Why do some small businesses feel scammed by AI agencies?

25 July 2026

Why do some small businesses feel scammed by AI agencies?

Most complaints come from a mismatch between what was sold and what was delivered. A business expected a practical, secure implementation that saves time or money. What it received was often a prompt pack, a basic chatbot, a Zapier workflow, or an AI SaaS subscription hidden behind agency language and a £5,000 to £30,000 invoice.

The short answer: they were sold certainty and delivered experiments

Some small businesses feel scammed because the sales conversation sounded like a guaranteed business result, but the delivery looked like an experiment. The agency promised saved hours, reduced headcount pressure, better leads, instant customer service, or a smarter business. Then the client received a chatbot that answered badly, a set of prompts in a Google Doc, a generic automation that broke after two weeks, or a dashboard nobody used.

That gap matters because most UK small businesses are not buying AI for novelty. They are buying it because time, margins, admin, recruitment, customer response speed, or compliance pressure is hurting them. According to the Department for Business and Trade, the UK had 5.5 million private sector businesses at the start of 2024, and 5.45 million of those were small businesses with 0 to 49 employees. Source: DBT Business Population Estimates 2024.

For a five-person accountancy firm, estate agency, manufacturer, trades business, clinic, or professional services company, a £10,000 AI project is not a harmless experiment. It is real money. If the output is unclear, unsupported, or impossible to measure, the client feels misled even if the agency did not set out to deceive them.

What bad AI agency delivery usually looks like

The most common bad pattern is a simple wrapper being sold as custom AI. A wrapper is not automatically bad. Many useful business systems are built by connecting OpenAI, Claude, Gemini, Microsoft Copilot, Make, Zapier, Airtable, HubSpot, GoHighLevel, Notion, or a private knowledge base. The problem is pretending that a light configuration is bespoke engineering.

A fair £2,000 to £5,000 engagement might include process discovery, workflow design, tool setup, staff training, documentation, and a handover. A fair £10,000 to £25,000 engagement should include deeper integration, testing, security review, access controls, failover thinking, measurement, and post-launch support. A £25,000 plus project should have proper technical architecture, data handling detail, acceptance criteria, source access where relevant, and a maintenance plan.

The scam feeling appears when the invoice says implementation but the deliverable is only a prompt library. Or when the contract says custom assistant but the client later discovers it is just a public chatbot with their website text pasted into a knowledge base. Or when the agency refuses to name the tools being used because its entire margin depends on hiding that the underlying subscription costs £20 to £200 per month.

This is also why honest comparison matters. If Microsoft Copilot, ChatGPT Team, Claude Team, Gemini for Google Workspace, Zapier, Make, or a CRM-native AI feature solves the job, a good agency should say so. You might still pay for setup, training, governance, and integration, but you should not be told you are buying proprietary technology when you are mostly buying configuration.

The biggest red flags before you sign

The first red flag is a proposal that promises outcomes but avoids baselines. If an agency says it will save 20 hours per week, ask where those hours are currently being spent, who measured them, what the automation will replace, and how success will be tracked after launch. If it cannot answer, the number is marketing, not a forecast.

The second red flag is no discussion of data protection. In the UK, AI projects that use personal data still sit under UK GDPR and the Data Protection Act 2018. The ICO has dedicated guidance and an AI and data protection risk toolkit for organisations assessing risks to individual rights and freedoms. Source: ICO artificial intelligence guidance. If an agency wants to connect AI to customer emails, call notes, HR records, support tickets, finance data, or CRM history without discussing lawful basis, retention, access, processor terms, security, and human review, that is not a small admin detail. It is a serious governance gap.

The third red flag is no ownership clause. You need to know who owns prompts, workflow logic, documentation, code, data mappings, trained retrieval indexes, vector databases, API accounts, domains, credentials, and generated content. If the agency keeps everything inside its own account and you cannot leave without rebuilding from scratch, you are renting your own operating system.

The fourth red flag is a demo that only works on perfect examples. Ask for edge cases. Ask what happens when the customer is angry, the data is missing, the question is ambiguous, the API is down, the model hallucinates, or a staff member needs to override the system. Good agencies enjoy those questions because they reveal whether the design is practical.

Why security makes bad AI projects feel worse

AI agency work often touches the places small businesses are already vulnerable: email, files, CRM data, payment workflows, client records, website forms, and staff accounts. That is why a bad AI implementation can feel more frightening than a bad website project. It does not just waste money. It can expose sensitive data or create a new route for mistakes.

The UK government's Cyber Security Breaches Survey 2025 found that 43% of businesses identified a cyber security breach or attack in the previous 12 months. It estimated that this equated to about 612,000 UK businesses. It also found that phishing remained the most prevalent and disruptive attack type, experienced by 85% of businesses that had a breach or attack. Source: DSIT Cyber Security Breaches Survey 2025.

The NCSC's small organisations guide says there are 5.5 million small organisations in the UK and that 1 in 2 small businesses suffer a cyber incident every year. Source: NCSC Small organisations guide to cyber security. So when an AI agency says, do not worry about security, that is not reassuring. It is a sign they may not understand the environment your business operates in.

At minimum, expect secure password handling, multi-factor authentication, separate admin accounts, least-privilege access, documented integrations, basic logging, backup and rollback thinking, and a named person responsible for post-launch support. For customer-facing AI, expect human escalation and a clear list of topics the AI must not answer. For internal AI, expect staff training on what data can and cannot be pasted into tools.

What a fair AI agency proposal should include

A fair proposal should be plain enough that a non-technical director can understand what is being bought. It should name the business problem, the current baseline, the proposed workflow, the tools involved, the expected cost, the delivery timeline, the support period, the data being used, the acceptance criteria, and what you will own at the end.

For UK small businesses, a sensible pricing guide is: £1,000 to £3,000 for a focused AI readiness or workflow audit, £2,500 to £7,500 for a narrow implementation such as document triage, internal knowledge search, enquiry routing, or CRM follow-up automation, £7,500 to £25,000 for a more serious multi-system implementation, and £25,000 plus where there is custom software, regulated data, complex integrations, heavy testing, or multiple departments. Anything can sit outside those ranges, but the explanation should be specific.

A good proposal will also tell you what not to do. Sometimes the right answer is to fix the process first. Sometimes the right answer is to buy a mainstream SaaS tool rather than commission custom work. Sometimes the right answer is staff training and a usage policy. Sometimes the right answer is no AI at all because the data is poor, the workflow changes weekly, or the business has not agreed who owns the process.

If you want a deeper check on competence before committing, read How Do I Know If My AI Consultant Is Actually Competent?. The short version is simple: a competent partner can explain trade-offs, failure modes, security, ownership, and measurement without hiding behind jargon.

How to protect yourself without becoming an AI expert

You do not need to become an AI engineer to avoid a bad deal. You need a practical buying checklist. Before signing, ask for a one-page delivery map. It should show the systems involved, the data flowing between them, who has access, what happens when the AI is uncertain, and what success looks like after 30, 60, and 90 days.

Ask the agency to separate three costs: discovery, build, and ongoing support. Discovery should produce something useful even if you do not proceed. Build should have acceptance criteria. Support should define response times, what is included, what costs extra, and whether model or platform subscription fees are passed through at cost or marked up.

Ask for a handover pack. This should include login inventory, integration notes, prompt or workflow documentation where relevant, data sources, escalation rules, testing notes, and a plain-English explanation your team can use. If the agency says the system is too complex to document, that is not a sign of sophistication. It is a sign of future dependency.

Finally, test the smallest valuable version first. A two-week pilot that processes 100 real enquiries, 50 documents, or one recurring workflow is usually more useful than a three-month strategy exercise. The pilot should answer one question: does this create measurable value in the real business, with real people, using real data, under realistic constraints?

When this does NOT mean you were scammed

Feeling disappointed does not always mean you were scammed. AI projects involve uncertainty. Models change, software vendors alter pricing, APIs fail, data quality is worse than expected, staff adoption can be slow, and some workflows are messier than they look from the outside. A good agency should warn you about those risks, but it cannot remove every one of them.

You probably were not scammed if the agency clearly explained what it was building, named the tools, documented assumptions, gave you access, showed limitations, trained your team, and responded properly when problems appeared. That may still be a failed project, but it is not the same as deception.

You should be more concerned if the agency avoided documentation, refused to explain the stack, locked you out of accounts, ignored security, invented savings figures, overpromised accuracy, or disappeared after launch. That is where a normal commercial disappointment starts to look like mis-selling.

Precise Impact AI is not the right fit for every business. If you want a one-hour ChatGPT tips session, a cheap template pack, or an enterprise transformation programme with a large consultancy team, we are probably not the best choice. If you want a candid assessment of where AI can help, where it cannot, what it should cost, and what risks need managing, that is the work we care about.

Is This Right For You?

This advice applies if you are a UK small business reviewing an AI agency, automation partner, chatbot provider, CRM consultant, or custom software company that has started selling AI implementation.

It does not apply if you are buying a clearly priced off-the-shelf tool, hiring a permanent internal AI engineer, or commissioning enterprise-scale work from firms such as Accenture, PwC, Deloitte, IBM Consulting, or McKinsey. Those projects have different budgets, procurement processes, legal review, and delivery teams.

If your budget is under £2,000, you should probably start with training, process mapping, or a narrow automation audit. If your budget is £5,000 to £25,000, you should expect a working implementation, clear documentation, named tools, security basics, and a measurable business case. If someone asks for that money but cannot explain exactly what you will own, pause.

Frequently Asked Questions

Is selling a ChatGPT wrapper as an AI solution always a scam?

No. A wrapper can be useful if it solves a real workflow, is priced honestly, and is explained clearly. It becomes dishonest when it is sold as proprietary custom AI without naming the underlying tools, limits, ownership, or support requirements.

How much should a small UK business pay before expecting a working AI implementation?

For £2,500 to £7,500, you should expect a narrow but working implementation with documentation and handover. For £7,500 to £25,000, you should expect stronger integration, testing, access controls, and support. Below £2,000, expect audit, training, or light setup rather than serious custom implementation.

What is the biggest contract red flag with an AI agency?

The biggest red flag is unclear ownership. The contract should say who owns workflows, code, prompts, documentation, accounts, data mappings, and generated assets. If you cannot leave without losing the system, you are taking on dependency risk.

Should an AI agency tell me which tools it uses?

Yes. It does not need to reveal every internal technique, but it should name the major platforms, models, data stores, automation tools, hosting environment, and accounts involved. Secrecy around the basic stack usually protects the agency margin, not your business.

What UK regulation should I ask about before using AI with customer data?

Ask how the project complies with UK GDPR and the Data Protection Act 2018. You should discuss lawful basis, data minimisation, retention, processor terms, access control, human review, and whether a data protection impact assessment is needed.

How can I check if promised AI savings are realistic?

Ask for the baseline. If the agency claims 20 hours per week saved, it should identify the current process, who performs it, how long it takes, what the AI will replace, what remains human, and how the saving will be measured after launch.

Is it safer to use Microsoft Copilot or ChatGPT Team instead of an agency?

Sometimes, yes. If your need is general productivity, writing, meeting notes, spreadsheet help, or simple research, mainstream tools may be enough. An agency is more useful when you need workflow design, integration, governance, staff adoption, security, or a measurable operational outcome.

What should I do if I already feel scammed by an AI agency?

Collect the proposal, contract, invoices, access details, deliverables, messages, and evidence of what was promised. Ask for a written handover and a clear remediation plan. If personal data or security is involved, review access immediately and consider legal, ICO, or cyber security advice depending on the risk.