AI Ethics for Small Business

By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer

TL;DR: A recent Harvard DCE article makes the case that AI ethics is now a core leadership competency, not a compliance checkbox. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, agrees with that premise entirely — but argues the article stops short of the most urgent audience: small and medium-sized businesses that are already deploying AI without any ethical framework in place. For SMBs, the ethics of AI is not an academic exercise. It is a liability question, a trust question, and a decision-making question that will define which businesses survive the next decade.

A regional accounting firm in the Southeast — forty employees, three partners, solid local reputation — started using an AI tool to draft client communications. Nobody told them to. Nobody told them not to. Within six months, the tool had generated three client letters with factual errors, one of which triggered a complaint to the state board. The partners had no policy governing AI use. They had no review process. They had rationalized that if the tool was available and it saved time, it was probably fine. Need, opportunity, and rationalization. Every ethical failure I have ever studied runs on that same engine.

What Harvard Got Right About AI Ethics

The Harvard DCE piece, written by Lizzie Short and featuring commentary from Michael Impink — an instructor of AI Ethics in Business at Harvard’s Professional and Executive Development division — makes a point I have been arguing for years: awareness is the starting line for ethical AI leadership. Impink puts it plainly: “For leaders, awareness is the number one step. Once leaders know where ethical AI issues might exist, they can begin to generate solutions.” That is not a controversial claim. It is a foundational one. You cannot govern what you refuse to see.

The article identifies the main categories of AI ethical risk correctly: data privacy and the legal exposure that comes from mishandling personally identifiable information, bias baked into training data or algorithms, and the transparency problem that arises when AI makes consequential decisions no human can fully explain. These are real. The article also rightly notes that AI governance is not just a domestic American conversation — the EU AI Act and the OECD AI Principles have created a global baseline that any organization doing international business cannot simply ignore. Harvard is right that this conversation belongs in the boardroom. My argument is that it also belongs in the back office of every SMB in the country.

As a business ethics keynote speaker and AI speaker and author, I have spent years watching how institutions frame ethical problems as belonging exclusively to large enterprises. The assumption is that ethics is a scale problem — that it takes a compliance department, a legal team, and a Chief AI Officer to get it right. That assumption is wrong, and in the context of AI, it is actively dangerous. Anthropic CEO Dario Amodei has projected that AI could replace 50 percent of entry-level white-collar jobs within five years. The accounting firm I described at the start of this article has entry-level staff. They have customer data. They have legal exposure. They do not have a Chief AI Officer.

Why Does AI Ethics Matter Specifically for Small and Medium-Sized Businesses?

The bias problem that Harvard describes is not just a problem for Google or JPMorgan. A small HR consulting firm that uses AI to screen resumes and allows a biased algorithm to systematically filter out candidates from a protected class is not less liable because it is small. The EEOC does not offer a small-business exemption for discriminatory hiring outcomes. The bias in the algorithm will produce the same adverse impact whether the firm has twenty employees or twenty thousand. What differs is that the large firm probably has legal counsel watching for this. The small firm probably does not.

The transparency issue cuts even deeper for SMBs. Impink describes the “black-box” problem — AI systems making decisions that even the people managing them cannot explain. For a community bank using AI to evaluate loan applications, or a regional healthcare provider using AI to flag patient records, or a small insurance agency using AI to generate policy quotes, this is not a theoretical concern. When a customer asks why they were denied and the employee cannot answer, trust erodes immediately. And for a small business, trust is the competitive advantage. You cannot rebuild that with a marketing campaign.

Here is what I consistently argue at ChuckGallagher.com and in the speaking work I do with business leaders: ethics is not what you add to AI after deployment. It is what you decide before the first prompt is submitted. The accounting firm I referenced made an ethical decision the moment they allowed an unreviewed AI tool to generate client-facing content — they just did not recognize it as a decision. That is the rationalization in action. “It saves time” is a need. An unsupervised AI tool is an opportunity. “It’s probably fine” is the rationalization. Three forces. One failure waiting to happen.

The Harvard article notes that companies using AI ethically and responsibly “will gain a competitive advantage,” citing Impink’s observation that firms behaving unethically may face difficulty “winning contracts or accessing data.” That framing — ethics as competitive strategy — is exactly right, and it translates directly to the SMB context. A medical practice that can demonstrate responsible data handling, a professional services firm that can document its AI review process, a retail business that can explain how its pricing algorithms work — these organizations will earn and keep customer trust in a market where that trust is increasingly fragile.

Three Things SMBs Can Do Right Now

As an AI ethics speaker and author, I have reduced this to three practical actions any small or medium-sized business can implement without a six-figure consulting engagement. First, write a one-page AI use policy before the end of this quarter. Not a manifesto. A clear statement of what AI tools your people are permitted to use, for what purposes, and with what review requirements before output leaves the building. If content is customer-facing, a human being must review it. That is not optional. Second, ask your AI vendors the three questions every SMB deserves answers to: What data are you training on? Who reviews outputs for bias? What happens to my customer data after I submit it? If a vendor cannot answer those questions clearly, that is your answer. Third, treat AI errors the way you would treat employee errors — as events that require documentation, root-cause analysis, and a corrective process. Not punishment. Process. An AI tool that produces a factual error in a client document is not a technology problem. It is a management problem that technology made visible.

The Harvard article closes with a reminder that “establishing ethical processes around data privacy, fairness, and transparency is critical for success.” I want to underscore that word: critical. Not aspirational. Not best-practice-adjacent. Critical. The small business that deploys AI without ethical guardrails is not moving faster than its competitors. It is accumulating risk it cannot see. And in my experience, unseen risk does not stay invisible forever. Every choice has a consequence. The businesses that acknowledge that truth about AI now will be the ones still standing when those consequences arrive.

Frequently Asked Questions

Why does AI ethics matter for small businesses, not just large corporations?

Small and medium-sized businesses face the same legal exposure as large enterprises when AI produces biased outputs, mishandles customer data, or generates inaccurate information. The EEOC, FTC, and state regulators do not offer liability exemptions based on company size. What differs is that smaller firms typically lack in-house legal counsel or compliance staff to catch AI-related problems before they become costly. According to Harvard DCE instructor Michael Impink, awareness of where AI ethical issues exist is the essential first step for any business leader.

What are the biggest AI ethics risks for a small business owner?

The three most significant risks are data privacy violations, algorithmic bias, and lack of transparency in AI decision-making. Any business handling personally identifiable information has a legal obligation to keep that data secure — including when it is submitted to AI tools. Bias in AI systems can produce discriminatory outcomes in hiring, lending, and service delivery that expose businesses to litigation. Transparency failures arise when businesses cannot explain why an AI system produced a particular output, which erodes customer trust and complicates regulatory compliance.

Does the EU AI Act apply to small businesses in the United States?

Any U.S. business that operates internationally, serves EU customers, or processes data on EU residents may be subject to the EU AI Act’s requirements, regardless of company size. As Michael Impink noted in Harvard’s recent piece on AI ethics, “The E.U. regulates the developed world” — meaning U.S. firms that want to access international markets effectively follow European standards. The EU AI Act classifies AI applications by risk level, with high-risk uses in areas like employment, credit, and education subject to the most rigorous requirements.

How can a small business build an AI ethics framework without a large budget?

A practical starting point is a one-page AI use policy that defines which tools employees may use, for which purposes, and what review is required before AI-generated content is shared externally. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, recommends that SMBs treat AI-generated errors the way they treat employee errors — as management events requiring documentation and a corrective process, not just a technology fix. Asking AI vendors three specific questions — about training data, bias review, and customer data handling — is a free and immediate step that reveals whether a vendor is operating responsibly.

What is AI bias and how does it affect business decisions?

AI bias occurs when the data used to train an AI system, the algorithm itself, or the priorities built in by programmers produce outputs that systematically favor or disadvantage certain groups. Harvard DCE’s Michael Impink identifies three sources: biased programmers, biased algorithms, and biased training data. In business applications, this can mean a hiring tool that filters out qualified candidates based on demographic patterns in past data, or a lending tool that denies credit to customers in ways that correlate with protected characteristics. A biased AI tool, as Impink notes, “can lead to a host of poor outcomes: inaccurate predictions, litigation, and wrongheaded conclusions.”

What Is Your Business Actually Doing?

I am curious where you are in this conversation. Are you running AI tools in your business right now — and do you have a written policy governing how they are used? The gap between those two realities is exactly where ethical failures begin. Leave a comment below and tell me: what is the one AI ethics question you wish someone had answered before you started using these tools? I read every comment personally and will respond. The five questions below are designed to push that reflection further.

Five Questions for Further Thought and Consideration

1. If an AI tool your business uses produced a discriminatory outcome tomorrow — in hiring, in pricing, in customer service — would you be able to explain to a regulator exactly how that outcome occurred and what you did to prevent it?

2. How would your customers respond if they learned that AI-generated content was being used in communications sent under your name, without human review?

3. When you adopted AI tools in your business, who in your organization was responsible for evaluating the ethical implications — and if the answer is “nobody,” what does that tell you?

4. The Harvard article projects that AI could replace 50 percent of entry-level white-collar jobs within five years. What obligation do you have to the employees in those roles right now, before that transition arrives?

5. If your AI vendor were acquired tomorrow and its data policies changed overnight, how exposed would your customers’ information be — and do you even know the aor, agrees with that premise entirely — but argues the article stops short of the most urgent audience: small and medium-sized businesses that are already deploying AI without any ethical framework in place. For SMBs, the ethics of AI is not an academic exercise. It is a liability question, a trust question, and a decision-making question that will define which businesses survive the next decade.

A regional accounting firm in the Southeast — forty employees, three partners, solid local reputation — started using an AI tool to draft client communications. Nobody told them to. Nobody told them not to. Within six months, the tool had generated three client letters with factual errors, one of which triggered a complaint to the state board. The partners had no policy governing AI use. They had no review process. They had rationalized that if the tool was available and it saved time, it was probably fine. Need, opportunity, and rationalization. Every ethical failure I have ever studied runs on that same engine.

What Harvard Got Right About AI Ethics

The Harvard DCE piece, written by Lizzie Short and featuring commentary from Michael Impink — an instructor of AI Ethics in Business at Harvard’s Professional and Executive Development division — makes a point I have been arguing for years: awareness is the starting line for ethical AI leadership. Impink puts it plainly: “For leaders, awareness is the number one step. Once leaders know where ethical AI issues might exist, they can begin to generate solutions.” That is not a controversial claim. It is a foundational one. You cannot govern what you refuse to see.

The article identifies the main categories of AI ethical risk correctly: data privacy and the legal exposure that comes from mishandling personally identifiable information, bias baked into training data or algorithms, and the transparency problem that arises when AI makes consequential decisions no human can fully explain. These are real. The article also rightly notes that AI governance is not just a domestic American conversation — the EU AI Act and the OECD AI Principles have created a global baseline that any organization doing international business cannot simply ignore. Harvard is right that this conversation belongs in the boardroom. My argument is that it also belongs in the back office of every SMB in the country.

As a business ethics keynote speaker and AI speaker and author, I have spent years watching how institutions frame ethical problems as belonging exclusively to large enterprises. The assumption is that ethics is a scale problem — that it takes a compliance department, a legal team, and a Chief AI Officer to get it right. That assumption is wrong, and in the context of AI, it is actively dangerous. Anthropic CEO Dario Amodei has projected that AI could replace 50 percent of entry-level white-collar jobs within five years. The accounting firm I described at the start of this article has entry-level staff. They have customer data. They have legal exposure. They do not have a Chief AI Officer.

Why Does AI Ethics Matter Specifically for Small and Medium-Sized Businesses?

The bias problem that Harvard describes is not just a problem for Google or JPMorgan. A small HR consulting firm that uses AI to screen resumes and allows a biased algorithm to systematically filter out candidates from a protected class is not less liable because it is small. The EEOC does not offer a small-business exemption for discriminatory hiring outcomes. The bias in the algorithm will produce the same adverse impact whether the firm has twenty employees or twenty thousand. What differs is that the large firm probably has legal counsel watching for this. The small firm probably does not.

The transparency issue cuts even deeper for SMBs. Impink describes the “black-box” problem — AI systems making decisions that even the people managing them cannot explain. For a community bank using AI to evaluate loan applications, or a regional healthcare provider using AI to flag patient records, or a small insurance agency using AI to generate policy quotes, this is not a theoretical concern. When a customer asks why they were denied and the employee cannot answer, trust erodes immediately. And for a small business, trust is the competitive advantage. You cannot rebuild that with a marketing campaign.

Here is what I consistently argue at ChuckGallagher.com and in the speaking work I do with business leaders: ethics is not what you add to AI after deployment. It is what you decide before the first prompt is submitted. The accounting firm I referenced made an ethical decision the moment they allowed an unreviewed AI tool to generate client-facing content — they just did not recognize it as a decision. That is the rationalization in action. “It saves time” is a need. An unsupervised AI tool is an opportunity. “It’s probably fine” is the rationalization. Three forces. One failure waiting to happen.

The Harvard article notes that companies using AI ethically and responsibly “will gain a competitive advantage,” citing Impink’s observation that firms behaving unethically may face difficulty “winning contracts or accessing data.” That framing — ethics as competitive strategy — is exactly right, and it translates directly to the SMB context. A medical practice that can demonstrate responsible data handling, a professional services firm that can document its AI review process, a retail business that can explain how its pricing algorithms work — these organizations will earn and keep customer trust in a market where that trust is increasingly fragile.

Three Things SMBs Can Do Right Now

As an AI ethics speaker and author, I have reduced this to three practical actions any small or medium-sized business can implement without a six-figure consulting engagement. First, write a one-page AI use policy before the end of this quarter. Not a manifesto. A clear statement of what AI tools your people are permitted to use, for what purposes, and with what review requirements before output leaves the building. If content is customer-facing, a human being must review it. That is not optional. Second, ask your AI vendors the three questions every SMB deserves answers to: What data are you training on? Who reviews outputs for bias? What happens to my customer data after I submit it? If a vendor cannot answer those questions clearly, that is your answer. Third, treat AI errors the way you would treat employee errors — as events that require documentation, root-cause analysis, and a corrective process. Not punishment. Process. An AI tool that produces a factual error in a client document is not a technology problem. It is a management problem that technology made visible.

The Harvard article closes with a reminder that “establishing ethical processes around data privacy, fairness, and transparency is critical for success.” I want to underscore that word: critical. Not aspirational. Not best-practice-adjacent. Critical. The small business that deploys AI without ethical guardrails is not moving faster than its competitors. It is accumulating risk it cannot see. And in my experience, unseen risk does not stay invisible forever. Every choice has a consequence. The businesses that acknowledge that truth about AI now will be the ones still standing when those consequences arrive.

Frequently Asked Questions

Why does AI ethics matter for small businesses, not just large corporations?

Small and medium-sized businesses face the same legal exposure as large enterprises when AI produces biased outputs, mishandles customer data, or generates inaccurate information. The EEOC, FTC, and state regulators do not offer liability exemptions based on company size. What differs is that smaller firms typically lack in-house legal counsel or compliance staff to catch AI-related problems before they become costly. According to Harvard DCE instructor Michael Impink, awareness of where AI ethical issues exist is the essential first step for any business leader.

What are the biggest AI ethics risks for a small business owner?

The three most significant risks are data privacy violations, algorithmic bias, and lack of transparency in AI decision-making. Any business handling personally identifiable information has a legal obligation to keep that data secure — including when it is submitted to AI tools. Bias in AI systems can produce discriminatory outcomes in hiring, lending, and service delivery that expose businesses to litigation. Transparency failures arise when businesses cannot explain why an AI system produced a particular output, which erodes customer trust and complicates regulatory compliance.

Does the EU AI Act apply to small businesses in the United States?

Any U.S. business that operates internationally, serves EU customers, or processes data on EU residents may be subject to the EU AI Act’s requirements, regardless of company size. As Michael Impink noted in Harvard’s recent piece on AI ethics, “The E.U. regulates the developed world” — meaning U.S. firms that want to access international markets effectively follow European standards. The EU AI Act classifies AI applications by risk level, with high-risk uses in areas like employment, credit, and education subject to the most rigorous requirements.

How can a small business build an AI ethics framework without a large budget?

A practical starting point is a one-page AI use policy that defines which tools employees may use, for which purposes, and what review is required before AI-generated content is shared externally. Chuck Gallagher, business ethics keynote speaker and AI speaker and author, recommends that SMBs treat AI-generated errors the way they treat employee errors — as management events requiring documentation and a corrective process, not just a technology fix. Asking AI vendors three specific questions — about training data, bias review, and customer data handling — is a free and immediate step that reveals whether a vendor is operating responsibly.

What is AI bias and how does it affect business decisions?

AI bias occurs when the data used to train an AI system, the algorithm itself, or the priorities built in by programmers produce outputs that systematically favor or disadvantage certain groups. Harvard DCE’s Michael Impink identifies three sources: biased programmers, biased algorithms, and biased training data. In business applications, this can mean a hiring tool that filters out qualified candidates based on demographic patterns in past data, or a lending tool that denies credit to customers in ways that correlate with protected characteristics. A biased AI tool, as Impink notes, “can lead to a host of poor outcomes: inaccurate predictions, litigation, and wrongheaded conclusions.”

What Is Your Business Actually Doing?

I am curious where you are in this conversation. Are you running AI tools in your business right now — and do you have a written policy governing how they are used? The gap between those two realities is exactly where ethical failures begin. Leave a comment below and tell me: what is the one AI ethics question you wish someone had answered before you started using these tools? I read every comment personally and will respond. The five questions below are designed to push that reflection further.

Five Questions for Further Thought and Consideration

1. If an AI tool your business uses produced a discriminatory outcome tomorrow — in hiring, in pricing, in customer service — would you be able to explain to a regulator exactly how that outcome occurred and what you did to prevent it?

2. How would your customers respond if they learned that AI-generated content was being used in communications sent under your name, without human review?

3. When you adopted AI tools in your business, who in your organization was responsible for evaluating the ethical implications — and if the answer is “nobody,” what does that tell you?

4. The Harvard article projects that AI could replace 50 percent of entry-level white-collar jobs within five years. What obligation do you have to the employees in those roles right now, before that transition arrives?

5. If your AI vendor were acquired tomorrow and its data policies changed overnight, how exposed would your customers’ information be — and do you even know the answer?

Related Articles:

EU AI Act Enforcement: Your GPAI Model Has No Passport

AI in Court: When Fabricated Citations Become a Sanctions Problem

Leave a Reply