AI Risk Controls

AI Tool Use, with the Risks Controlled

The short answer

AI is a tool, not a tether. We use it deliberately, for defined jobs, and we control the risks it brings: where your data goes, who approves what it produces, and what happens when a provider changes its terms or fails. Nothing we build needs a permanent connection to an AI provider to keep working.

The Problem with Permanent Connection

Many AI products are built so that their value only exists while you stay connected. Every visitor question, every document, and every answer passes through someone else's model, on someone else's terms, often priced per message.

When the provider changes its terms, its prices, or its model, your service changes with it. When it has an outage, so do you. For an organization that handles personal or sensitive information, it also means that data leaves the building every time someone types.

That is dependency, not capability.

The Risks, and How Each One Is Controlled

Each row below can be recorded in a risk register as a risk with its control.

AI tool risks and the controls we apply
RiskWhat can go wrongHow we control it
Data leaving your controlVisitor questions, documents, and content are processed on a provider's systems, outside your jurisdictionRetrieval-only answers and an air gap by default; data held in the jurisdiction you choose
Personal data exposurePersonal details typed by visitors are stored, or sent on to a third partyCommon identifiers removed before anything is stored; retention period you set; nothing sent to an AI provider by default
Inaccurate or unapproved answersAn AI-written answer misstates fees, eligibility, or compliance statusAnswers come only from approved content; regulated statements given word for word from the Verified Answer Bank; AI output stays a draft until a person approves it
Provider dependencyYour service changes or stops when a provider changes its terms, prices, or modelsBenefits kept in structures you own; answer systems work with no AI connected
Cost escalationPer-message pricing rises as use growsAI used for defined jobs, on your own provider account, with a key you can remove
Service outageA provider's downtime takes your service down with itAnswering runs on your own infrastructure and does not depend on a provider
No audit trailNobody can show where an answer came from, or who approved itEvery answer traces to a source page or an approved answer, with a named approver

Two Ways to Use AI

AI as a permanent connection compared with AI as a tool
Compared onAI as a permanent connectionAI as a tool
Visitor questionsPass through the provider's model, every timeAnswered from your own content; nothing sent by default
CostOften metered per message, rising with usePredictable: AI is used for defined jobs
Provider changes terms or pricesYour service changes with themNothing you rely on stops working
Provider outageYour service goes down tooAnswers keep working
Who approves outputsOften no one, before visitors see themA person, before anything is applied
If you disconnectLittle of the value remainsContent, approved answers, answer system, structured data, and measurement all remain

Four Principles for AI Tool Use

  1. Draft, Not Decide

    AI suggests answers, wording, and vocabulary. Every suggestion arrives as a draft for a person to approve, and nothing is applied automatically.

  2. Use Once, Keep the Benefit

    We use AI to do the heavy lifting on your content, then keep the results in structures you own: approved answers, vocabulary, and structured data. The benefit stays after the AI is gone.

  3. Air Gap by Default

    Nothing is connected unless you choose. When AI is useful, a person copies a prompt into the model of their choosing and pastes the result back. See Air Gap by Default.

  4. Connect Only When It Earns Its Place

    If a live connection makes sense for a task, you connect your own provider account, do the work, and remove the key afterward.

AI Agents Now Come with Ordinary Hosting

Not long ago, running an AI agent meant renting a separate server and building the plumbing yourself. Today it can arrive as a standard feature of a basic web hosting account, sitting alongside the file manager and the email settings.

Eco CPanel Hosting is one example. Its plans include an AI coding agent in the file manager that can read a site's files and server logs and write code, and its largest plan adds a persistent assistant for scheduled site health checks and recurring tasks. See what ecocpanel.com includes.

Nothing is switched on for you. The agent only works once the account holder connects their own ChatGPT or Claude account, an approach known as bring your own key. You choose the provider, you hold the account and its terms, and you can disconnect it whenever you like. That is the tool-not-tether principle built into the product.

AI tools in Eco CPanel Hosting plans
ToolWhat it doesPlansHow it is switched on
AI coding agentWorks in the file manager: reads site files and server logs, runs commands, and writes codeAll plansYou connect your own ChatGPT or Claude account
Persistent assistantRuns scheduled site health checks, summaries, and recurring tasks in the backgroundLargest planYou connect your own ChatGPT or Claude account

One point to weigh before connecting: what the agent sends to your AI provider is processed under that provider's terms and wherever it operates. Your hosting location decides where your files live. It does not decide where your agent's requests are processed.

What Keeps Working When the AI Is Switched Off

  • Your content, restructured so people and machines read it the same way.
  • Your Verified Answer Bank, given word for word.
  • Your private answer system, answering from your own content in retrieval-only mode.
  • Your structured data and authorship, which answer engines keep reading.
  • Your measurement, showing which visits and enquiries answer engines send you.

The Test Applied to Our Own Products

Every product we deploy passes the same test: switch the AI off, and it keeps working. See what we build.

Our products, where their data is held, and what each needs from an AI provider
ProductWhat it doesData heldAI provider
My Chat AssistantOur self-hosted answer engine, answering only from content you have approved.Your own server, in the jurisdiction you chooseNot needed. Optional help drafting suggested answers, using your own key; nothing is used until a person approves it
CQIP StaticFast static pages with answer-first structure and structured data built in.No database; pages hold only what you publishNone
CQIP Trust DeclarationStates who wrote and reviewed each page, so answer engines can verify it.Your own websiteNone
CQI Referrer AttributionShows which visits and enquiries come from AI assistants.Your own website's databaseNone
Semantic JourneyShows which pages are read, and which lead people to make contact.Your own website or serverNone
Eco CPanel HostingHosting in a named jurisdiction, for sites and answer systems.The jurisdiction you chooseNot needed. Optional AI agent tools stay off until you connect your own key

Why This Matters at Board Level

Costs stay predictable, because value does not depend on a per-message meter. Data stays in the jurisdiction you choose. Every answer can be traced to an approved source, which is what auditors and regulators ask for. And no single provider's decision can switch your service off.

The organizations that gain most from AI will be the ones that can switch it off and keep going. That is the standard we build to.

See it in practice

Built and Run by Us

My Chat Assistant

Our self-hosted answer engine is built this way: air gap by default, retrieval-only answers, and AI only when you choose to connect it.

Visit mychatassistant.com

Questions

Frequently Asked Questions

How do these controls fit our risk register?

Each risk in the table can be recorded with its control. For each deployment we provide a written description of how every control is configured, for your risk and data protection assessments.

Are you against using AI?

No. We use AI where it does a job well, such as drafting answers and suggesting vocabulary. We object to making your service depend on a permanent connection to it.

Do your answer systems work with no AI connected at all?

Yes. They run in retrieval-only mode by default, answering directly from your approved content.

Can we use our preferred AI provider?

Yes. When a connection is useful, you use your own provider account, on your terms, and you can remove the key when the task is done.

What does bring your own key mean?

You connect an AI tool to your own account with a provider such as ChatGPT or Claude, rather than a vendor's shared account. You choose the provider, you control the account, and you can remove the connection at any time.

What happens if an AI provider changes its terms or prices?

Nothing we deliver stops working. The benefits live in structures you own, not in a provider's service.

Keep reading

Start with a Confidential Chat

A no-obligation conversation with H D Fraser about how answer engines represent your organization today, and what a privacy-first approach would involve. NDA on request.