The Basics
What AI actually is and how it works
Not quite. A search engine finds existing pages that match your words. AI โ specifically the kind called a large language model โ generates a new response by predicting what words should come next, based on patterns learned from billions of documents. It's less like looking something up and more like asking a very well-read assistant to compose an answer on the spot.
๐ก That's also why AI can be confidently wrong. It's generating plausible-sounding text, not retrieving verified facts. Always check important outputs against a trusted source.
They're all AI assistants built on large language models, but from different companies with different philosophies. ChatGPT (OpenAI) is the most recognized name. Claude (Anthropic) is known for longer, more careful reasoning and stronger privacy defaults. Gemini (Google) is deeply integrated into Google Workspace. Copilot (Microsoft) is built into Microsoft 365 products. For most everyday business tasks, they're more similar than different โ the bigger question is which one has the right data agreements for your use case.
For most small businesses, the honest answer right now is: it replaces tasks, not people. Drafting a first version of an email, summarizing a long document, generating a social media post, pulling together a report โ those are tasks AI does well. The judgment calls, client relationships, and local knowledge that make your business yours are harder to automate. The businesses that struggle will be those that ignore AI entirely while competitors use it to move faster and do more with the same team size.
โ Think of it as a very capable intern that never sleeps โ useful for volume tasks, but still needs direction and review.
It depends entirely on the tool and the plan you're using. Free tools often do use your inputs to improve their models โ that's part of how they're funded. Most paid business plans explicitly promise they do not train on your data, and that's written into their terms. This distinction matters enormously if you're working with client information, financial data, or anything sensitive. When in doubt, read the data policy or ask your vendor directly.
Implementation
How to actually bring AI into your business
Start with your biggest time drains. Think about the last week โ what tasks took longer than they should have? Common starting points for South Dakota businesses: writing and editing (emails, proposals, job postings, social content), research and summarizing (reading through long documents, comparing options), and customer communication templates. Pick one task, try it for two weeks, and see how much time you save before adding more.
๐พ The best first AI project is the one you'll actually use โ not the most impressive one on paper.
Two things kill AI adoption: no clear guidance on what to use it for, and no clear guidance on what not to use it for. Before rollout, give your team three things: a short list of approved use cases, a short list of things that should never go into AI (client PII, passwords, internal financials), and a simple way to ask questions when they're unsure. Staff who understand the guardrails feel more confident experimenting โ not less.
โ Designate one person as your internal "AI point of contact" โ someone who tries things first and fields questions. It doesn't require a tech background, just curiosity.
For most small businesses, the entry point is $20โ$30 per user per month for a quality paid plan with solid data protections. That's less than a tank of gas and buys you meaningful productivity gains if used consistently. Enterprise-grade implementations with custom integrations, API access, and compliance packages run higher โ but the vast majority of Mitchell-area businesses don't need that level to start. Don't start with free tiers for business use โ the data policy trade-offs aren't worth the savings.
For basic AI tools โ no. Tools like Claude, ChatGPT Business, or Copilot 365 are designed for non-technical users and work right in the browser. You don't need to write code or hire an IT person to get started. Where you do start needing technical help is when you want to connect AI to your existing systems โ your CRM, your scheduling software, your intake forms. That's where an implementation partner earns their keep.
Risk & Compliance
The things that can go wrong โ and how to prevent them
Using free AI tools with real client, patient, or employee data โ without knowing whether those tools are permitted to store or train on that data. It's happening constantly, often innocently, and it creates real legal exposure. The second biggest mistake is publishing AI-generated content without reviewing it โ especially anything with specific facts, figures, dates, names, or legal/medical claims. AI makes things up. A human needs to catch it before it goes out.
Yes โ intent doesn't change compliance obligations. If protected health information ends up in a tool without a signed Business Associate Agreement, that's a HIPAA violation regardless of how it happened. If AI generates content that infringes copyright or makes a false factual claim about a person, you're the publisher. Regulators and courts are still catching up to AI, but the underlying laws โ HIPAA, FTC rules on advertising, employment law โ already apply. "I didn't know the AI would do that" is not a defense that has held up well.
โ Review any AI output that will be seen by clients, posted publicly, or used in a legal or financial context before it goes out.
Without a signed data agreement in place, keep these out of any AI tool:
Client/patient identifying information โ names, dates of birth, SSNs, addresses combined with other identifiers
Employee records โ performance reviews, salary information, disciplinary files
Financial account details โ account numbers, routing numbers, tax ID combinations
Passwords or credentials โ ever, under any circumstances
Attorney-client or doctor-patient privileged communications
When you need AI help on a sensitive topic, anonymize first. "My client John Smith, born 4/12/1968" becomes "a client in their mid-50s." You still get useful output with zero exposure.
Client/patient identifying information โ names, dates of birth, SSNs, addresses combined with other identifiers
Employee records โ performance reviews, salary information, disciplinary files
Financial account details โ account numbers, routing numbers, tax ID combinations
Passwords or credentials โ ever, under any circumstances
Attorney-client or doctor-patient privileged communications
When you need AI help on a sensitive topic, anonymize first. "My client John Smith, born 4/12/1968" becomes "a client in their mid-50s." You still get useful output with zero exposure.
Almost certainly yes โ and the answer isn't to ban it, because bans don't work and they push usage further underground. The answer is to get in front of it with a policy. A one-page "AI use at work" guideline โ approved tools, approved use cases, what never goes in โ is enough to dramatically reduce your risk and channel the energy productively. Staff who are already using AI are often your most efficient people. Give them a sanctioned path.
Oversight & Control
How to stay in charge of what AI does in your business
The short answer: you verify anything that matters. AI is best used as a first draft engine, not a final authority. For content, check that specific facts, names, dates, and statistics are accurate before publishing. For research, confirm conclusions against a primary source. For anything legal, financial, or medical โ treat AI output as a starting point for a professional to review, never the final word. The more specific and verifiable a claim, the more worth checking it is.
โ Ask the AI to cite its sources or explain its reasoning โ if it can't, that's a signal to verify independently.
A functional business AI policy doesn't need to be long. It needs to answer four questions:
1. Which tools are approved? (List 1โ3 vetted options with signed agreements where required)
2. What can staff use AI for? (Drafting, research, summarizing, brainstorming โ be specific to your business)
3. What can never go into AI? (Client PII, financial details, privileged info โ see above)
4. Who do staff ask when they're unsure? (Name a person, not just a department)
One page. Review it annually. That's a real AI policy.
1. Which tools are approved? (List 1โ3 vetted options with signed agreements where required)
2. What can staff use AI for? (Drafting, research, summarizing, brainstorming โ be specific to your business)
3. What can never go into AI? (Client PII, financial details, privileged info โ see above)
4. Who do staff ask when they're unsure? (Name a person, not just a department)
One page. Review it annually. That's a real AI policy.
Technically yes โ but in most regulated industries, a human must remain the decision-maker of record. Using AI to screen job applicants, for example, can create Fair Housing or EEOC exposure if the model reflects biased training data. Using AI to make credit or lending decisions triggers financial regulation. The general rule: AI can inform and assist decisions. The accountability for the decision stays with a person. Build your workflows with that separation clear.
Start with a simple inventory โ ask your team what AI tools they're currently using, even informally. Most organizations are surprised by the answer. From there: limit official use to a short approved list, use business accounts rather than personal accounts so there's an admin layer, and build a brief check-in into your regular team meetings ("anything new you've been using AI for?"). Audit trail features in paid enterprise tools give you more formal visibility, but for most small businesses, a culture of transparency gets you 80% of the way there.
For a small to mid-size South Dakota business, a realistic timeline looks like this:
Week 1โ2: Identify your highest-value use case. Pick one approved tool. Get it set up properly with a business account.
Week 3โ4: Run a small pilot with 1โ2 staff on that specific use case. Gather feedback.
Month 2: Write your one-page AI policy. Expand to the full team on that one use case.
Month 3โ6: Add a second use case. Evaluate ROI. Decide what comes next.
Six months in, you have something you can genuinely call a strategy โ not because you planned it on a whiteboard, but because you built it from real experience.
Week 1โ2: Identify your highest-value use case. Pick one approved tool. Get it set up properly with a business account.
Week 3โ4: Run a small pilot with 1โ2 staff on that specific use case. Gather feedback.
Month 2: Write your one-page AI policy. Expand to the full team on that one use case.
Month 3โ6: Add a second use case. Evaluate ROI. Decide what comes next.
Six months in, you have something you can genuinely call a strategy โ not because you planned it on a whiteboard, but because you built it from real experience.
Want help building your AI policy or identifying your first use case?
Free 30-minute conversation. No pitch, no pressure โ just a plain-spoken local perspective.