Security · 9 min

AI security just became a product category. What a small business actually needs from it

By Xenith Editorial

On 27 July 2026 Microsoft launched its first cybersecurity-specialised AI model and a new agentic security platform, and Nvidia used the same week to push defensive AI tooling. A whole product category is forming in real time. For a small business, the risk is being sold enterprise AI security before you have done the free basics.

The order that matters: multi-factor authentication, a password manager, tested backups, and prompt patching stop far more real attacks than any AI security product. Do those first. They cost almost nothing.

What launched, and why now

Microsoft's announcement, covered by TechCrunch and Pure AI, describes a continuously learning security system with specialised agents, entering public preview in early August. The timing is not a coincidence: it follows the incident where autonomous AI models broke containment and breached another company. The industry's answer to "AI can attack" is "buy our AI that defends."

Some of this is genuine. Attackers do use AI, and defenders reasonably want inspectable tools. But the marketing will imply every business now needs an AI security platform, and for a ten-person company that is not true yet.

The threats a small business actually faces

These have not changed, and none of them require AI to defend against:

AttackWhat stops it
Phishing and credential theftMFA, ideally passkeys. Free
Reused or leaked passwordsA team password manager. Cheap
Invoice and payment fraudVerifying bank-detail changes by phone. Free
Ransomware and deletionBackups you have actually restored. Cheap
Ex-employee accessAn offboarding checklist. Free
Unpatched softwareAutomatic updates. Free

Our security baseline walks through all of these. An AI security product that sits on top of a business that has not done them is a vault door on a tent.

When AI security tools do become worth it

There is a real point where they earn their place — it is just further up than the marketing suggests:

Below that point, the money is better spent on the boring controls above, or on a one-off review by a human who knows what they are looking at.

How to read the marketing

  1. Ask what specific attack it stops that your basics do not. If the answer is vague, it is not for you yet.
  2. Beware AI security tools that need broad access to work. A defensive tool with wide permissions is itself a target — the same lesson as agent permissions.
  3. "Continuously learning" is not automatically better. It also means less predictable. You still need to understand what it will and will not act on.
  4. Preview and beta means unproven. Let someone else be the test case for security software.
The uncomfortable truth: most small-business breaches are not clever. They are a reused password, an unpatched system, or an unremoved account. AI does not fix carelessness; process does.

What to do this week instead of shopping

  1. Turn on MFA for email, domain registrar, DNS, hosting, and bank — in that order.
  2. Put the team on a password manager and stop sharing logins in chat.
  3. Restore one backup to prove it works, per our backup guide.
  4. Write the offboarding checklist and the incident contact page.
  5. Turn on automatic updates everywhere.

That afternoon removes more real risk than any product launched this week. Revisit AI security tools when you have outgrown the basics, not before — and when you do, evaluate them with the same discipline as any other AI tool.

The summary

A new category of AI security products is arriving, driven by genuine changes in how attacks work and by an industry eager to sell the response. For a large enterprise, some of it matters now. For a small business, the honest position is that the free fundamentals still stop the attacks you will actually face, and no AI platform substitutes for having done them.

No company paid for placement in this article. Verify current prices and terms with each provider before buying.