five signals.
one week.
nobody kept
the list._
the average small business spends about $2,400 a year on ai. the real number is nearer $5,000 once somebody has to learn it.
smb ai adoption hit 66 percent this summer against 55 percent a year ago, a third of owners are spending more than they were twelve months back, and average direct spend sits near $2,400 a year against a true cost closer to $4,000 or $5,000 once training hours and integration upkeep are counted.
the condition underneath the number is that nobody ever made a purchasing decision here. a seat went on a card in march. a second tool arrived on a trial that converted. every individual charge stayed under the amount that triggers a conversation, so no conversation happened. the cost is not the line item. it is two tools doing the same job with different data inside them, a third configured halfway and abandoned, and a team that cannot tell you which one is the system of record.
the fake fix is consolidating onto one bigger platform, which swaps four small unexamined charges for one large one and moves the same confusion inside a single vendor. do the version that holds: pull ninety days of card and bank statements, list every ai charge next to the date anyone last opened it, cancel everything untouched in thirty days today, and for each survivor write the one job it does and the one person who owns it. the audit takes an afternoon and it is the only spend review that also tells you what your business actually runs on.
the four biggest cloud companies are budgeting up to $630 billion on ai capacity this year, up from $388 billion. that bill comes back out of somebody's invoice, and it is not theirs.
big four capital spending for 2026 is running near $630 billion against $388 billion last year, roughly a 62 percent jump, with about three quarters of it going into ai infrastructure. meta has already raised its own range twice on component and data centre costs.
the condition underneath the number is that most companies attached ai to something that matters, quoting, drafting, support triage, at introductory usage pricing with no contractual ceiling and no way to run the process without it. the cost lands twice. there is the invoice. and there is the fact that a 40 percent price move is no longer a negotiation, because the manual version of that workflow has not been run by anyone in eight months and nobody currently employed remembers how.
the fake fix is shopping vendors at renewal, which takes a quarter, moves your data onto a different meter you also do not control, and assumes the next company is not funding the same capacity bill. do the version that holds: for every ai tool sitting on revenue or payroll, write down this month's actual usage, what a doubling costs you, and whether the work can run manually for two weeks if it had to. then ask for a capped rate over a multi year term at renewal and keep your exports current, so leaving is a decision you make in a week rather than a project you cannot afford to start.
every ai browser tested at black hat fell to the same trick: a hidden line of text on a page, and the agent takes its orders from the page instead of from you.
researchers at black hat usa this month reported that every ai browser they analyzed was vulnerable to prompt injection, opera's ai browser, perplexity comet and chatgpt atlas among them. brave's own researcher put it plainly: there is no clean fix for this yet.
the condition is structural rather than a bug somebody patches on tuesday. an agent that browses for you cannot reliably separate the page's content from your instruction, so invisible text on a supplier site, a review page or an email preview becomes a command it runs inside your logged in session. the cost is not a stolen password, which is what your controls were built for. it is a purchase placed, a form submitted, a document shared out of your drive, every action correctly authenticated as you, which means neither your bank nor whoever handles your it sees a problem until the statement arrives.
the fake fix is telling the team to point the agent only at sites they trust, which holds until the first trusted site carries a comment field, an ad slot or a supplier's pdf. do the version that holds: give the agent its own browser profile with no saved cards, no password manager and no session on email, banking or payroll. keep the accounts that move money in a separate browser the agent never opens. require a human click before anything spends, sends or shares. let it read the web for you. do not let it hold the card while it does.
write the list.
put a name on each line.
cancel what nobody claims.
43 percent of companies cannot produce an accurate list of the ai already running inside their own business. they are paying for all of it.
the 2026 numbers put 43 percent of organizations in the position of not being able to answer a basic question: what ai are we running. the spend is the smaller half of it, 4 to 9 percent of the software line, real money but survivable.
the part that matters is that each unlisted tool is an account somebody opened with a work email, a card on file nobody reconciles, and a pile of customer records sitting inside a vendor you never diligenced. that is also why 82 percent of workplace genai use runs through personal accounts your it people cannot see. the exposure is not the subscription. it is that your customer list has been copied into somewhere you cannot name, by somebody who was trying to do their job faster.
the fake fix is an ai policy, because a policy is a document and the tools are a fact. do the version that holds, and it takes an afternoon: pull the card statements and the sso logs, list every ai tool by name, put one person's name against each one, cancel the orphans, move the survivors onto managed accounts. you cannot govern an inventory you have never written down, and nobody is going to write it down for you.
an ai company sold small businesses a bot that would close their sales. the ftc banned the owners in march, entered an $18 million judgment, then suspended most of it because there was nothing left to collect.
the ftc's order describes the standard shape: a tool wrapped in an income promise, a refund policy that did not survive contact with a refund request, and buyers who paid up front for a business rather than for work.
the money is mostly unrecoverable, which is the part worth internalizing. a suspended judgment means the regulator agreed you were robbed and also that you are not getting paid. this category is expanding right now, because anyone can put a chat window on a landing page and call it infrastructure, and the demos are excellent for the simple reason that demos are the only thing they build.
the fake protection is more diligence on the technology, watching the demo twice, asking which model it runs on. the technology is not what fails. run one test instead: make the seller name a number already in your p&l, say how much it moves and by when, and hand you two customers in your industry who have run it for six months. if the pitch is the income rather than the work, it is a business opportunity scheme with a chatbot on the front, and the ftc will reach it about eighteen months after your card clears.