Four risks worth taking seriously
Scepticism here is healthy. These are the risks that actually matter, stated plainly, before we get to the controls.
Wrong facts. An AI that guesses a price, a date, or a policy can put something untrue in front of a customer, and it will do it with total confidence. On its own, a general chatbot has no reliable sense of what is true about your business. This is the risk people picture first, and they are right to.
Wrong tone. A reply can be accurate and still land badly. Too stiff, too casual, or tone-deaf to a thread that has already turned tense. Tone is where a careless message does quiet damage to a relationship you have spent years building.
Privacy. Customer communication involves customer details, so it matters what the system can see and where that information goes. A setup that is wired to everything by default is a bigger exposure than one that only ever sees what you connect it to.
Silent over-automation. The real disaster is rarely one bad email. It is a system left to send unsupervised, quietly firing off dozens of messages before anyone notices something is off. Speed without a human in the loop turns a small mistake into a big one.
Approval-first removes most of the danger
Most of those risks share one fix: a person approves every message before it is sent. In an approval-first setup the AI drafts, prepares, and reminds, but nothing that reaches a customer leaves without your sign-off. You stay the one who presses send. That single rule turns "the AI emailed a client something wrong" into "the AI drafted something I corrected in ten seconds, then approved." The mistake never reaches the customer, because you are the last step, not the AI.
Start read-only, earn trust in stages
You do not have to hand over everything on day one, and you should not. A sensible setup starts read-only: it can see the sources you connect and draft from them, but it is not given the keys to send or change anything until you have watched it work. Trust is earned in stages. As you see that the drafts are good, you widen what it is allowed to prepare. You are always the one deciding how far it goes.
Where your information actually goes
It is worth being precise about this, because a vague answer is where trust breaks. Your setup runs on your own computer, and your business knowledge lives in files you control. The AI itself runs through Claude Code or Codex, signed in to your own Anthropic or OpenAI account. There is no third-party API key in the middle, and nothing is routed through us. The connection is yours.
Two things make that genuinely safe rather than just tidy. On a business subscription, Anthropic and OpenAI do not train on your data - that is part of what you are paying for. And where information is sensitive, it can be anonymised before it is sent. On top of that, the setup only touches the sources you choose, starts with the least access it can, and never sends a customer anything without your approval.
What we would not let it handle
Some conversations should never be automated, and we will tell you which. Complaints that need a genuine apology, bad news, anything legal or contractual, and the delicate moments in a client relationship belong with a person. An AI setup is there to take the routine volume off your plate - the quotes, the confirmations, the questions you answer a hundred times - so you have more attention for the conversations that actually need you. Using it to dodge the hard conversations is exactly how businesses get burned.