Now Reading
5 cyber risks founders take every time they use AI tools

5 cyber risks founders take every time they use AI tools

5 cyber risks founders take every time they use AI tools

When my business insurance came up for renewal, it prompted me to look properly at my cover. My business consultancy policy covered advisory work such as digital marketing, but not AI advisory or cybersecurity, such as your accounts being hacked for sensitive data. As a founder, keeping your data secure is critical, and even more so when you hold data for clients.

The second trigger was a new contract involving more AI training. To be completely honest, if my policy had carried on for a few more months, I might have overlooked the fine print. Reading it showed me how many founders could be exposed without realising it, simply because they use AI tools every day, for themselves or for their clients. Here are five risks worth looking at.

1. Your data may be going further than you think

Every time you paste in an email, meeting notes, or a document, that information leaves your business. Some AI tools use your conversations to train their models by default and keep them for a long time. Check the privacy settings in every AI tool you use, and be clear about what should never be pasted in: client details, passwords, bank information.

2. Your AI account can become a back door

Beyond basic chat, most of us start using connectors, which link an AI tool to other tools: most commonly email, files, and your calendar. Check every connector’s settings so you know exactly what the AI can and can’t do. Allowing AI to read your emails, draft replies, and send them can be quite risky. You’re relying not just on the AI tool but on third-party connections into other applications. In effect, you’re creating back doors into your working system, and your email, files, and calendar may hold sensitive data.

3. Scams are getting smarter

As AI is built into more systems, scams are becoming more frequent. Many emails now ask you to click through to somewhere else. Hover over the link first and you’ll see the real address; it’s usually obvious when it’s phishing. If you’re unsure, paste the email into an AI tool, with any personal details removed, and it will often spot the scam quickly.

The bigger picture includes AI voice scam calls, fake images, and videos. My best advice is to be vigilant and trust your gut: in my experience, if something feels fishy, it probably is. Pause before you say yes or click that button, and never give personal, bank, or card details unless you’re 100% sure who you’re talking to.

4. Confident answers aren’t always right

AI tools, in particular large language models, give very confident answers, even when they’re wrong. If you know your field, you’ll spot it immediately. But if you’re writing about something you don’t know well, the output can look intelligent and sound, and still be incorrect or give bad advice. Sense-check everything, check the references, and do your own research. If it feels odd, it probably is.

See Also
AI agents in 2026: predictions and 2025 takeaways

5. Your insurance may say nothing about AI

Be cautious with generic click-and-buy policies that might list you as an ‘AI consultant’ or similar. I spoke to several insurers and explained exactly what I do: advisory, consulting and training, online and in person. I went through my day-to-day tasks to make sure every business activity was listed on my policy. In the UK, AI consultancy generally comes under IT consultancy, and cyber cover is usually not included as standard.

Speak to an insurer on the phone if you can. You’ll have a record that you told them exactly what you do, in case a claim is ever made against you, for example for advice about an AI tool that caused a client a problem. We can’t control what AI tools do, or what the companies behind them change. So we need to cover ourselves, as much as we can, for the advice we give, the work we do and the training we deliver.

Three things you can do yourself, even as a solo founder

  1. Transparency – write and share an AI policy. It’s a simple way to start looking at how you use AI in your business and with your clients, and to let them know
  2. Governance – set your rules. Decide what you will and won’t use AI for, and what you will and won’t allow it to do. The key mantra is to always keep a human in the loop: any output goes through a human first, and you read and check everything before it goes out
  3. Privacy – don’t allow training on your data. Most AI tools have a toggle you can switch off

Then, when it comes to insurance, pick up the phone and have a conversation. Together, these build a strong foundation to reduce the risks of using AI tools.

Startups Magazine. All rights reserved. c 2026. Company number is: 06755141

Scroll To Top