I simply disagree. Small offices are some of the easiest offices to lock down - providing you know where to look.
What you lack, unfortunately, is an advocate in the user community that will allow those standards to be set. You are right, you can't just show up Monday and start editing group policies. What you can do is show the owner or financial person the cost associated with cleaning a virus, versus the cost associated (and increased productivity) with keeping a computer streamlined and protected.
Small businesses - especially in this economy - will listen to ANYONE who can tell them how to save a buck. The ding-dong receptionist who just happens to need AutoCad on her computer because she prints some stuff for the guy in the corner office needs to be protected the MOST because she's on Facebook all day playing Bejeweled.
Additionally, when you tell the financial person that she's ON Facebook all day - that may prompt an entirely separate conversation. Companies aren't fond of paying people now a days to just surf the Internet all day.
Keep on it - you're right - it's political and can be a mess. Just don't throw up your hands and say "welp, can't beat 'em, so I'll just join 'em."