Abstract
Generative artificial intelligence is rapidly entering small and medium-sized enterprises through public chatbots, AI-enabled office applications, programming assistants, customer-service systems, security tools, and autonomous software agents. These technologies offer substantial productivity advantages while simultaneously changing the cybersecurity environment. Generative AI lowers the cost of producing personalized phishing messages, accelerates reconnaissance, assists vulnerability analysis, and creates new risks involving prompt injection, sensitive-information disclosure, model and data poisoning, insecure AI supply chains, shadow AI, and excessive agent privileges. At the same time, AI can improve phishing detection, vulnerability remediation, code review, security-log analysis, threat-intelligence processing, and incident triage. This paper examines whether generative AI increases or decreases overall cybersecurity exposure for SMEs. The evidence suggests that AI should be understood as a force multiplier for both attackers and defenders. SMEs are particularly vulnerable because adoption of inexpensive AI tools frequently occurs faster than the development of governance, access controls, cybersecurity expertise, and data-protection procedures. Security outcomes therefore depend on whether AI is integrated into identity management, data governance, least-privilege controls, human approval, logging, vendor management, and incident response. Generative AI does not inherently make SMEs less secure, but uncontrolled shadow AI and highly privileged autonomous agents can create new pathways for compromise.
References
European Union Agency for Cybersecurity. (2025). ENISA Threat Landscape 2025.
Heiding, F., Schneier, B., Vishwanath, A., Bernstein, J., & Park, P. S. (2024). Devising and detecting phishing emails using large language models. IEEE Access, 12, 42131-42146.
National Institute of Standards and Technology. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1).
OECD. (2026). Empowering SMEs in the age of AI: The 2026 OECD D4SME Survey.
Open Worldwide Application Security Project. (2025). OWASP Top 10 for LLM Applications 2025.
Verizon. (2025). 2025 Data Breach Investigations Report.
Verizon. (2026). 2026 Data Breach Investigations Report.

This work is licensed under a Creative Commons Attribution 4.0 International License.
Copyright (c) 2026 Mihai Cosmin Poenaru