AI for Small Business: What to Automate First
Cicero Campelo, CISSP
August 1, 2026 · 12 min read
Part of our guide to AI for startups.

Table of contents
- What AI for small business actually means now
- Start with the work that is already queued and never gets done
- Automate the back and forth, not the craft
- The free distribution channel most small business owners already have
- Why the team changes faster than the tools
- The order to adopt AI in a small business
- The security questions small business AI adoption skips
- What to do this week
- Sources
- Frequently asked questions
Most advice about AI for small business is a list of tools. That is the least useful part. What an owner actually needs is an order: which job goes to an agent first, which one should stay human for now, and what breaks when you move too fast.
A five-minute talk at Y Combinator's Root Access gives you that order from someone running a real business rather than selling software. Siddhi Mittal co-founded yhangry, a London marketplace that sends private chefs to people's homes and partners with vacation rentals so their guests can book one too. She studied computer science with an AI focus at Columbia and spent about six years trading at Barclays, latterly in credit, before leaving finance to start the company with co-founder Heinin Zhang, as her Y Combinator founder profile records. In the talk she puts the business at roughly 50 million in GMV and says the goal is to grow that tenfold this year, then walks through what happened when every part of the company went to agents.
What AI for small business actually means now
AI for small business means using AI to complete recurring operational work rather than to answer questions on demand. In practice the phrase covers two very different things. One is a chat subscription you open when you remember it, which produces answers. The other is agents that hold a defined job and finish it while you do something else, which produces work. The team building Gusto's AI teammate for small businesses made the same observation from the vendor side: owners mostly treat AI as a glorified search engine, asking it things instead of handing it work, which is the gap their AI co-founder product was built to close.
Mittal's version is the second kind, and the pattern repeats across three areas of her company: engineering, product, and growth. In each one the agent takes over work that was already queued, already repetitive, and already costing the business money by sitting there. That is the practical shape of everything on the AI for startups pillar, applied to a company with a normal headcount and no research budget.
Start with the work that is already queued and never gets done
Her first example is engineering, and it is the cleanest illustration of where to begin. She was three weeks into maternity leave in January when she looked at the bug backlog. The company was pointed at higher-return initiatives, so the small stuff never moved: "what eventually gets dropped are tiny little bugs, the really annoying ones that our developers just never get to."
The company built an autonomous bug fixer in less than four days. Her reported result: "Literally 25 plus bugs fixed in week one and shipped." She puts one-shot bug fixing at 60 to 70 percent today and is upfront that the benchmark is contested. The problem she names is not model quality. It is supply of context, and the open question she leaves the room with is "how we can feed it enough context such that it's self-improving."
If you do not have a bug backlog, you have its equivalent. Every small business carries a queue of jobs that are individually trivial and collectively expensive: review replies nobody writes, quotes nobody follows up, listings that go stale, refunds that sit for a week, the same five questions answered by hand every morning. That queue is where AI for small business actually starts paying, for three reasons. The work is already defined, so you do not have to invent a specification. Nobody is doing it today, so a 60 to 70 percent agent beats the status quo instead of competing with a human who is better. And the failure mode is cheap: a clumsy draft you rewrite, not a lost customer.
The constraint she names is the one that decides whether any of this works. An agent that can see your ticket history, your past replies, your policies, and your data fixes things. An agent handed a prompt and nothing else guesses. That is the entire discipline behind context engineering for AI agents, and it is where most small business pilots quietly die.
Automate the back and forth, not the craft
Her product example matters more for owners, because it says what not to automate.
Booking a chef today is a sequence of steps and messages: find someone, ask about the menu, ask about dates, wait, adjust, confirm. Customers drop out along the way. Chefs lose hours to it, and she says they are "wasting so much time on admin, like sending the same stuff over and over and over again." Her verdict on the whole flow is blunt: "There is no reason for this back and forth to take days."
The answer was already sitting in the company's own records. They know what chefs respond to and what customers like, she says, and they had simply never used it to make the match instantly. So the AI product aims at the coordination layer rather than the cooking. The chef still cooks. The agent removes the messaging.
She is also honest about where it is stuck, which is the part most case studies leave out. Chefs validated the idea and want it. It still has not shipped, because in her words "the chef's side is too divergent": some are precise about what they want, others will ask anything at all, and the team has not found the smallest version that covers that spread. Her own summary is one line: "It's just not good enough to ship."
Take both halves seriously. Coordination overhead is the highest-value thing an agent can absorb in a service business, because it is pure loss. Nobody is paying you for the fourteenth message. But the open-ended side of a two-sided flow is genuinely hard, and shipping a weak version of it damages the supplier relationship the whole business rests on. The same asymmetry shows up in AI for field service, where answering the phone is worth thousands and answering it badly is worth less than nothing.
The free distribution channel most small business owners already have
The third example costs nothing and has no software in it, which is why a small business can copy it this month.
Mittal noticed that almost nobody around her could explain AI agents in plain language, and that she could: "no one has a clue as to what's going on in this whole world." So she stopped pitching her company to conference organizers and offered to teach their audiences how to build AI agents in 30 minutes instead. They said yes immediately. By her account the swap earned about 50k worth of conference slots for free, and the teaching deck itself runs through her company's affiliate integration and demos the new product. People photograph the slides and post about the value afterward.
That is founder brand with the vagueness removed. Her definition: "You just do things you are really good at, get a lot of attention and funnel it back to your company." What she is trading on is a computer science background in AI and the ability to explain the subject in plain English, and she gives the explanation away for free.
You have a version of this. You know something specific and current that your customers and your peers do not: how your trade actually prices jobs, what changed in your local market this year, what you learned wiring agents into your own operations. Mittal's evidence that the demand is there is that every organizer she offered it to said yes immediately. That is a distribution channel priced in preparation time rather than ad budget, which is the same logic that lets a solo founder compete with a staffed team.
Why the team changes faster than the tools
"Every single area in our company, people are doing AI agents or making sure their workflows are AI native," she says. Getting there took two moves that have nothing to do with which model you pick.
The first is people, and she is unusually direct about it. She says she fired her tech lead after finding that he did not know what skills were, one of the basic building blocks of current agent tooling, and that "he was the ceiling in our company." She hired a new head of engineering within the week. She also says she probably needs to "kill my human empathy a little bit more, a little bit faster."
Take that as what she says, not as a template to copy. The transferable part is the diagnosis rather than the speed: in a company this size, one person who has stopped learning caps what everybody else can do, and that cost compounds every week you leave it. The empathy line is worth pushing back on. Acting quickly on a role that is blocking the company is a decision you can make with care, notice, and a fair exit. Treating your own discomfort as the thing to remove is how founders end up with a team that stops telling them the truth, which is the one input agents cannot replace.
The second move is a learning loop. She runs weekly agentic labs with her head of engineering, because "everyone has a different learning curve right now and it's really kind of wild," and because you cannot tell from the outside who is actually good: "people are saying they're building agents, but you just don't know how good they are." They draw the workflows out, feed the session transcripts to Claude Code, and hand the team back diagrams everyone can follow.
That is the real bottleneck for a small business going all in. Not the tools, which are cheap and improving monthly. The spread of skill inside a small team, which is wide, invisible, and closes only if somebody puts it on the calendar. It is the same muscle behind building an AI-native company, and the reason going all in on AI is a management program before it is a technology program.
The order to adopt AI in a small business
For a non-technical owner, the sequence in her talk generalizes cleanly.
- Write down the queue. List every recurring job that is already defined and never gets done. Rank by how often it repeats, not by how impressive it would be to automate.
- Give context before autonomy. Assemble what a competent new hire would need to do that job: past examples, your policies, where the data lives, what a good answer looks like. Most failed pilots are context failures wearing a model costume.
- Time-box the first build to a week. The yhangry bug fixer took under four days. If your first agent needs a quarter, you picked the wrong job.
- Count shipped outcomes. Bugs fixed and messages avoided, not demos given. An agent that produces drafts nobody uses is a cost.
- Book the weekly hour. Everyone shows what they built and how they know it works. This is how you find out who is genuinely ahead and who is repeating vocabulary.
- Fix the ceiling. If one person is blocking the rest, help them move or move the role. Do it with care and do it early, because the gap widens monthly.
The security questions small business AI adoption skips
I write this as a CISSP, and the security gap in small business AI adoption is not exotic. It is that agents get handed real access before anyone decides what real access should mean. A booking agent sees customer names, home addresses, phone numbers, dietary and allergy information, and payment details. A bug-fixing agent has write access to your product. A personal assistant agent wired into your messaging apps, like the open-source OpenClaw setup Mittal mentions running over Telegram voice, sits on top of your entire communication history.
Four things, answered in writing, before an agent touches anything that matters: what data leaves your systems and reaches a model provider, and whether it is retained or used for training; what the blast radius is when the agent is wrong or is manipulated by text it reads, meaning whether it can merge code, issue refunds, and email customers or can only draft; who genuinely reviews its output, and whether that review is real or a rubber stamp by week three; and what you tell a customer when an agent rather than a person is answering them. A small business does not need a security program. It needs those four answers before the second agent goes live, because the first one always becomes ten.
What to do this week
- List every recurring job in your business that is already queued and never gets done, then rank by frequency rather than by how impressive automating it would sound.
- Take the top one and give an agent the context a new hire would need: past examples, your policies, and access to where the data actually lives. Budget a week.
- Find the coordination step where customers or suppliers drop out, count the messages it takes today, and aim to get it to one exchange.
- Book one talk, workshop, or local meetup where you teach the thing you know that your market does not, and put your product in the demo instead of the pitch.
- Write down the four security answers for every agent already running, and be honest about whether the person who is stuck is being helped or is quietly capping the team.
Running a small business on agents is not a tool purchase. It is an operating decision about which work leaves human hands, in what order, and under what controls. That operating picture is exactly what we teach in the AI Operating System for Startups.
Sources
- How a Private Chef Startup Went All In on AI Agents (Y Combinator, Root Access), the talk this article distills, on the bug fixer, the booking product, the conference swap, and the team changes.
- Background on yhangry and its founders: Forbes on the two co-founders leaving finance for food and the short-term rental partnerships, TechCrunch on the 2021 seed round, and the Y Combinator company and founder profiles, which carry both founders' bios in their own words. Identity links: Siddhi Mittal, computer science with an AI focus at Columbia and about six years trading at Barclays, latterly in credit, and Heinin Zhang, philosophy and economics at the London School of Economics and a career at Goldman Sachs and then Barclays before yhangry.
- Solving the Blank Canvas Problem: Gusto's AI Co-Founder (Y Combinator) for the observation that small businesses often use AI as a search engine rather than handing it work.
- OpenClaw, the open-source personal AI agent that runs through messaging apps, for the tool Mittal mentions using over Telegram voice.
Frequently asked questions
What is AI for small business?
AI for small business means using AI to actually complete recurring operational work rather than to answer questions on demand. The weak version is a chat subscription an owner opens when they remember it. The strong version is agents that hold a defined job and finish it: clearing a backlog of small fixes, replying to routine customer messages, chasing quotes and follow-ups, reconciling records, or matching supply to demand from data the business already has. The practical difference is whether the AI has enough context about your business to act without a human writing the whole answer first.
What should a small business automate with AI first?
Start with the queue of small jobs that are already defined and never get done, not the impressive-sounding project. Every small business has one: review replies nobody writes, quotes nobody follows up, stale listings, refunds sitting for a week, the same five questions answered by hand every day. That work is the right first target because the task is already specified, an imperfect agent beats nobody doing it at all, and the failure mode is cheap to correct. Siddhi Mittal of yhangry started exactly there: her company pointed an agent at the tiny bug backlog its developers never reached and shipped more than 25 fixes in the first week.
Do you need a technical team to use AI agents in a small business?
You need someone who will keep learning, which is not the same as a large engineering team. The bottleneck in small companies is rarely the tools, which are cheap and improving monthly. It is the spread of skill inside the team, which is wide and invisible unless someone schedules time to close it. Siddhi Mittal, co-founder of the London private chef marketplace yhangry, runs weekly sessions with her head of engineering for exactly this reason, and says that people claim to be building agents while nobody can tell how good those agents are. A weekly hour where everyone demonstrates what they actually built is a better investment than another tool.
What are the security risks of running AI agents in a small business?
The main risk is handing an agent real access without deciding what real access means. A booking agent sees customer names, addresses, phone numbers, dietary information, and payment details. A coding agent has write access to your product. A personal assistant agent wired into your messaging apps sits on your whole communication history. Before an agent goes live, answer four questions in writing: what data leaves your systems and reaches a model provider and whether it is retained, what the agent can do if it is wrong or is manipulated by text it reads, who genuinely reviews its output, and what you disclose to customers when an agent rather than a person is replying.
Build your AI Operating System
A practical course to grow with AI, build internal tools, and operate safely. v1.0 launches August 31, join the waitlist.