Back to home

Training

trust is a choice

On the gap between fear and knowledge in Dutch small business, and why AI literacy isn't a compliance checkbox

I stand in front of a room full of small-business owners fairly often, telling them something about AI, and there’s one reaction that nearly always comes first. The fear that data leaks out. Every single time.

And then there are those two numbers. Fifty-one percent of Dutch business owners are scared of data leaks from AI. Seven percent actually know how the rules work. Both from the same study, run by the Dutch government and the KVK (the national chamber of commerce), late 2025. And together? They pretty much tell you the whole story.

The fear sits high. The knowledge sits low. And in that gap? All kinds of things happen. Just not sensible decision-making.

the gap between fear and knowledge

Three in ten business owners use ChatGPT or Microsoft Copilot by now. Professional services? There it’s 46 percent. And at that very same moment 53 percent are worried about a lack of transparency, and 52 percent about regulation and compliance. So they use it and they’re scared of it. Both at once.

One number sticks with me. Only 2 to 3 percent are actually taking any real steps around the European AI rules. The rest, nothing. More than half don’t even have plans for it.

So that’s not an adoption problem. It’s a trust problem. Look, I watch companies shoot off in one of two directions. Either they dodge AI completely, or they go at it with no controls at all. Both harmful. And both from exactly the same source: if you don’t get how a thing works, you can’t handle it in any controlled way either. So you’re left with dodging. Or gambling. There’s no third flavor.

where the fear sits, and where the risk sits

The biggest fear? That AI trains on your data. And honestly, that fear isn’t even crazy. It sits highest on customer data, and I get that too. Companies have customer data, and in today’s market that’s hugely important. Privacy. Only: it’s usually aimed at the wrong spot.

Because it’s not down to the provider. It’s down to your plan. Consumer plans use your data for training by default. Anthropic even flipped that toggle straight to on in August 2025. Small print, under a big Accept button. Business plans don’t do that: they rule out training on customer data contractually, in black and white, right there in the Commercial Terms and DPAs. Work with a party like that and it doesn’t run on your data at all, and you can just switch that training off anyway. Really sensitive stuff? Go for a European vendor, or run the model locally. Options enough.

You learn that difference in ten minutes. And still almost nobody knows it. So you get policy built on a picture that’s just wrong. While honestly, on this front, I reckon there’s a lot more to gain than there is to fear.

And meanwhile the real risk sits somewhere else entirely. A good bit less exciting, too, than some model secretly learning. Look: Samsung engineers pasted source code into consumer ChatGPT without IT catching it. Group-IB found over 101,000 devices infected with infostealers, ChatGPT credentials saved right on them. And AI agents have been led up the garden path more than once, with instructions tucked away inside emails and documents.

See what those incidents have in common? Not one was about a model quietly training on the side. Zero. Every single one was about people. About configuration. Training is not the problem in 99 percent of small-business AI incidents. The people and the settings are.

And yet not all distrust is misplaced. There’s one kind I actually do think is healthy. And it isn’t the fear for your data. It’s depending on one single model. Put your whole shop on one provider, and they change their terms, hike the price or go down for a day, then you’re standing still too. If half the world’s soon leaning on that same one model, well, you don’t want that. So there you’re allowed to be a bit distrustful: make sure you can switch. That’s not fear. That’s just spreading your risk.

article 4 is not a checkbox

And then the lawmaker walks in. The EU AI Act applies broadly to small business from 2 August 2026. For most uses the obligations are light, honestly: tell customers they’re talking to AI, make sure AI-generated image and audio is recognizable, and know yourself which AI you’ve actually got in the house. And I don’t just mean that you’ve got it. At least one person in the shop should genuinely know what each model in there is doing, and what for. With me that’s just a running list: every functionality on it, in plain language what we use it for and to what end. One shared document already covers that overview. A legally mandated register it is not. This really isn’t a six-figure project, and the calm walkthrough lives in the AI act without panic.

But article 4 of that same law asks for something else. And that gets systematically underrated. Organizations have to demonstrably work on their people’s AI literacy. Since the 2026 amendment that’s formally a duty of effort. No exam. Get the difference? It’s about the people. Not the tools.

And what the market does with that, well, you can guess. AI literacy turns into some compliance obligation. Buy an e-learning, everyone a little certificate, tick, done. Exactly the way it went with the privacy trainings before.

And right there, exactly there, the reflex misses the point. Because tools change faster than your policies. A rule your team memorizes today is already stale in three months. New feature, changed term, and just like that it doesn’t fit anymore. That’s why people have to get why the rules are there. Not just what they are. Otherwise they don’t feel when to escalate. And escalating happens to be the exact behavior that heads off incidents.

And yeah, fair’s fair. I run training on AI in small business myself. So I’ve got a stake in the conclusion putting training over tooling. Weigh that in, really. Only: those numbers up there aren’t mine. And that pattern in the incidents isn’t either.

what a business owner actually does

The good news, and it’s genuinely good news: the distance between that 7 percent knowledge and just enough knowledge is small. Five steps. No consultancy track. And this is the order I keep myself.

First, take stock. Which AI tools is your team actually using, on which plan, on which data. An hour of work, no more. And believe me, you’ll be startled by what’s already running without anyone ever really deciding on it. Then: pick one official AI package for the whole team, on the business tier. Because all those scattered personal accounts, that’s where the Samsung scenarios start. Step three, write your policy on one page. What’s allowed in AI, what isn’t, what you do when you’re not sure, and who’s ultimately on the hook. One sheet. That’s plenty.

And then step four. That one I think is the most important myself, and it’s exactly why I hang this whole piece on the why. Train your people on the why. This is the step article 4 means. And the only one that still moves along when the tools change again tomorrow. Last, get your disclosure live on time. Because from 2 August 2026 every customer has to be able to know they’re talking to AI. And then you’re there. Done.

Whoever takes these five steps suddenly belongs to a small minority. Funny really, because the bar isn’t high at all. Only: almost nobody steps over it. That’s the whole thing.

trust is a choice

People often act like trust in AI is something that has to grow on its own. As if it just shows up, if only the technology gets more mature. The vendors more transparent. The rules clearer. So: sit tight and wait.

Well, I don’t buy that. That 51 percent who fear data leaks? They’re not going to feel any calmer about the next generation of models. Fear that comes from not knowing doesn’t go away because of a better product. It goes away through understanding. Full stop.

Trust here is just a choice. You don’t feel it, you make it. You choose a plan whose terms you’ve actually read. You choose rules your team gets the why of. And you choose to know what happens to your data, instead of just sort of hoping.

And that’s why the gap between 51 and 7 percent doesn’t leave me gloomy either. Every company that closes it for itself turns fear into an informed call. And sometimes that call is still no. Also completely fine, honestly. A no from understanding is worth more than a yes from not knowing.

Trust isn’t something a vendor comes and hands you. You build that yourself. And the first brick? That’s understanding.

nlen