absolutely have obligations. AI tools for field service businesses routinely collect customer names, addresses, phone numbers, payment information, and access codes to homes and businesses. That’s a target-rich dataset.

Most states now have data breach notification laws. Several - including California, Colorado, Virginia, and Connecticut - have comprehensive data privacy statutes. If your AI scheduling tool gets compromised and leaks 3,000 customer home addresses alongside their “the spare key is under the mat” service notes, you’re facing notification costs, potential lawsuits, and reputation damage that a Yelp recovery campaign can’t fix.

What to check:

  • Does the AI vendor have SOC 2 Type II certification (or equivalent)?
  • Where is customer data processed - US data centers or overseas?
  • Who owns the data your AI tool collects?
  • Is payment information isolated from other customer data?

Several state bars have already issued formal opinions on AI use in legal practice. The ABA has active proposals on AI ethics requirements. The direction is clear: attorneys have a duty of competence that extends to understanding the AI tools they use.

The risk here isn’t just data breach - it’s malpractice. If an AI drafting tool hallucinates a citation (and they do), or an AI communication tool discloses privileged information through a shared data pipeline, the attorney is responsible. Not the vendor.

Critical questions for legal AI tools:

  • Does the tool train on your client data? (Many do, buried in the terms of service.)
  • Is client-attorney privilege maintained in the data architecture, not just the marketing copy?
  • Can you get a complete data deletion when a matter closes?
  • Has the vendor had an independent security audit in the last 12 months?

The EU AI Act: coming whether you’re ready or not

If you serve any EU-based customers - or use AI tools from EU-based vendors - the EU AI Act becomes fully applicable on August 2, 2026. That’s less than five months away. It introduces transparency requirements, risk classifications, and documentation obligations that most US small businesses haven’t even heard of yet.

This isn’t a future problem. It’s a now problem with a deadline.

Why your AI vendor’s security page isn’t enough

Most AI vendors targeting small service businesses are startups. Their security practices often amount to a reassuring paragraph on their website and a checkbox that says “256-bit encryption.” That tells you almost nothing.

Here’s what actually matters:

  • Independent security audits - not self-assessments
  • Data processing agreements that specify exactly what happens with your information
  • Incident response plans - what do they do when (not if) something goes wrong?
  • Data residency clarity - where your data physically lives and which jurisdictions govern it
  • Subprocessor transparency - who else touches your data downstream?

Your AI compliance checklist

Before you sign with any AI vendor, run through this list:

  • BAA or DPA signed - Business Associate Agreement (healthcare) or Data Processing Agreement (everyone else), executed before any data flows
  • Data ownership confirmed in writing - you own your data, full stop
  • Encryption verified - at rest AND in transit, with specific standards named (AES-256, TLS 1.2+)
  • Audit logs available - you can see who accessed what and when
  • Data deletion policy documented - what happens when you leave, with a timeline
  • Subprocessors disclosed - every third party that touches your data is listed
  • Security audit completed - independent, within the last 12 months
  • Breach notification terms defined - how fast will they tell you, and what’s included
  • AI training opt-out confirmed - your data is not used to train their models without explicit consent
  • Insurance verified - the vendor carries cyber liability coverage

If a vendor can’t check every box, that doesn’t automatically disqualify them - but you need to understand exactly which risks you’re accepting.

Why this matters to us at Solas AI

I built Solas AI because I saw the gap firsthand. I’m a CISSP and CISM certified Information System Security Manager working in the Department of Defense. I spend my days evaluating security architectures and compliance frameworks for systems where the stakes are as high as they get.

That background is rare in the AI consulting space. Most AI agencies are built by developers or marketers. They can build automations, but they can’t tell you whether those automations will survive a compliance audit or protect you in a breach.

We can. Every AI system we design for clients - dental, HVAC, plumbing, electrical, legal - is built with security and compliance as a structural requirement, not an afterthought.

Get a free AI compliance audit

Not sure where your current AI tools stand? We offer a free 30-minute AI compliance and readiness audit. We’ll review your existing tools, flag specific risks for your industry, and deliver a written report with concrete next steps.

No sales pitch. No pressure. Just a clear-eyed look at where you stand.

Reply “audit” to [email protected] or call (307) 357-1525 to schedule yours.