Skip to content
The AI-First Web

40% of SMBs Have No AI Usage Policy, ESET Finds

ESET's survey of 4,400 SMB leaders found 40% have no AI usage policy, as agent adoption rises separately.

K
Kannan SP
· 5 min read
Share on X LinkedIn
40% of SMBs Have No AI Usage Policy, ESET Finds
Key finding

SMBs with no AI usage policy: 40% (Source: ESET global survey of 4,400 SMB decision-makers (2026))

Governance is lagging adoption

Small and mid-size businesses have moved past AI chatbots and started handing work to AI agents, with some running multi-agent 'assembly lines' where a supervisor agent manages a swarm of specialist agents, according to ESET. Separately, a global survey of 4,400 SMB decision-makers found that 40% had no AI usage policy in place — a broad measure of AI governance generally, not a count limited to businesses confirmed to be running agents. ESET's researchers note that formal AI rules were more common at companies that had already suffered an incident — governance arriving after a breach rather than before one.

40%
SMBs with no AI usage policy
Source: ESET global survey of 4,400 SMB decision-makers (2026)

A skills marketplace with no gatekeeping

Agents extend their reach through 'skills' — packaged instructions telling an agent what actions to take and which tools to use. Between March and May 2026, ESET scanned close to 900,000 unique skills pulled from popular repositories. More than 25,000 were flagged as suspicious, and over 3,000 were classified outright malicious, tied to credential theft, data exfiltration and remote code execution. ESET points out that a one-time check at install time isn't sufficient, since a skill's upstream instructions or services can change afterward — the 'rug pull' scenario where a tool that behaved normally later turns into an infostealer.

3,000+
Malicious skills identified in ESET's scan
Source: ESET, skill repository scan, March–May 2026

Familiar attacks, faster execution

AI-specific risks haven't displaced the established paths into company systems. ESET's SMB Cyber Readiness Index 2026 lists phishing and exploitation of known software vulnerabilities as the two leading causes of breaches. Microsoft reports that AI-automated phishing emails achieve a 54% click-through rate, compared with 12% for standard phishing attempts. ESET separately notes that AI makes tailored lures cheap to produce at scale, one factor it cites in why many phishing campaigns are now built to withstand the scrutiny employees have learned to apply. Separately, ESET found that nearly a quarter of the roughly 500 known exploited vulnerabilities recorded in the first half of 2026 were exploited on or before the day they were publicly disclosed, leaving little room for defenders to patch ahead of attackers.

54% vs. 12%
Click-through rate, AI-automated phishing vs. standard phishing
Source: Microsoft, cited by ESET (2026)
~25% of ~500
Known exploited vulnerabilities (H1 2026) exploited on or before disclosure
Source: ESET SMB Cyber Readiness Index 2026

The 'lethal trifecta' framing

ESET frames the core exposure as a combination of three conditions in any single agent: access to sensitive data, exposure to material from outside the company, and permission to communicate or act externally. An agent that reads a shared drive, processes incoming email, and sends messages holds all three at once. Removing any one leg, the firm notes, reduces the risk substantially. ESET has also documented more than 100 distinct tools built specifically to disable endpoint detection and response (EDR) software, most abusing vulnerable drivers, with new variants appearing on a regular basis — a sign that attackers are investing in disabling defenses, not just bypassing them.

What budget-holders should ask their team

For SMBs with lean IT staff, the practical questions are about visibility and ownership rather than tooling alone. Leaders should ask: which AI agents and skills are currently connected to company systems, and who approved each one? Does any single agent combine data access, external content exposure, and outbound communication in one workflow? Is there a documented AI usage policy, or is one only likely to appear after an incident? And for phishing and patching — given the gap between AI-assisted and standard phishing click rates, and the share of vulnerabilities exploited at or before disclosure — does the current detection and response arrangement include monitoring of what agents pull in and act on, not just what employees click?

Share this insight