AI Security Is Now a Business Responsibility
You may already use AI to draft messages, summarise documents, answer customer questions, or organise internal work. That convenience is useful, but it also creates a new question: what happens when criminals use AI to attack your business faster and more convincingly?
A recent open letter signed by more than 100 technology companies, including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta and Fortinet, called for stronger cooperation between companies and governments to defend against AI-related cyber threats. TechCrunch reported the companies’ warning.
You do not need to operate a large technology company to be affected. If your SME depends on email, online banking, cloud software, customer databases, payment platforms, or messaging apps, you have systems that attackers may try to exploit.
TL;DR
AI can help attackers create more convincing scams, automate reconnaissance, and move quickly after finding a weakness. You can reduce your exposure by tightening access controls, verifying unusual requests, training staff, and documenting how AI tools are used.
Do not treat cybersecurity as only an IT concern. For a small business, it is also an operations, finance, customer trust, and business continuity concern.
What This Means
The open letter is based on a straightforward concern: as AI systems become more capable, cyber attacks may become more frequent, automated, and difficult to recognise. The letter specifically calls for cooperation between the private sector and governments at local, national, and international levels. The source article quotes the letter’s warning about AI-enabled cyber attacks.
In plain language, an attacker can use AI to do tasks that previously required more time and effort. These tasks may include writing believable phishing messages, translating scams into natural Malay or English, studying public information about your company, generating fake documents, or creating many variations of an attack.
AI may also be connected to business systems through assistants, automation platforms, browser tools, or application programming interfaces. If these tools receive too much access, a mistake or malicious instruction could affect files, customer records, calendars, email accounts, or other connected services.
The risk is not limited to so-called “rogue AI” acting independently. A more common concern for SMEs is a normal business workflow being manipulated. For example, an employee may receive a convincing message that appears to come from a director, supplier, or customer. The message may request a change to bank details, an urgent transfer, a document upload, or access to a shared folder.
Key insight: AI does not replace the need for basic cybersecurity discipline. It makes that discipline more important because attackers can scale convincing deception more easily.
How This Applies to Malaysian SMEs
1. Your finance process needs a human verification step. Malaysian SMEs commonly communicate with suppliers, customers, accountants, logistics partners, and banks through email and messaging platforms. An AI-assisted scam may imitate a familiar writing style or create a realistic invoice. If someone asks to change a supplier’s bank account or approve an unusual payment, verify the request using a separate channel, such as a known telephone number or an in-person confirmation. Never rely only on the reply address or message thread.
2. Your staff may use AI tools without a clear internal rule. Employees may paste customer enquiries, sales records, contracts, employee information, or internal procedures into public AI services to get faster assistance. That can create confidentiality and compliance concerns, especially when the information includes personal data. Malaysia’s Personal Data Protection Department publishes guidance and information related to personal data protection obligations, which you should review when deciding what information can be entered into external tools. Refer to Malaysia’s Personal Data Protection Department for official guidance.
3. Your cloud accounts are likely to be more important than your office network. Many SMEs rely on Microsoft 365, Google Workspace, accounting platforms, CRM systems, e-commerce dashboards, and cloud storage. If an attacker takes over one administrator account, they may access email, reset passwords, download files, or impersonate staff. Turn on multi-factor authentication for email, cloud storage, finance systems, and administrator accounts. The Malaysian Cyber Security Awareness campaign also provides practical public guidance on safer online behaviour. See CyberSecurity Malaysia resources for cybersecurity awareness information.
4. AI-generated messages may be harder for busy staff to judge. Traditional scam messages often contain obvious spelling mistakes or unusual wording. AI can produce polished messages in English, Bahasa Malaysia, Mandarin, or other languages. Train your team to focus less on grammar and more on behaviour: urgency, secrecy, unusual requests, unexpected attachments, login links, and changes to established procedures.
5. Your customer service automation needs boundaries. If you use an AI chatbot or automated assistant, define what it may and may not do. It should not approve refunds above a set limit, expose customer records, change delivery details without verification, or provide internal information simply because someone asks confidently. Keep sensitive actions behind a human approval step.
A Simple Risk View for Your Business
| Business area | Possible AI-assisted threat | Practical control |
|---|---|---|
| Email and messaging | Impersonation of a director or supplier | Verify unusual requests through a separate channel |
| Finance | Fake invoices or changed bank details | Use two-person approval and a supplier callback |
| Cloud systems | Account takeover and data theft | Enable multi-factor authentication and review access |
| AI tools | Confidential information being uploaded | Create a written list of approved and prohibited data |
| Customer service | Automated disclosure or unauthorised action | Limit permissions and require human approval |
Practical Takeaways
- List every important online account your business uses, including email, cloud storage, accounting, payroll, e-commerce, and social media.
- Turn on multi-factor authentication, beginning with administrator, finance, and email accounts.
- Remove access promptly when an employee leaves or changes responsibilities.
- Create a rule that bank-detail changes must be verified using a known contact method.
- Teach employees to report suspicious messages without fear of blame.
- Do not place customer identity information, passwords, confidential contracts, or internal financial records into unapproved AI tools.
- Limit AI assistants to the minimum information and system access they need.
- Keep offline or separately protected backups of essential business records and test whether you can restore them.
- Review your incident response contacts, including your technology provider, bank, insurer if applicable, and relevant authorities.
- Run a short phishing and impersonation exercise with your team at least once a year.
A 30-Day Action Plan
Week 1: Identify your most important systems and who can access them. Mark accounts that can approve payments, reset passwords, export customer records, or manage company-wide settings.
Week 2: Enable multi-factor authentication, remove unused accounts, update recovery details, and check whether old employees or former vendors still have access.
Week 3: Write a one-page AI usage policy. State which tools are approved, what information cannot be uploaded, and when a human must review an AI-generated answer or action.
Week 4: Test your people and processes. Send a simulated unusual request, review how staff respond, and improve the verification steps if anyone approves it too quickly.
The Bigger Picture
The technology companies’ open letter points towards a longer-term change: cybersecurity will increasingly require cooperation between software providers, security firms, financial institutions, infrastructure operators, and governments. The letter called for new partnerships and stronger security standards.
For you as an SME owner, this does not mean waiting for a new product or government programme. It means treating security controls as part of how your business operates. Your supplier onboarding process, staff training, payment approvals, customer data handling, and software purchasing decisions all contribute to your cyber defence.
AI can still be useful for administrative work, marketing drafts, research, and customer support. The sensible approach is not to reject it, but to introduce clear boundaries. Give tools limited access, keep sensitive decisions under human control, and make verification normal for high-impact requests.
The businesses that cope best with AI-related threats will not necessarily be those with the biggest technical teams. They will be the ones that know which systems matter, control who can access them, and teach employees to pause when a request feels urgent or unusual.
Ready to Streamline Your Operations?
Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →
