AI Without Guardrails: What Malaysian SMEs Must Prepare For

AI Without Guardrails: What Malaysian SMEs Must Prepare For — featured image

by

When AI Stops Saying “No”, Your Business Needs Better Controls

You may already use AI to draft emails, summarise documents, answer customer questions or help staff write code. The attraction is clear: AI can handle routine work quickly, while your team focuses on customers and operations.

But a new development deserves your attention. Some companies are now offering access to open-weight AI models with their built-in safety refusals removed. This is known as abliteration. The service reported by TechCrunch allows users to query modified models through a browser or API, including for security testing and other activities that standard models may refuse. Source: TechCrunch

You do not need to use such a model for it to affect your business. Your employees, vendors, developers or attackers may encounter these systems. The practical question is not whether you should panic. It is whether your business is prepared for AI that can produce more harmful, deceptive or risky output with fewer built-in obstacles.

TL;DR

AI guardrails are useful, but they are not a complete security plan. Malaysian SMEs should control what data enters AI tools, verify AI-generated work and monitor how staff use APIs and browser-based services.

For legitimate security testing, use authorised professionals, written rules and isolated systems. Do not let “testing” become an excuse for unsafe experiments on live business assets.

What This Means

Most commercial AI tools include safeguards designed to refuse certain requests. These may cover malware, credential theft, violent instructions, dangerous biological activity or requests involving personal data. Guardrails can be implemented through model training, moderation filters, access controls and monitoring.

Open-weight models are different from ordinary chat services. Their model files can be downloaded, adapted and run by organisations or individuals. Researchers have long experimented with removing refusal behaviour from these models. TechCrunch reported that Abliteration.ai has packaged this practice as a hosted service, providing modified models through a web interface and API. Source: TechCrunch

The intended argument is that defenders need to reproduce harmful behaviour before they can protect against it. A cybersecurity team may want to test whether an AI agent can be tricked into writing exploit code or exposing sensitive information. However, removing refusals also lowers the barrier for people with malicious intentions.

This creates a difficult balance. The same capability may help a professional red team identify weaknesses, while making abuse easier for someone without permission. The article quotes experts who disagree about how useful abliterated models are in everyday security work. Some prefer fine-tuning open models, while others see value in using models that can produce behaviour ordinary systems reject. Source: TechCrunch

Guardrails can reduce risk, but responsibility cannot be outsourced to the AI model. Your access rules, staff training, approval process and monitoring still matter.

How This Applies to Malaysian SMEs

1. Your customer-service workflow can become a data leak. Suppose your team copies a customer complaint into an AI tool to create a reply. The complaint may contain a phone number, address, order details or identification information. If staff use an unapproved model, you may lose control over where that information goes. A model without strong safeguards may also be more willing to reproduce private details or generate convincing fraudulent messages.

Create a simple rule: staff may use approved AI tools for approved information only. Remove personal identifiers before sharing text. For example, replace a customer’s name with “Customer A” and remove order numbers unless they are essential. Keep a short list of tasks that require human approval, such as refunds, account changes and messages involving legal complaints.

2. Your software or automation vendor may introduce hidden risk. Many SMEs use third-party tools for websites, accounting workflows, recruitment, marketing and customer support. Ask vendors whether their product uses an external AI API, an open-weight model or a model hosted on their own infrastructure. You should also ask what happens to prompts, uploaded files and generated output.

You do not need a highly technical contract to start. Request clear answers about data retention, access logging, deletion, human review and incident notification. If a vendor allows customers to connect any AI model through an API, ask whether it can restrict unapproved providers and record who made each request.

3. Your business can be targeted by more convincing scams. AI without refusals can assist with harmful content, but even ordinary AI tools can already produce polished phishing messages. A fake supplier email may imitate your usual writing style. A fraudulent message may refer to a real project, employee or customer. If attackers use less restricted models, the quality and volume of such attempts may increase.

Protect yourself with process controls rather than relying on staff instinct. Require independent confirmation for bank-account changes, unusual payment requests and urgent requests for passwords or one-time codes. Verification should use a known phone number or an established communication channel, not the contact details provided in the suspicious message.

4. Security testing must be authorised and isolated. If you hire a cybersecurity consultant to test your website, chatbot or internal AI assistant, insist on a written scope. It should identify the systems being tested, permitted techniques, testing dates, emergency contacts and how evidence will be handled. Never allow experiments against a live customer database unless the risks and approvals are clearly documented.

A small company does not need to operate its own uncensored model to conduct a useful review. A qualified security provider can test prompt injection, unauthorised data access, harmful output and excessive permissions using controlled methods. The important point is that the tester must have permission and must protect any information discovered during the exercise.

Practical Takeaways

  • Set an approved-tools list: name the AI applications staff may use and block or discourage unknown browser tools for business data.
  • Classify information: mark data as public, internal, confidential or highly restricted before employees place it into an AI system.
  • Remove identifiers: redact names, phone numbers, identity numbers, passwords, API keys and account details from prompts.
  • Use least privilege: connect AI assistants only to the files, systems and actions they genuinely need.
  • Keep human approval: require a person to review financial, legal, employment, medical or customer-impacting decisions.
  • Verify sensitive requests: confirm payment changes, password resets and access requests through a separate trusted channel.
  • Review vendors: ask where prompts and files are processed, how long logs remain and who can access them.
  • Record incidents: create a basic reporting route for accidental data uploads, suspicious AI output or unusual tool usage.
  • Test safely: use a separate test environment and written authorisation for red-team or penetration-testing work.
  • Train regularly: show staff realistic examples of prompt injection, phishing and fabricated AI answers.

A Simple AI Risk Checklist

Area Question for your business Action
Access Can every employee use any AI website or API? Approve tools and review access by role.
Data Can staff paste customer or company secrets into prompts? Apply a no-sensitive-data rule unless specifically approved.
Output Can AI send messages or change records without review? Require human approval for high-impact actions.
Vendors Do suppliers explain model use and data retention? Request written answers and update contracts where appropriate.
Testing Is security testing limited to authorised systems? Define scope, contacts, evidence handling and shutdown procedures.

These controls are practical for a small team because they focus on decisions and habits. You do not need to understand every model architecture. You do need to know which tools your staff use, what information they submit and which actions AI can trigger.

The Bigger Picture

The spread of modified open-weight models means AI safety will increasingly depend on the environment around a model. A provider may add careful refusals, but another party can alter or host a version with different behaviour. TechCrunch reported that governments and experts are considering controls such as harmful-activity classifiers, identity verification for access to advanced computing resources and restrictions where misuse is suspected. Source: TechCrunch

For Malaysian SMEs, this points to a broader shift in responsibility. You cannot assume that a familiar chatbot is the only AI your staff, customers or suppliers will encounter. You also cannot assume that an AI-generated answer is safe merely because it sounds professional.

Over time, the strongest businesses will treat AI access like other business technology: approved applications, clear permissions, documented procedures and regular review. This approach supports useful experimentation without allowing every employee or vendor to connect unrestricted AI to customer records, internal documents or operational systems.

Start with one meeting this week. List the AI tools your team currently uses, the information they handle and the actions they can perform. Then close the most obvious gaps first. When AI tools become less predictable, disciplined business processes give you the control that model guardrails alone cannot provide.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →