Is an AI chatbot safe for my business?
- ai
- chatbots
- security
- privacy
When I suggest a chatbot to a small business owner, the reply is usually some version of “isn’t AI dangerous?” They’ve read about one making things up, or leaking something, or being talked into saying something awful. Some of them have read that it’s going to take over the world.
Fair. Some of the fears are real, and I’ll say which. Others are mostly wrong for the kind of chatbot a small business would put on its website, and I’ll say why. I run one on this site, so I can show you how it behaves rather than describe a brochure.
“It will make things up”
This one is real. A language model writes the most plausible next sentence, and plausible is not the same as true. Ask it something it doesn’t know and it may answer anyway, fluently.
And you own what it says. In February 2024 a Canadian tribunal ruled on Moffatt v. Air Canada. The airline’s chatbot had told a grieving customer they could book at the full fare and claim the bereavement discount afterwards, within 90 days. The airline’s own policy page said otherwise. Air Canada argued, in the tribunal’s words, that the chatbot was “a separate legal entity that is responsible for its own actions”. The tribunal didn’t buy it: “It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot.” The airline paid C$812.02 in the end. Small money, large precedent.
So the fear is right. Its mistake is the assumption that a business has to accept whatever the model feels like saying, when most of what a chatbot on a small firm’s website needs to say can be written down in advance by a person who knows the answers.
On my site, most questions never reach a model at all. They’re matched in the browser against a fixed set of answers I wrote and checked myself. Only what that set can’t handle goes on to the model, and the model gets a short brief about me with an instruction to refuse rather than guess. It’s told never to state a day rate or a delivery date, because a confident wrong number is the worst thing it could produce. The greeting tells visitors it’s an assistant and not me, and that anything important is worth confirming.
That cuts the risk. It doesn’t remove it. If your chatbot is going to quote prices, write them down for it and test it against awkward questions before it goes live. If it would ever need to give legal or medical advice, don’t build it.
“It will train on my customers’ data”
Mostly not, if it’s built on a business API rather than a free consumer app. Anthropic, whose model runs behind my chatbot, says on its privacy centre (updated 18 August 2026) that “by default, we will not use your inputs or outputs from our commercial products” to train its models. The exceptions are explicit: feedback a user deliberately sends, or a customer opting in.
That’s one vendor’s stated policy, and it’s the thing to read before you pick one. Consumer plans run under different terms.
The part that is true is that the data still leaves your website. Whatever a visitor types goes to a third party to be answered. My privacy page says exactly that, names the company, and asks people to keep personal details out of the chat box and use the contact form instead. I keep no copy of the conversation. Your privacy notice needs the same paragraph, written for what your chatbot actually does.
“Somebody will hijack it”
Real, and it won’t be fixed soon. The NCSC’s view is blunt. In a December 2025 post it says that because a model draws no hard line between data and instructions, “it’s very possible that prompt injection attacks may never be totally mitigated”. I’ve seen it myself. A model I was testing obeyed an instruction hidden in a text file, eight runs out of eight, and told nobody.
The NCSC’s 2023 post on building with language models gives the two ends of what can go wrong. At the mild end, a company chatbot coaxed into saying “upsetting or embarrassing things” that ended up on social media. At the bad end, a banking assistant reading a booby-trapped transaction and sending the customer’s money to the attacker.
The difference between those two isn’t the model. It’s what the model is connected to. The same NCSC post on prompt injection says the job is “reducing the likelihood or impact”, and impact is the part you control.
Mine is connected to nothing. It has no tools and no database, it can’t read an inbox, and there is no route from it to an order, a booking or anybody’s email address, because I never built one and the model can’t build one for itself. It sees the brief, the visitor’s message and the last few turns of the conversation. A message is capped at 500 characters, and the server allows 15 messages per visitor every ten minutes, which also stops anybody running up my bill. The worst a hijacker can do is make it say something silly, in a screenshot of their own browser. I’d rather that didn’t happen, but nobody loses money.
The moment a chatbot can act (refund an order, change a booking, read a customer record) it’s a different build with a different price. Every action needs a check in code that the model can’t talk its way past. That’s the design I’d insist on, and it’s slower to build.
“AI is going to take over”
I’m not going to tell you the long-run arguments about powerful AI are nonsense. Serious people make them. But they are not about a box on your contact page that answers questions about your opening hours. That box takes text in and sends text out. It can’t do anything you haven’t wired it to do.
The risks on a small business website are much more ordinary. A wrong answer. An embarrassing answer. Customer details typed somewhere you didn’t plan for. All three are dealt with by how it’s built, and none of them by hoping.
When I’d tell you not to bother
If your customers ask the same ten questions, a well-written FAQ page answers them better and costs nothing to run. Write those ten down first. If a page covers them, you don’t need a model.
If you’re in a field where a wrong answer is a regulatory problem, keep the bot to directions and opening hours or leave it out.
If you want one anyway, it’s a software build: a fixed price, quoted after a free scoping call, never a day rate. The code and the account are yours, the model provider is named in your privacy notice, and I test it against the attacks above before it goes live. I’m one person and take on a few projects at a time. I’ll also tell you on the first call if the honest answer is a FAQ page.
