Software & AI case study

How We Protect a Public AI Website From Misuse and Unexpected Costs

We limit request size and frequency, check for attempts to trick the AI into ignoring its rules, and block unsafe answers from becoming trusted website information.

Built in our own support systemHuman-reviewedSoftware & AI for business
How We Protect a Public AI Website From Misuse and Unexpected Costs — Your IT and Tech Mates Software & AI case study
Public AI security controls protecting against prompt injection, abuse and unnecessary provider costs

Quick answer

We limit request size and frequency, check for attempts to trick the AI into ignoring its rules, and block unsafe answers from becoming trusted website information.

The practical problem

A public AI feature receives genuine customer questions and hostile input through the same box. Some people or automated tools may try to overwhelm it, make it ignore instructions or deliberately increase paid usage.

What we built

We put a separate safety layer in front of outside AI services. It limits input and output size, checks for suspicious attempts to override the rules, limits repeated requests and keeps visitors from choosing the AI service or spending level.

How the workflow works

  1. Customer input is cleaned and checked against firm size limits.
  2. The website checks for suspicious wording that tries to make the AI ignore its rules.
  3. Request limits prevent one source from repeatedly consuming outside AI capacity.
  4. The server—not the browser—decides whether outside AI is allowed and which option can be used.
  5. Returned text is cleaned before it is shown.
  6. Unsafe AI output is not saved as trusted reusable information or published automatically.

Where AI is useful

AI can still help with suitable customer questions after the safety checks allow the request to continue.

Where AI is not allowed to decide

A visitor cannot turn off the controls, choose a more expensive AI service, reveal private instructions, approve work or make AI output become public website fact automatically.

Security, privacy and cost controls

If important request-limit information is damaged, the safer default is to block extra outside AI work. Passwords, API keys and private service addresses stay private, and public answers should not reveal hidden internal reasoning.

What another small business can take from this

Before launch, decide the maximum input, output, request rate, simultaneous usage, spending limit, safe fallback and which AI outputs will never be trusted automatically.

What this does not prove

No filter can guarantee that a public AI feature will never receive a new kind of malicious input. The goal is to limit what a bad request can do and keep important business decisions outside the AI feature.

Part of our smarter website project

This implementation story is one part of a larger Your IT and Tech Mates project exploring how practical AI, automation, trusted business knowledge and human-controlled workflows can work together.

Explore the complete smarter website project

Frequently asked questions

What does “trying to trick the AI” mean?

It includes wording intended to make the AI ignore its safety or business rules.

Can visitors choose a more expensive AI service?

No. AI service choice and spending limits stay on the server.

What happens to unsafe AI output?

It is blocked from becoming trusted reusable website information or automatically published content.

Are private prompts or API keys shown to customers?

No. Private instructions, credentials and service addresses stay private.

Can these controls stop every possible attack?

No single filter can. The design uses several limits and keeps the AI’s authority narrow so one bad prompt cannot become a business decision.

Related Your IT and Tech Mates help

Could a similar workflow help your business?

Tell us how the process works today. We can look at whether better website logic, automation, custom software, AI—or something simpler—would be useful. A person reviews the request before any scope or price is agreed.

Start QuoteMe