AI Just Made Scams Cheap to Personalize. What a Solo Owner Should Actually Do

A dark desk lit low with a softly glowing laptop and a metal padlock resting on the keyboard, in deep blue tones.

6 min read

Here is the number that should reframe how you think about your inbox: roughly 82 percent of phishing emails are now written with AI, and the ones that are get clicked at more than four times the rate of the old hand-typed scams. That is not a distant enterprise problem. For a solo owner, whose whole business runs through one email account and one phone, it is the most important AI story of the year, and almost nobody is writing it for you.

In the first two weeks of September 2026, every major AI lab shipped a model with serious cyber capabilities. Google, Anthropic, and OpenAI all announced cyber-focused models and safeguards within days of each other. The coverage framed it as a security-industry milestone. The part that matters for you is quieter: the same capabilities that help defenders are, in cheaper and less careful hands, making attacks easier to run at scale. Let me make the skeptic’s case for taking this seriously without panicking.

Why solo owners are the soft target now

The uncomfortable logic is this. AI has made attacks cheap to personalize, and personalization is exactly what used to protect small operators. The old scams were generic and easy to spot: bad grammar, a stranger’s name, a link that looked wrong. AI removes all three tells.

Modern AI-generated phishing produces messages that reference real projects, use the correct internal terminology, and match the writing style of someone you actually know. Attackers can now scrape your public footprint, your website, your LinkedIn, a podcast you appeared on, and generate a message that sounds exactly like a real client or supplier. When you are a one-person business, there is no IT department to flag it and no colleague to say “that doesn’t sound like Maria.” The email lands, it looks right, and you are the only line of defense.

The deepfake side is worse and growing fast. Voice cloning now needs only a few seconds of audio, the kind you happily post in a video introduction or a webinar. A cloned voice saying “hey, it’s me, can you move that payment today” is no longer a movie plot. It is a documented, rising attack.

The counter-argument, taken honestly

A fair skeptic pushes back here: is this just fear-selling? Security companies profit from making you anxious, and the internet has cried wolf about cyber threats for twenty years while most small businesses carried on fine. That objection deserves a real answer, not a dismissal.

The answer is that two things are true at once. Yes, the security industry oversells fear. And yes, the underlying shift this time is genuine, because the economics changed. What made small businesses safe before was not that they were well defended; it was that they were not worth the effort to attack individually. AI erased that. When a convincing, personalized attack costs almost nothing to generate, the “too small to target” shield is gone. You are not being targeted by a person who chose you. You are being caught in an automated net that now scales to everyone.

So the correct posture is neither panic nor dismissal. It is the boring, unglamorous middle: a few habits that cost you almost nothing and close the doors that matter. This is the same clear-eyed approach we took to the myths solo owners believe about AI and their data, separating the real risk from the noise.

What actually protects a one-person business

You do not need an enterprise security budget. You need four habits, and none of them require technical skill.

Verify money and access requests out of band. This is the single most valuable rule. Any message asking you to send money, change payment details, or hand over a login gets confirmed through a different channel than the one it arrived on. If the email says wire the deposit, you call the person on the number you already have. A cloned voice and a fake email cannot both be intercepted if you switch channels to confirm.

Turn on two-factor authentication everywhere, using an app or a hardware key, not text messages. Text-message codes can be intercepted; an authenticator app or a physical security key cannot, as easily. This one setting, applied to your email and your banking, blocks the majority of account takeovers even if your password leaks.

Slow down on urgency. Nearly every AI-driven scam manufactures time pressure, because urgency is what stops you from checking. Train yourself to treat “do this right now” as the warning sign it is. The pause is the defense.

Assume your voice and face are already public, and plan around it. If you post audio or video of yourself, accept that it can be cloned, and set a rule with anyone who handles money for you: no financial action on a voice request alone, ever. A shared code word between you and a bookkeeper costs nothing and defeats a voice clone entirely.

The tools that help, used carefully

AI is not only the threat here; it is also part of the defense. Modern email providers now use AI to filter a growing share of these attacks before they reach you, and it is worth making sure yours is switched on and current. Password managers, most of which now flag reused and leaked credentials automatically, quietly remove one of the biggest weaknesses in any solo setup. The point is not to buy a security suite. It is to use the protective features already sitting inside tools you pay for.

There is a broader lesson in this September’s news. As AI gets better at finishing whole tasks on its own, the same autonomy that helps you also helps the people trying to reach you, and not all of them mean well. The owners who stay safe will not be the most technical. They will be the ones who kept a few stubborn human habits: verify, slow down, switch channels.

The one thing to do this week

If you do nothing else, do this: turn on app-based two-factor authentication for your email account today, and set one rule that no payment or payment-detail change ever happens on a single message without a second-channel check. Those two moves, together, defend against the large majority of what AI has made cheap. The threat is real. The defense is boring. That is good news, because boring is something a busy solo owner can actually keep up.

Related reading

Have you already seen an AI-written scam aimed at your business? What tipped you off? Share it below so other owners know what to watch for.

Leave a Comment

Scroll to Top