Small and medium-sized enterprises (SMEs) are rapidly adopting artificial intelligence (AI) to improve productivity, efficiency, and competitiveness. In many cases, however, AI adoption is outpacing the development of cybersecurity and governance capabilities, exposing SMEs to new and poorly understood risks. While existing practitioner and academic work highlights the importance of secure and responsible AI, there remains limited actionable guidance tailored to the constraints and realities of SMEs. Drawing on a three-month UK government–funded intervention involving approximately 400 SMEs in Greater Manchester, this paper translates intervention-based insights into practice-relevant managerial guidance. Using a reflective and practice-based approach. we examine how SMEs engage with AI-cyber risk when governance is framed as a managerial rather than a technical challenge. The paper distills seven practice-based insights derived from observing SME engagement with the intervention and demonstrates how lightweight, inclusive support mechanisms can strengthen AI-cyber readiness under real-world constraints. Overall, the findings reposition cybersecurity and AI governance as evolving managerial capabilities rather than static compliance exercises, offering timely insight for SME leaders navigating accelerated AI adoption.
Chen et al. (Fri,) studied this question.