How to Integrate AI Into an Existing App or Website
To integrate AI into an existing app, choose one task where a model's answer can be checked, decide what data the model may see, and call a hosted or self-hosted model from your backend. Test it against real examples before release, add guardrails and spending limits, then roll it out to a small group of users first. Most of the engineering sits around the model: data access, evaluation and what the app does when an answer is wrong.
The same steps apply to a website. A chat assistant or a smarter search box on a marketing site is an app feature with a public front end.
Is AI worth adding to your app?
AI is worth adding where a task is frequent, involves text or messy data, and produces an output someone can check. Where an exact rule already works, keep the rule.
Adoption is broad, and returns are less common. McKinsey's State of AI 2026 survey (August 25, 2026; 1,719 participants surveyed May 4 to June 8, 2026) found that "Nearly nine in ten respondents report regular use of AI in at least one business function". Yet "Thirty-seven percent of respondents attribute at least some EBIT impact to AI use".
A 2024 Gartner prediction names likely causes. In a press release dated July 29, 2024, it predicted that "At least 30% of generative AI (GenAI) projects will be abandoned after proof of concept by the end of 2025, due to poor data quality, inadequate risk controls, escalating costs or unclear business value." Each of those four causes maps to a step below.
Step 1: How do you pick the first AI use case?
Pick a task with a clear input, an output you can check, and a cheap failure. The first feature should prove value in weeks and teach the team how the model behaves on your data.
| Use case | Example in an app or website | What the model needs | Risk if it is wrong |
|---|---|---|---|
| Summaries and drafts | Ticket summaries, reply drafts, meeting notes | The record being summarized | A person edits before sending |
| Classify and extract | Route emails, pull fields from invoices | A fixed output schema | A wrong field, caught by validation |
| Search | "Find the clause about renewals" | An index of your content | Irrelevant results |
| Answers from your content | Help-center assistant, website chat | Search over your documents (RAG) | A customer acts on a wrong answer |
| Actions | Book, update a record, issue a refund | Tools with permissions (agents) | A real-world action, so it needs approval rules |
Start near the top of the table, where a person or a validator sits between the model and the outcome. Customer-facing answers and actions come next, once evaluation and guardrails are in place. For conversational features see AI chatbot development.
Step 2: What data may the model see?
Decide, field by field, what is sent to the model, where it is processed and how long the provider keeps it. Then read the provider's terms for the exact product tier you will use, because terms differ between tiers.
Two providers' public documentation shows why. OpenAI's data controls page, read October 5, 2026, states: "As of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)." It adds that abuse monitoring logs are "retained for up to 30 days" by default. Google's Gemini API terms (last modified April 28, 2026) treat tiers differently. For unpaid services, "Google uses the content you submit to the Services and any generated responses to provide, improve, and develop Google products and services and machine learning technologies". For paid services, "Google doesn't use your prompts ... or responses to improve our products."
Personal data adds legal duties. For the UK, the Information Commissioner's Office guidance on AI and data protection states that "In the vast majority of cases, the use of AI will involve a type of processing likely to result in a high risk to individuals' rights and freedoms, and will therefore trigger the legal requirement for you to undertake a DPIA." The ICO notes the guidance is under review following the Data (Use and Access) Act.
Send only the fields the task needs, mask identifiers before the call, sign a data processing agreement with each provider, and keep prompt logs under your own retention rules.
Step 3: Should you use a hosted model or an open-weight model?
Use a hosted model API to reach a working version quickly and to choose from many commercial models. Use an open-weight model on your own servers when data must stay in your environment, when volume is high and steady, or when you need to fix the model version yourself. Many products use both, chosen per task.
| Factor | Hosted model API | Open-weight model you host |
|---|---|---|
| Time to a first version | Short: an account and an API key | Longer: servers, serving software and monitoring |
| Where data is processed | The provider's infrastructure, under its terms | Your cloud account or data center |
| Cost shape | Pay per token used | Pay for servers whether busy or idle |
| Operations | The provider scales and patches | Your team scales, patches and secures |
| Model versions | The provider retires versions on its schedule | You decide when to upgrade |
| Fits | Most first features and variable traffic | Sensitive data, steady high volume, offline or regulated settings |
Keep a thin model interface in your backend so the feature can change model without a rewrite. For self-hosting, see private LLM deployment and our private LLM guide. For model selection and tuning work, see LLM development.
Step 4: How should the app call the model?
Call the model from your backend, never directly from the browser or the mobile app, so keys, limits and logs stay under your control. Then choose the pattern that matches the feature:
- Server-side request. Your API authenticates the user, builds the prompt and calls the model. A website chat widget should call this endpoint, so the provider key never reaches the browser.
- Streaming. Chat interfaces show text as it arrives.
- Structured output. Anything your code consumes should come back in a fixed schema. Anthropic's structured outputs documentation, read October 5, 2026, describes the feature as constraining responses "to follow a specific schema, ensuring valid, parseable output for downstream processing."
- Retrieval. For answers about your own products or policies, fetch the relevant passages and pass them to the model. Our RAG vs fine-tuning article explains when retrieval beats training.
- Tool calls. For actions, the model proposes a call and your code validates the arguments and checks permissions before running it.
- Background jobs. Work nobody waits for, such as nightly summaries, can run in a queue.
Every pattern needs a timeout and a fallback, such as standard search results or a route to a person.
Step 5: How do you test an AI feature before release?
Build an evaluation set from real examples and score every prompt, model or code change against it. Unit tests alone do not cover a component whose output varies.
OpenAI's evaluation best practices guide, read October 5, 2026, puts it this way: "Generative AI is variable. Models sometimes produce different output from the same input, which makes traditional software testing methods insufficient for AI architectures." Its process starts with "Define eval objective" and ends with "Continuously evaluate", which includes running evals "on every change".
In practice:
- Collect real inputs from logs, tickets or documents, including hard and hostile ones.
- Write the expected result or the rule a good answer must meet.
- Score correctness, format validity, grounding in the supplied sources, refusals, response time and cost per request.
- Set a pass threshold before launch and rerun the set whenever the prompt, the model or the data changes.
Step 6: Which guardrails does an AI feature need?
An AI feature needs controls on what goes in, what comes out and what the model is allowed to do. The OWASP Top 10 for LLM Applications 2025 is a practical checklist; it includes prompt injection, sensitive information disclosure, improper output handling, excessive agency and unbounded consumption.
Do not count on filtering to stop prompt injection. OWASP's prompt injection entry states: "Given the stochastic influence at the heart of the way models work, it is unclear if there are fool-proof methods of prevention for prompt injection." Design for containment instead:
- Give tools the narrowest permissions the task needs.
- Require human approval for payments, deletions and messages sent on a user's behalf.
- Treat model output as untrusted input: escape it before display and validate it before use.
- Keep secrets and other users' data out of prompts.
The business answers for what its AI says. In Moffatt v. Air Canada, 2024 BCCRT 149 (February 14, 2024), British Columbia's Civil Resolution Tribunal held an airline responsible for a chatbot's wrong answer about a fare policy: "It should be obvious to Air Canada that it is responsible for all the information on its website. It makes no difference whether the information comes from a static page or a chatbot."
Disclosure is becoming a legal requirement. The European Commission's AI Act page (last updated August 3, 2026) says that "when using AI systems such as chatbots, humans should be made aware that they are interacting with a machine", and that "The transparency rules of the AI Act will come into effect in August 2026."
Step 7: How do you keep AI costs under control?
Measure cost per request and per user from the first release, and set hard limits before traffic grows. In the McKinsey 2026 survey, "About 20 percent of respondents report that AI-related operating costs (including token costs) constrained their AI use."
The main levers:
- Send simple tasks to smaller, cheaper models and reserve large models for hard ones.
- Cap input and output length, and trim conversation history.
- Cache repeated context and answers.
- Run non-urgent work as batch jobs.
- Set per-user and per-account quotas, which also address OWASP's "unbounded consumption" risk.
Our article on how to reduce LLM API costs covers each lever, and LLM cost optimization describes the service.
Step 8: How should you roll out an AI feature?
Release the feature behind a flag to internal users, then to a small share of customers, and widen only when quality and cost hold. Log inputs, outputs and feedback within your privacy rules, and add failures to the evaluation set. Treat a provider's model upgrade like a dependency upgrade: rerun the evaluation set before switching.
Key takeaways
- Start with one checkable task, such as summaries, drafts or extraction, before customer-facing answers or actions.
- Read the provider's data terms for your exact tier. Free and paid tiers can treat your data differently.
- Call models from your backend, use structured output for anything code consumes, and add a fallback.
- Test against a set of real examples on every change, because model output varies.
- A tribunal held Air Canada responsible for its chatbot's wrong answer in 2024. Guardrails and human approval belong in the first version.
- Track cost per request from day one. About 20 percent of McKinsey's 2026 respondents said AI operating costs constrained their use.
Frequently asked questions
How do I integrate AI into my existing app?
Choose one task with a checkable output, decide what data the model may see, and call a hosted or self-hosted model from your backend. Test the feature against real examples, add guardrails and spending limits, and release it to a small group before everyone.
How do I add AI to my website?
Add a backend endpoint that calls the model and connect your site's chat widget or search box to it. Keep API keys on the server, ground answers in your own content, tell visitors they are talking to an AI, and offer a route to a person.
Do I need to train my own AI model?
Usually not. App features typically use an existing model and supply your content at request time through retrieval. Fine-tuning helps with consistent format or style. Our RAG vs fine-tuning article compares the two.
Is it safe to send customer data to an AI API?
It can be, if the provider's terms for your tier, your data processing agreement and your own controls fit the data. Send only the fields the task needs, mask identifiers, and in the UK expect to complete a data protection impact assessment.
How much does it cost to integrate AI into an app?
There are two costs: the engineering work and the running cost per request, which depends on the model, the length of inputs and outputs, and traffic. Measure it during the pilot and set quotas before a wide release.
Easital Technologies Ltd. builds AI features into existing products and runs its own AI products, StepVideo, Manob.ai and mAutomate. We work with all major commercial model providers and with open-weight models, and choose per task on quality, speed and cost. See AI agent development, LLM development, RAG development and AI chatbot development, or browse our work.
Sources
All sources were opened and checked on October 5, 2026.
- McKinsey & Company (Dan Tinkoff, Lieven Van der Veken, Michael Chui, with Tara Balakrishnan), "The state of AI in 2026: On the road to ROI", August 25, 2026. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
- Gartner, "Gartner Predicts 30% of Generative AI Projects Will Be Abandoned After Proof of Concept By End of 2025", press release, July 29, 2024. https://www.gartner.com/en/newsroom/press-releases/2024-07-29-gartner-predicts-30-percent-of-generative-ai-projects-will-be-abandoned-after-proof-of-concept-by-end-of-2025
- OpenAI, "Data controls in the OpenAI platform", API documentation, undated, read October 5, 2026. https://developers.openai.com/api/docs/guides/your-data
- Google, "Gemini API Additional Terms of Service", last modified April 28, 2026. https://ai.google.dev/gemini-api/terms
- Information Commissioner's Office, "What are the accountability and governance implications of AI?", Guidance on AI and data protection, under review, read October 5, 2026. https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/what-are-the-accountability-and-governance-implications-of-ai/
- Anthropic, "Structured outputs", Claude API documentation, undated, read October 5, 2026. https://platform.claude.com/docs/en/build-with-claude/structured-outputs
- OpenAI, "Evaluation best practices", API documentation, undated, read October 5, 2026. https://developers.openai.com/api/docs/guides/evaluation-best-practices
- OWASP Gen AI Security Project, "OWASP Top 10 for LLM Applications 2025", March 12, 2025. https://genai.owasp.org/llm-top-10/
- OWASP Gen AI Security Project, "LLM01:2025 Prompt Injection", 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
- Civil Resolution Tribunal of British Columbia, Moffatt v. Air Canada, 2024 BCCRT 149, February 14, 2024. https://decisions.civilresolutionbc.ca/crt/crtd/en/item/525448/index.do
- European Commission, "AI Act", Shaping Europe's digital future, last updated August 3, 2026. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

