What an AI assistant should never say on your site
The first question a careful owner asks about a website assistant is not what it can say. It is what it might say that they would have to apologize for.
A website assistant should never invent a price, give medical, legal, or financial advice, claim to be a person, or guess when it does not know. We enforce those limits by training each assistant only on the client's live website, retraining it every time the site is published, and giving it a clear way to hand off to a human.
The short list
Here is the list we put in front of every client before an assistant goes live. It is the same list for a cabinet shop, a retirement advisor, and a landscaper, with a few lines added per industry.
- No invented prices. If the number is on the site, it may quote it. If it is not, it says pricing depends on the project and offers a callback. It never estimates.
- No medical, legal, or financial advice. A retirement advisor's assistant can explain what the firm does and how to book a conversation. It cannot tell a visitor what to do with their savings. A home builder's assistant can describe the permit process in general terms. It cannot tell someone whether their fence is legal.
- Never pretend to be human. If asked, it says it is an assistant. It does not use a fake photo, claim to be at a desk, or say "let me check with my manager."
- Say when it does not know. "I do not have that on the site, but I can have someone call you" is a complete answer. Guessing is not.
- No promises the business has not made. No guaranteed timelines, no "we always," no "we can definitely." It describes what the site describes.
- No opinions about competitors, politics, or anything off topic. It is polite, brief, and steers back.
- No collecting more than needed. A name and a phone number or email. Not a social security number, not a date of birth, not a card number. If a visitor volunteers something sensitive, it does not repeat it back or store it in a note.
Why training on the live site is the real guardrail
Rules in the instructions help. But the strongest protection is what the assistant is allowed to know in the first place. Every assistant we build answers only from the client's published website. Not from the open internet, not from a general knowledge base, not from whatever the model picked up in training. If the answer is not on the site, the assistant does not have it, and it says so.
This sounds limiting. It is the point. A website is the one set of statements the owner has already approved. Every page was written or signed off by someone at the business. When the assistant quotes from it, it is quoting the business. When it cannot find an answer, that is a signal that the site is missing a page, which the owner hears about in the morning recap.
Retrain on publish, not on a schedule
A site changes. A service gets added, a price gets updated, a town gets dropped from the service area. If the assistant is working from last month's copy, it is now confidently wrong. So we tie retraining to publishing. The moment a page goes live, the assistant re-reads the site and the old version is gone. There is no window where the site says one thing and the assistant says another.
The same rule applies in reverse. If an owner removes a page, the assistant forgets it. An old promotion that was deleted from the site cannot be quoted by the assistant a week later.
The hand off
Every assistant has an exit. When it hits a question outside the site, a visitor who is frustrated, or anything that smells like a complaint or an emergency, it stops trying to help and gets a person involved. In practice that means collecting a name and a number, telling the visitor who will reach out and roughly when, and creating a task for a specific person with a due time. For a few clients it also sends a text to the owner right away.
The hand off is not a failure of the assistant. It is the assistant doing the most useful thing it can when it reaches the edge of what it knows.
How we test the limits
Before launch we try to break it. We ask for prices that are not published. We ask legal questions. We tell it we are having a medical emergency. We ask if it is a real person. We type in a fake card number and see what it does with it. We ask it what it thinks of the competitor down the road. Then we read every answer with the owner. If one is wrong, we fix the rules and run the set again. The set stays with the client, and we run it after every major change.
Every assistant we have shipped, for businesses from Delray Beach up through Palm Beach County, is held to this same list. The owner gets to be comfortable not watching it, and that comfort is the product.
Questions people ask
What does the assistant say when it does not know the answer?
It says so plainly, tells the visitor it can have someone from the business follow up, and collects a name and number. It does not guess and it does not search the internet for an answer the business never approved.
How does the assistant stay accurate when the website changes?
It is retrained the moment a page is published, not on a weekly schedule. The old version is replaced right away, so there is no window where the site says one thing and the assistant says another. Removed pages are forgotten the same way.
Will the assistant ever claim to be a real person?
No. If a visitor asks, it says it is an AI assistant for the business. It does not use a fake photo or pretend to check with a manager. The name it carries is for clarity, not disguise.
Want this done for your business?
Two minute intake. A real person reads every one and replies within a business day.
Keep reading
What an AI assistant on a website actually does all day
What a website AI assistant does all day for a Florida service business: page matched openers, tap qualifying, price callbacks, CRM leads and a morning recap.
AI at workHow we pick an AI model for a client project
How a Delray Beach studio picks an AI model for a client project: the job, speed versus depth, cost, privacy, and why one product often uses several models.
AI at workOpenAI, Anthropic, Google and the rest: what each is for when you are building
A builder's map of OpenAI, Anthropic, Google, Meta, xAI, DeepSeek and Mistral: what each is known for, hosted versus open models, and how we choose per job.