AI agents for small business: what to check before you trust one
An AI agent is software that can plan and take actions, not only answer questions. Before you give one access to your business, check what it can touch, who approves its important actions, what it reads from outside, how you will catch its mistakes, and what the law says about telling people it is an AI. These checks come from public bodies in the US, the EU and the UK, and from a security project.
Updated 3 October 2026
What is an AI agent?
The US National Institute of Standards and Technology (NIST) describes AI agent systems as "capable of planning and taking autonomous actions that impact real-world systems or environments." [1] In plain words, a chatbot gives you text, and an agent can also do something with it: send a message, change a file, or spend money, if you let it.
NIST says such agents could have "a wide range of potential benefits, such as automating scientific research or serving as personal assistants." [2] The same ability to act is why you need to check them first.
What can an agent get wrong?
Generative AI can state false things confidently. NIST defines this as "the production of confidently stated but erroneous or false content." [3] A text tool with this flaw gives you a wrong draft. An agent with this flaw can act on the wrong idea. NIST also warns about "excessive deference to automated systems," where people trust the output too much. [3]
What should I check before I trust an AI agent?
1. What can it reach?
The OWASP Gen AI Security Project defines excessive agency as the vulnerability that "enables damaging actions to be performed in response to unexpected, ambiguous or manipulated outputs from an LLM". [4] Its advice is to limit the tools an agent may call "to only the minimum necessary," and to limit the permissions it has in other systems in the same way. [4] For a small business: give an agent its own account with narrow rights, not your main login.
2. Who approves the big actions?
OWASP recommends a human-in-the-loop control "to require a human to approve high-impact actions before they are taken." [4] Decide in advance which actions are high-impact for you, such as payments, public posts, contracts and deleting data.
3. What does it read from outside?
NIST defines agent hijacking as a type of indirect prompt injection in which "an attacker inserts malicious instructions into data that may be ingested by an AI agent, causing it to take unintended, harmful actions." [2] OWASP explains that indirect injections happen "when an LLM accepts input from external sources, such as websites or files," and advises you to "separate and clearly denote untrusted content." [5] So an email, a web page or an uploaded file can carry instructions. Ask any vendor how its agent treats content that comes from outside.
4. Does it tell people it is an AI?
The European Commission says Article 50 of the AI Act "applies as from 2 August 2026." [6] It says providers must design systems that talk directly to people, "such as chatbots, AI agents, and avatars," so that people are informed they are interacting with AI. [6] If you sell in the EU, ask how the tool does that.
5. Are the claims honest?
The US Federal Trade Commission says "there is no AI exemption from the laws on the books." [7] Be careful with any product that promises income or fixed results. Ask for evidence you can read, and do not rely on testimonials alone.
6. Who is responsible for the data?
The UK data protection regulator says that when you buy an AI solution from a third party you "need to conduct an independent evaluation." [8] Find out what customer data the agent sees, where it goes, and who can read it.
What about cost and records?
These two points are practical advice, not rules from a source. Set a spending limit that the agent cannot change, and check it at the start. Keep a log of what the agent did, so that you can find the cause when something goes wrong. Review the log weekly at first.
A short checklist
- The agent has its own account with only the rights it needs.
- A person approves payments, public posts and anything that cannot be undone.
- I know what outside content it reads, and I treat that content as untrusted.
- I can see a record of what it did.
- People who talk to it are told it is an AI.
- I have read the vendor's claims, and I do not rely on promised results.
What does a small example look like?
This is an example, not a real business. A bakery in Uppsala lets an AI agent answer customer emails. First it only drafts replies, and the owner sends them. After two weeks the owner lets the agent send answers about opening hours by itself, but not refunds or special orders. A customer's email contains a hidden line telling the agent to give a discount. Because the agent cannot issue discounts without approval, nothing happens. That is the idea behind checks 1 to 3: limited rights, human approval and untrusted outside content.
What should I read next?
For the wider picture of what AI can do for a new company, see starting a company with AI. List what a tool costs in the startup budget template, and test your idea with real people first: how to validate a business idea without spending money.
Easeable helps a person structure an idea, take it into execution, and run the business with them. You can describe your idea in the box at the end of this page.
Sources
- NIST: CAISI issues request for information about securing AI agent systems (12 January 2026)
- NIST: Technical blog, strengthening AI agent hijacking evaluations (17 January 2025)
- NIST AI 600-1: Generative AI Profile (July 2024)
- OWASP Gen AI Security Project: LLM06:2025 Excessive Agency
- OWASP Gen AI Security Project: LLM01 Prompt Injection
- European Commission: Transparency obligations under Article 50 of the AI Act
- US Federal Trade Commission: crackdown on deceptive AI claims and schemes (25 September 2024)
- UK Information Commissioner's Office: Accountability and governance implications of AI