As summer vacation comes to an end, we can all look back and reflect on sunny days, cookouts, beach trips, and creepy summer flings. Isn’t that right, Grease?
While some people may be confessing to a possible felony on the bleachers of their high school right about now, agencies all over are probably hearing about a new passionate romance via Zoom calls with clients that go something like this:
“OH EM GEE, there’s this AI Chatbot that is so charming. It writes poetry and knows like 40 different languages. It also agrees that all my bad ideas will most definitely double my conversions.”
And look, we get it. AI is smooth. It’s exciting. It probably wears a leather jacket and races cars down by the L.A. River.
But as the web agency, it’s your job to stand in the doorway, holding a blunt object, with arms crossed, asking: “So, what are your intentions with my client’s website?”
Because if you don’t vet this digital suitor before letting them move into the codebase, you might wake up to find out your new AI tool-in-law has been stealing your visitors’ personal data, seeing third-party servers on the side, telling visitors to ‘F off’ and go elsewhere (true story, btw), taking your client to regulatory court, and leaving them to live by the L.A. River.
So, before you give your blessing, make sure that AI passes this Website Dating Checklist – and proves it isn’t a total creep.
1. Does it have a past?
My college roommate got a job interview with the FBI a few years after we lived together. The FBI called me and interrogated me for about 45 minutes about whether or not my old roommate was a Russian spy… with a heavy southern accent.
That was the second-most intense background check I’ve been a part of. The first was when my mother found out I was going on a date with a girl I had just met in college and – armed with nothing but Facebook and Google – found out how many siblings she had, what her favorite food was, the last time she went to the dentist, and her Top 5 Johnny Depp movies in the correct order. All this before I knew if she’d rather eat at Olive Garden or Chili’s for our upcoming date.
You don’t have to be that weird (Mooooommmm), but it is a good idea to be a little paranoid when dealing with a shiny new AI tool. You’re going to want to do some vendor privacy due diligence, which involves:
- Check their policies – Look at the company’s Privacy Policy and Terms of Service to see what kind of data their tool collects, who it shares that data with, and what it is allowed to do with that data. Also, look to see if data collected by AI is used to train the AI. If it just says “Trust me, bro,” don’t trust it, bro.
- Check for good privacy practices – Does their own site practice good privacy by design? Do they have data retention limits in place? Do they practice data minimization and only collect data that’s crucial for their AI tool to work?
- Check for past problems – Has this hot new AI startup had three data breaches in the last six months because they built their infrastructure out of duct tape? A quick Google search does wonders.
- Check their customer reviews – You’d be surprised how many companies sign people up for subscriptions without their consent, refuse to cancel subscriptions, or how many products are just plain bad.
- Check their employee reviews – Nobody shares tea like a past employee (think Glassdoor) that quit due to a toxic environment, constant restructuring, and general instability in the company.
We recently did a whole podcast episode on vendor privacy due diligence. Definitely worth a listen if you’d like to learn more about how you can best judge a vendor by how it covers privacy.
2. Does it kiss and tell?
There’s nothing worse than having a date run back to their friends to tell them that you accidentally swallowed your gum and almost choked to death during the first kiss… or some other completely made-up scenario that definitely didn’t happen to me.
The AI world isn’t exactly known for keeping details just between you and it.
Many cheap or free AI tools have terms that say something along the lines of: “By using this service, you grant us permission to use your inputs to train and improve our machine learning models.”
Translation: If a visitor types their private medical symptoms, financial struggles, or unpublished trade secrets into your client’s AI chatbot, that bot might chew it up, digest it, and spit those exact details back out to a random stranger in Idaho six weeks later. Oopsies.
- Check for ZDR – Try to look for AI tools that mention zero data retention (ZDR), meaning it processes inputs and outputs in real time without permanently saving, logging, or reusing your content.
- Check the settings – Some AI tools will allow you to specifically forbid them from using data for foundational model training.
- Check for disclaimers – If a client insists on having an AI Tool that shares data, you may want to put a disclaimer underneath a chatbot, for example, that tells users not to share information like their Social Security number or financial information.
3. Does it respect personal space?
Relationship hack: It’s always a good idea to get consent and agreement that living together would be a good idea BEFORE you bring a toothbrush and your pet parakeet over.
AI tools, just like non-AI tools, should never drop tracking cookies onto users’ browsers before they have a chance to consent. This is a great way to get into trouble with the likes of GDPR, CIPA, and other privacy laws that require consent before tracking can take place.
If your client’s website doesn’t need to comply with one of the laws that require websites to have a cookie consent banner, move on to #4. If they do have to comply, you should check the following:
- Check for cookies – Visit your website in an incognito window > don’t touch the banner > right click > “Inspect” > Application > Network. If the AI tool is placing cookies before you gave it permission via the banner, that’s a red flag.
- Check your banner – Before you break up with that AI tool over cookies, you may want to test your consent solution to make sure it’s working properly as well.
4. Is it too controlling?
Some AI tools just want to answer FAQs and help visitors find the right product. Totally fine. Healthy relationship.
But some AI tools are more interested in screening job applicants, flagging user accounts, or determining who qualifies for something. Tools like this could lead to problems with privacy laws like GDPR that claim individuals have the right not to be subject to decisions made solely by automated means that produce legal or similarly significant effects.
The EU AI Act also classifies AI tools that significantly influence employment decisions as high-risk, which means you should:
- Check the tool’s supervision – If your client wants an AI tool for the purposes of making unsupervised choices, you may want to push back.
- Check that the AI isn’t hiding – Speaking of the EU AI Act, any AI features such as chatbots, text or images need to be labeled as such.
The Pre-Date Checklist for Web Agencies
Before you let this AI take your client’s website out to see The Blob at the local drive-in… let me stop the blog here.
As much fun as it has been for me to bring up Grease references, a movie made in 70’s about the 50’s, to explain today’s ultra scary and advanced technology, let’s be real. You did not give birth to your client. They are their own adult responsible for their own life choices, and you are just doing a job as their Agency.
However, like a parent, a young client in love is going to do what a young client in love is going to do. Your job is just to give them the information you have based on your own experiences as a professional and let them make the choice. It’s a client’s responsibility in the end to make sure their website is using privacy-friendly AI Tools, the following checklist is simply a tool you can use to guide them (hopefully) down the right direction.
So, let’s recap everything AI should do before it dates your client’s website:
- Check their policies – Look at the company’s Privacy Policy and Terms of Service to see what kind of data their tool collects, who it shares that data with, and what it is allowed to do with that data. Also, look to see if data collected by AI is used to train the AI. If it just says “Trust me, bro,” don’t trust it, bro.
- Check for good privacy practices – Does their own site practice good privacy by design? Do they have data retention limits in place? Do they practice data minimization and only collect data that’s crucial for their AI tool to work?
- Check their customer reviews – You’d be surprised how many companies sign people up for subscriptions without their consent, refuse to cancel subscriptions, or how many products are just plain bad.
- Check their employee reviews – Nobody shares tea like a past employee (think Glassdoor) who quit due to a toxic environment, constant restructuring, and general instability in the company.
- Check for past problems – Has this hot new AI startup had three data breaches in the last six months because they built their infrastructure out of duct tape? A quick Google search does wonders.
- Check for ZDR – Try to look for AI tools that mention zero data retention (ZDR), meaning it processes inputs and outputs in real time without permanently saving, logging, or reusing your content.
- Check the settings – Some AI tools will allow you to specifically forbid them from using data for foundational model training.
- Check for disclaimers – If a client insists on having an AI tool that shares data, you may want to put a disclaimer underneath a chatbot, for example, that tells users not to share information like their social security number or financial information.
- Check for cookies – Visit your website in an incognito window > don’t touch the banner > right click > “Inspect” > Application > Network. If the AI tool is placing cookies before you gave it permission via the banner, that’s a red flag.
- Check your banner – Before you break up with that AI tool over cookies, you may want to test your consent solution to make sure it’s working properly as well.
- Check the tool’s supervision – If your client wants an AI tool for the purposes of making unsupervised choices, you may want to push back.
- Check that the AI isn’t hiding – Speaking of the EU AI Act, any AI features such as chatbots, text or images need to be labeled as such.
It’s ok to be a bit protective as an agency
It’s a tale as old as time. A client falls in love with shiny tech and ignores the red flags. Luckily, they have you – their agency – looking out for their best interest.
By running every new AI integration through a quick privacy vetting process, you protect your client from messy legal breakups, maintain visitor trust, and prove that your agency is the responsible adult in the room.
Of course, when you tell a starry-eyed client that their beloved new AI chatbot needs strict guardrails (or maybe shouldn’t be installed at all), they might not take it well. In which case, feel free to share the story. As Danny Zuko’s questionable hype squad would ask:
“Tell me more, tell me more… did they put up a fight?”


