Why do some small businesses feel scammed by AI agencies?
26 July 2026
Why do some small businesses feel scammed by AI agencies?
The problem is rarely that AI itself is fake. The problem is a gap between what was sold and what was delivered. A £5,000 to £30,000 AI project can feel like a scam if the buyer receives prompts, Zapier-style automations, a chatbot demo or a repackaged SaaS tool but was led to expect a secure, integrated, business-specific system.
Most small businesses do not feel scammed because an AI project failed once. They feel scammed because the agency made the work sound bespoke, strategic and technically serious, then delivered something the owner could have pieced together with ChatGPT, Make, Zapier, a chatbot plugin and a few hours on YouTube.
That distinction matters. A simple automation is not a scam if it is sold as a simple automation. A prompt library is not a scam if it is sold as a prompt library. A low-code workflow is not a scam if the agency explains the tooling, limitations, ownership and support. The trust problem appears when a cheap, fragile or generic setup is sold as custom AI transformation.
For UK small businesses, the money is not trivial. A basic AI audit might cost £2,000 to £5,000. A focused workflow build might cost £5,000 to £25,000. A wider implementation with CRM, documents, email, support workflows and reporting can run £25,000 to £75,000 or more. Monthly support often sits between £1,500 and £8,000. At those prices, a buyer is entitled to expect visible engineering work, risk control, documentation, testing and a commercial result.
The wider market makes this worse. The GOV.UK Cyber Security Breaches Survey 2025/2026 found that around a third of businesses and charities, 31%, were using AI, adopting it or actively considering it. But of that group, only around a quarter of businesses, 24%, said they had cyber security practices or processes in place to manage risks from AI technology. Source: GOV.UK Cyber Security Breaches Survey 2025/2026.
That means buyers are interested, but many are not yet equipped to challenge the detail. Weak agencies thrive in that gap.
The most common route to disappointment is a strong demo. The agency shows an assistant drafting emails, summarising documents, answering customer questions or moving data between systems. It looks impressive because AI demos usually look impressive when the input is clean, the examples are friendly and nobody tests the edge cases.
Then the live business environment appears. Customer records are inconsistent. Staff use three different naming conventions. The CRM has old fields nobody trusts. The helpdesk knowledge base is outdated. Excel files contain exceptions. Customers ask awkward questions. The AI answers confidently when it should escalate. A workflow fails silently. Nobody knows who maintains the prompt. Costs are unclear. The agency says the original scope did not include that level of complexity.
This is why the buyer feels scammed. The agency may say it delivered what was agreed. The buyer says they bought a business outcome, not a toy demo. Both sides may be reading the same proposal, but the proposal was too vague to protect either party.
In a proper AI project, the boring work comes before the demo. The agency should map the workflow, inspect data quality, define decision points, identify high-risk outputs, agree human approval steps, document suppliers, set acceptance criteria and decide what happens when the system is unsure. If none of that happened, the project was probably sold too fast.
| What was sold | What was delivered | Why it feels like a scam |
|---|---|---|
| Custom AI assistant | A chatbot connected to a few uploaded PDFs | The buyer expected workflow integration, not a document search demo |
| Sales automation | Template emails generated from CRM fields | The buyer expected qualified follow-up logic and reporting |
| AI operations system | Several low-code automations stitched together | The buyer expected ownership, monitoring and robust error handling |
| AI strategy | A generic slide deck and tool list | The buyer expected prioritised projects, costs, risks and ROI assumptions |
There is a grey area in AI services where the agency is not committing outright fraud, but the commercial presentation is still unfair. This is where many small businesses end up angry.
One agency might charge £3,000 to configure an off-the-shelf chatbot honestly. Another might charge £18,000 for almost the same thing but describe it as a proprietary AI customer engagement engine. One consultant might charge £1,500 for a prompt and process workshop. Another might charge £7,500 for a similar workshop and call it a strategic AI transformation sprint. The work can be similar, but the packaging changes the buyer's expectation.
The issue is not that agencies use public models. Almost every practical AI build uses third-party models, APIs, SaaS platforms or open-source components somewhere. OpenAI, Anthropic, Google, Microsoft, AWS, Azure, Make, Zapier, n8n, Pinecone, Supabase, Airtable and HubSpot can all be legitimate parts of a solution. The issue is whether the agency explains what is custom, what is configured, what is licensed, what is reusable and what you actually own.
A fair invoice separates discovery, process mapping, data cleaning, prompt design, integration work, security review, testing, documentation, training, licences, model usage and support. A suspicious invoice hides everything behind phrases like AI setup, implementation package, automation deployment or proprietary platform access.
The Cabinet Office generative AI framework says organisations need to understand generative AI's limitations, use it lawfully and responsibly, keep tools secure, maintain meaningful human control and manage the full lifecycle. It also warns that generative AI outputs are not guaranteed to be accurate and need testing. Source: GOV.UK Generative AI Framework for HMG.
That is government guidance, not agency marketing. It gives small businesses a useful test: if the proposal ignores limitations, security, lifecycle management and human control, it is not mature AI delivery.
Here are the reasons we see most often, in plain terms.
- Vague outcomes: The agency promised efficiency, growth or transformation but never defined the actual workflow result.
- Thin wrapper delivery: The finished product is just a branded front end on ChatGPT, Claude, Gemini or a SaaS tool, with little genuine integration or testing.
- No proof of work: There is no process map, test log, architecture diagram, data flow, evaluation set, prompt inventory, handover pack or failure report.
- Hidden costs: The buyer later discovers separate charges for API usage, hosting, licences, support, changes, monitoring, storage or extra workflows.
- Poor data handling: The agency cannot clearly explain where data goes, which suppliers process it, whether it is retained, and whether UK GDPR processor terms are in place.
- No measurable ROI: Nobody measured the baseline, so nobody can prove whether the AI saved time, reduced errors or improved conversion.
- No support after launch: The agency hands over a brittle workflow, then charges again when it breaks or the model behaviour changes.
The data point that should worry buyers is supplier risk. The same GOV.UK Cyber Security Breaches Survey found 43% of UK businesses identified a cyber security breach or attack in the previous 12 months, equal to about 612,000 businesses. It also found only 15% of businesses formally reviewed risks from immediate suppliers, and only 6% reviewed the wider supply chain. Source: GOV.UK Cyber Security Breaches Survey 2025/2026.
AI agencies sit inside that supplier-risk gap. If an agency connects your CRM, mailbox, website forms, customer data, documents and cloud tools, they are not just a creative supplier. They are part of your operational and data supply chain.
A serious agency should be able to show its working without burying you in jargon. For a small UK business, useful proof usually includes:
- A workflow map showing the before and after process.
- A clear list of systems connected, including CRM, email, files, accounting software, helpdesk or website forms.
- A data flow diagram showing what data is sent where.
- A supplier list naming the AI model providers, automation tools, hosting and databases used.
- Acceptance criteria explaining how success will be tested.
- A test log with real examples, failures and fixes.
- Human approval rules for high-risk outputs.
- A handover pack covering prompts, configuration, access, maintenance and ownership.
- A support plan with response times, monitoring and what is excluded.
- A simple ROI model based on time saved, error reduction, capacity released or revenue impact.
None of this has to be heavyweight. A £4,000 pilot does not need enterprise documentation. But it does need enough evidence for the buyer to understand what exists, what it does, what it costs, what could go wrong and how to leave.
The ICO's AI guidance is clear that organisations using AI with personal data still need to apply data protection principles. Source: ICO artificial intelligence guidance. For a small business, that means the agency cannot wave away data protection because the project is innovative or because the tool is popular.
If the agency processes personal data on your behalf, ask about UK GDPR roles, processor terms, sub-processors, retention, deletion, access controls, security measures and breach handling. This is not legal fussiness. It is basic responsible buying.
A fair engagement starts smaller than the sales pitch. The agency should identify one valuable workflow, agree the baseline, price the discovery separately if needed, and only recommend a build once the data, systems, risk and expected value are understood.
For example, a good first project might be: reduce manual quote drafting time from 45 minutes to 15 minutes for standard enquiries, with human approval before anything is sent. The agency would review current quote examples, map the data needed, connect approved sources, build the draft workflow, test 30 representative cases, document failures, train staff and measure the result after 30 days. That is concrete.
A weak version would be: implement AI in your sales process to increase productivity. That might sound bigger, but it gives you nothing to hold the agency to.
Fair pricing should also match risk. If the work is a one-day ChatGPT training session, £750 to £2,000 may be reasonable. If it is a workflow audit, £2,000 to £5,000 is common. If it is a focused integration pilot, £5,000 to £20,000 can be fair. If it is a business-critical system touching customer data, £25,000 plus support may be justified. The price is not the scam. The scam feeling comes when the price suggests serious delivery but the evidence looks like a weekend prototype.
Good agencies will also tell you when not to buy. Sometimes the right answer is to fix your CRM fields, document your process, clean your product data, train staff on existing tools, or use Microsoft Copilot or ChatGPT Team before paying for custom work. An agency that cannot recommend a cheaper path when it is clearly better has a trust problem.
This does not apply to every disappointing AI project. Some projects fail for normal reasons: the buyer changed scope, internal data was worse than expected, staff did not use the system, access to systems was delayed, the business process was undocumented, or the commercial goal was unrealistic from the start.
It also does not apply where the agency was transparent about using low-code tools or third-party AI. A Make, Zapier, n8n, Airtable, HubSpot, Microsoft Copilot or ChatGPT-based solution can be excellent if it solves a real problem, is priced fairly, and is documented honestly. Custom code is not automatically better. Proprietary platforms are not automatically better. The right test is fitness for purpose.
Finally, small businesses need to accept their side of the responsibility. If you buy AI without agreeing success criteria, without giving access to the real workflow, without nominating an internal owner, and without checking data protection, the project is more likely to disappoint. A good agency should guide you through that. But the buyer still has to participate.
Ask five blunt questions before paying a deposit.
- What exactly will we receive at the end, in plain English?
- Which parts are custom, which parts are configured, and which third-party tools are being used?
- What evidence will you provide to prove the system works?
- Where will our data go, who will process it, and what UK GDPR terms apply?
- What happens if we stop working with you after 90 days?
If the answers are clear, specific and written down, the risk drops. If the answers are vague, defensive or full of mystical AI language, pause.
Also ask for a paid discovery phase if the scope is unclear. A £2,500 discovery that tells you not to proceed is cheaper than a £25,000 build that never gets used. Discovery should produce a useful artifact: workflow map, costed options, data risks, recommended first project, implementation estimate and a no-build recommendation if AI is not the right answer.
If you want to explore whether an AI project makes sense for your business, start with a focused workflow review. No pressure, no magic claims. The right first question is not "which AI tool should we buy?" It is "what business problem are we solving, what evidence would prove it worked, and what risk are we taking on?"
You can also read our related checklist on AI agency contract red flags before signing anything substantial.
Is This Right For You?
This applies if you run a UK small business and you are considering an AI agency, AI consultant, automation partner, chatbot supplier, CRM automation build, internal copilot, document workflow or managed AI retainer. It is especially relevant if the proposed work is more than £2,000, touches customer data, connects to internal systems, or promises measurable savings.
It does not mean every AI agency is dishonest. Some agencies do careful workflow discovery, build useful integrations, document the system, test outputs, monitor failures and hand over properly. The point is simpler: the buyer should be able to see exactly what work is being done, what proof will be delivered, what tools are involved, what data is touched, and how success will be measured.
Frequently Asked Questions
Are AI agencies usually scams?
No. Many AI agencies do legitimate work. The risk is that a young market makes it easy for weak suppliers to sell vague promises, repackage simple tools and avoid hard questions about data, ownership, proof and support.
What is the biggest sign an AI agency is overcharging?
The biggest sign is a high project fee with no itemised scope, no proof-of-work artifacts, no named tools, no acceptance criteria and no handover plan. Expensive can be fair. Expensive and vague is the problem.
Is a ChatGPT wrapper a scam?
Not automatically. A ChatGPT wrapper can be useful if it is sold honestly, priced fairly, connected safely, tested properly and maintained. It becomes dishonest when it is sold as proprietary custom AI without explaining what is really underneath.
How much should a small business pay before seeing proof?
For an unclear AI project, keep the first paid step small. A useful discovery phase is often £2,000 to £5,000. Be cautious about paying £15,000 or more before you have a written workflow map, data review, success criteria and implementation plan.
What documents should I ask an AI agency for?
Ask for a statement of work, data flow diagram, supplier list, acceptance criteria, security notes, pricing breakdown, support plan, handover pack and exit terms. For personal data, ask for UK GDPR processor terms and sub-processor details.
Can low-code AI automation be good enough?
Yes. Low-code automation can be the right answer for many SMEs because it is faster and cheaper than custom software. The agency must still be honest about limits, ownership, monitoring, failure handling and ongoing costs.
What should I do if I already feel scammed?
Ask for the deliverables, access details, tool list, data flow, test evidence and handover documentation in writing. Compare that with the signed proposal. If personal data or material money is involved, speak to a UK commercial solicitor before escalating.
Should I avoid AI agencies and just use Microsoft Copilot or ChatGPT Team?
If your needs are simple, yes, start there. Use Microsoft Copilot, ChatGPT Team, Claude Team or Gemini for Workspace before paying for custom work. Bring in an agency when you need workflow design, integration, security, training, measurement or ongoing support.