← All posts
July 23, 2026The Thursday ForgeLessons

Secure from what?

When I taught my AI security class for the Wyoming SBDC, I displayed three example questions to start out the class:

  1. Is this software secure?
  2. Is my CRM secure?
  3. Is free tier AI secure?

All fair questions. And all missing the same word. Secure from what?

Here's an embarrassing story about me. One day I was deep in a work session with Claude Code when my computer crashed. My first thought: hack. So I went and checked which devices were logged into my Claude account, and there it was. A device out of Denver I did not recognize.

I booted every device off the account and changed my password as fast as I could type. Logged back in. The Denver device was there again. Booted everything a second time, logged back in, and by now I was freaking out. Literally shaking. All I could think was "wow, this guy is good."

Then I did some more research. When my phone is on LTE, its traffic routes through Denver. The mystery attacker was my own phone. It was me the whole time, and I had spent an hour chasing myself in circles like a dog chasing its own tail.

I tell that story in every class for a reason. It wasn't a real attack, but the feeling was absolutely real, and it was scary to feel that way. If you've ever had that spike of dread about your business's tech, I'm not going to tell you you're being paranoid. I've been there, shaking at my desk over my own cell phone.

That feeling was real. It just had the wrong shape.

A monster in the dark is terror. A monster in the light is a to-do list.

"Is AI secure?" keeps the monster in the dark, because it's unanswerable. No tool on earth is just "secure." Your truck isn't secure. Your office isn't secure. They're secure against specific things you've thought about: you lock the doors, you don't leave the keys in it, you know which neighborhoods to park in.

AI is the same. When you name the actual threats, each one turns out to have a boring, doable answer:

  • Afraid your data gets used to train someone's model? That's a settings-and-plan question. Business tiers of the major AI tools let you turn training off. Takes five minutes to check.
  • Afraid an employee pastes something sensitive into a free chatbot? That's a policy question. Decide what categories of information never go into an AI tool, write it down, tell your team.
  • Afraid of scammers using AI against you? That's the big one, honestly, and it's mostly about phishing. It deserves its own post, and it's getting one next Thursday.

None of those are terrifying. They're chores. The fear only survives as long as the question stays vague.

So that's the whole first lesson from the class: stop asking if AI is secure. Ask what you're actually afraid of, out loud, one item at a time. Then turn the lights on and look at it.

The monster becomes a to-do list. And to-do lists are something a business owner knows how to beat.

-Thayne

Got a task like this eating your week?

Tell me who you are and my AI assistant Ember researches your business before we ever talk. No call required.

See what I'd build for you