MANILA, Philippines — Artificial intelligence is rapidly becoming a business tool for Philippine micro, small and medium enterprises (MSMEs), promising faster operations, lower costs and better customer service. But as adoption accelerates, businesses with limited budgets and technical resources are also confronting new risks involving data privacy, cybersecurity, implementation costs and the lack of AI expertise.
The concern comes as AI moves beyond experimentation and into everyday business functions such as marketing, customer support, document preparation, pricing, accounting and other administrative tasks.
A recent survey of Philippine businesses commissioned by Alibaba Cloud found that 91% of respondents had a positive view of AI adoption, while 57% said they were already exploring or implementing the technology. Yet 51% identified data privacy and security as the biggest obstacle, followed by implementation costs at 41%.
That creates a complicated situation for smaller enterprises: AI can potentially reduce the cost of doing business, but deploying it without adequate safeguards can expose companies to risks that they may not have the resources to manage.
The cybersecurity problem
For smaller companies, one of the biggest concerns is what happens to sensitive information when employees begin using AI-powered services.
Customer records, financial information, business plans, supplier details and other confidential data can potentially pass through digital systems. As businesses become increasingly connected, their exposure to cyberattacks can also grow.
Cisco previously reported that only about 45% of Philippine enterprises had the cybersecurity measures needed to protect data used in AI models, highlighting the gap between AI adoption and security readiness.
The OECD has similarly warned that SMEs face a cybersecurity readiness gap. Its 2026 report found that 46% of surveyed SMEs had no or only minimal security measures, while 22% had already experienced a digital security breach.
For a large corporation, a major technology investment or cybersecurity program may be easier to absorb. For a small enterprise operating with tight margins, the financial and operational consequences of a data incident can be much harder to manage.
AI isn’t simply a plug-and-play investment
Another challenge is the cost of adopting AI properly.
While many generative-AI services are inexpensive or even free at entry level, serious business deployment can involve software subscriptions, cloud infrastructure, cybersecurity protections, employee training, integration and ongoing monitoring.
This is particularly important because simply purchasing an AI tool does not guarantee productivity gains.
The Philippines’ DOST has identified lack of awareness as a major barrier preventing MSMEs from using AI effectively. In August, DOST-Caraga partnered with Limitless Lab to train AI-capable personnel who can subsequently help businesses adopt the technology. The program aims to contribute to a national effort supporting 17,500 Philippine MSMEs by 2027 under the ASEAN Foundation’s AI for MSME Advancement program.
The Philippines is pushing AI adoption anyway
The risks have not stopped the government from encouraging businesses to experiment with AI.
Under the Philippines’ 2026 ASEAN chairmanship, Southeast Asian leaders adopted an agenda promoting AI-powered growth for MSMEs. The proposed AI MSME Hub is intended to give smaller businesses access to AI tools, training and advisory services.
DICT and LandBank have also been working on AI tools designed to help MSMEs prepare business plans, comply with government requirements, set prices, review contracts, produce marketing materials and identify financing opportunities.
The push illustrates the other side of the AI story: policymakers see the technology as a way for smaller companies to narrow the productivity gap with larger competitors.
But the technology gap could become a security gap
The challenge, therefore, isn’t necessarily whether small businesses should use AI. It is how they use it.
In June, Inquirer reported that the Philippines was moving toward a broader AI governance framework, with policymakers considering rules covering areas such as high-risk AI systems, accountability and human oversight.
Separately, proposed AI legislation discussed in July included measures designed to encourage AI development and adoption while imposing stronger safeguards on high-risk applications.
For MSMEs, the practical issue is increasingly straightforward: AI can automate work and improve efficiency, but businesses need to know what information they are feeding into AI systems, who can access the resulting data, how outputs are verified and what happens when an AI system makes a mistake.
The opportunity—and the catch
AI could give a small retailer, startup, restaurant, professional service provider or family-owned company access to capabilities that once required expensive software or specialized personnel.
But the same technology can also introduce new vulnerabilities if companies adopt it without employee training, data controls and human oversight.
Earlier Inquirer reporting on Philippine SMEs noted that AI could help automate marketing, customer service and administrative work, while stressing the importance of upskilling workers and establishing workplace guardrails.
The emerging picture is therefore not simply an AI-versus-small-business story.
It is a race between AI adoption and AI readiness.
For Philippine MSMEs, the businesses that benefit from the AI boom may ultimately be those that can combine automation with something technology cannot replace easily: sound judgment, proper data protection and people who know when an AI-generated answer should—and should not—be trusted.