The Compliance Reckoning Small Businesses Can No Longer Postpone

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Small businesses face a growing convergence of privacy regulation, AI governance and cybersecurity threats. Here’s how to prepare before compliance becomes a crisis.

Abhik Biswas is the Co-Founder and CTO at Prakat Solutions Inc, writes to bridge scientific insights with practical engineering.

getty​For years, small and midsize businesses could reasonably treat regulatory compliance and enterprise-grade security as someone else’s problem—a cost of doing business reserved for banks, hospitals and companies large enough to carry a dedicated legal and security function.

That assumption is breaking down everywhere at once, and most small businesses haven’t caught up to it.

According to Verizon’s 2025 Data Breach Investigations Report, 88% of breaches at small and midsize businesses involved ransomware, with a median ransom payment of $115,000. For a business of that size, that’s often much more than a line item. Plus, it’s happening against the backdrop of a regulatory environment that is expanding, globally, faster than most small businesses are tracking it.

According to the International Association of Privacy Professionals, data protection or privacy laws are now in effect in 144 countries, a number that has grown steadily since the EU’s General Data Protection Regulation set the template in 2018.

In just the last year, India notified its Digital Personal Data Protection Rules, Vietnam rolled out a new personal data protection law and decree, and Saudi Arabia’s Personal Data Protection Law continued its own phased rollout. Brazil, Nigeria, Indonesia and Malaysia have all done versions of the same thing in the recent past.

There is still no comprehensive federal privacy law in the United States, but that isn’t the same as no exposure. More than 20 states now have comprehensive consumer privacy laws in effect or taking effect by 2026, according to legislative trackers from MultiState and the IAPP.

A small business operating online, by definition, is rarely selling into just one of those jurisdictions.​

The most closely watched attempt to regulate AI directly, the EU’s AI Act, illustrates just how unsettled this space still is. Its ban on prohibited AI practices took effect in February 2025, and obligations for general-purpose AI model providers followed in August 2025. But an “AI Omnibus” simplification package that entered into force in mid-2026 pushed back several of the Act’s more consequential deadlines—standalone high-risk AI systems covered by Annex III now apply from December 2027, while rules for high-risk AI systems embedded in regulated products are delayed until August 2028.

Even the jurisdiction that moved fastest and most deliberately on AI regulation is still recalibrating how to do it. For a small business trying to figure out what governance its own AI tools—a support chatbot, an AI sales assistant, an internal coding copilot—actually require, the honest answer in most of the world right now is: less than you’d expect, and less than you should rely on.

The absence of a clear rule is not the same as the absence of risk.

Research from ReversingLabs’ 2026 Software Supply Chain Security Report found a 73% year-over-year rise in open-source malware, describing the shift as one from implicit trust in dependency ecosystems to a requirement for continuous validation.

And it isn’t only small companies getting caught out. In 2025, the Indian stock brokerage Angel One disclosed a breach of client data from cloud infrastructure, and Tata Technologies, a large global engineering services firm, had a ransomware group claim theft of 1.4 terabytes of data across more than 730,000 files. Both are sophisticated organizations with real security budgets.

The lesson isn’t that scale offers no protection. It’s that scale offers less protection than most people assume, and a small business without a dedicated security function, running its operations on whatever combination of cloud and SaaS tools got the job done fastest, has far less margin for error when something goes wrong.

This risk isn’t evenly distributed. A handful of small-business categories are most likely to feel it sooner than others: consumer-facing e-commerce and D2C brands sitting on payment and order data at scale; fintech, insurtech and wealthtech companies layering new data-protection obligations on top of existing financial-sector rules; healthtech and clinical businesses handling some of the most sensitive data categories that exist; and B2B software companies that face this exposure from both directions—as consumers of the open-source ecosystem, and as suppliers of security and compliance risk to every customer who runs their product.

Any business that outsources development, operations or customer support to third parties should also assume that obligation follows the data, not the org chart. Outsourcing the work rarely outsources the liability.

• Map where customer data actually lives across every jurisdiction you sell into, not just where you’re headquartered.

• Assign clear, named ownership for privacy and security decisions, even if it’s a part-time responsibility for now.

• Inventory the open-source components and AI tools your product and team actually rely on. You cannot secure, or govern, what you haven’t mapped.

• Write an internal policy for what your AI tools are and aren’t allowed to do with customer data, even in jurisdictions where no law requires one yet.

• Treat ransomware readiness—backups, a tested incident response plan—as a baseline operating cost, not a response you improvise after the fact.

• Build compliance and security into the annual budget as a recurring line item rather than a reaction to the first incident or the first regulator’s letter.

The specifics differ by jurisdiction—a data protection board in one country, a state attorney general in another, a sectoral regulator in a third—but the underlying pattern is the same from Brussels to Brasilia to Bengaluru. The era in which “we’re too small to be a target” or “we’re too small to be regulated” were safe assumptions is ending everywhere at roughly the same time.

The advantage, for the next few years, goes to whoever stops treating this as someone else’s problem first.

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/05/the-compliance-reckoning-small-businesses-can-no-longer-postpone/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business