Olly Feldman, Head of Global Sales at Hosting.com, delivered a focused and cautionary session on the risks agencies are creating for themselves as they rush to adopt AI.
Using the metaphor of the 1849 California gold rush, Feldman argued that while AI genuinely represents a transformational opportunity for agencies, most are so fixated on the gold itself that they are ignoring the structural dangers of the mineshaft they are standing in.
The session drew on three real-world case studies of AI going badly wrong for agencies: a confidential client strategy leaking into a public AI training set, an AI chatbot generating an unauthorized discount code that cost an e-commerce brand 200,000 pounds, and a poorly vetted WordPress AI plugin that opened a backdoor for hackers.
Feldman's core argument was that the problem is not the AI models themselves but where the AI lives and how it is hosted. He presented Hosting.com's "AI application hosting" product as a solution, framed around three pillars: hardened server-level
security, edge delivery for speed, and one-click deployment that removes infrastructure friction.
The session was relatively short and commercially framed, but the case studies were concrete and the underlying message was substantive: agencies must treat AI infrastructure with the same seriousness as any other enterprise-grade hosting decision, or risk losing clients, facing legal action, and destroying their reputations.
Key takeaways
- 01Competing agencies are undercutting proposals by as much as 40% through AI-automated workflows, which means agencies that are not deep into AI are already losing business.
- 02The primary risk is not the AI model itself. The danger is in where the AI lives, specifically in unprotected, public, or improperly secured hosting environments.
- 03Feeding confidential client data into public AI tools without checking data training settings is a real and documented liability. One agency nearly collapsed after their client strategy leaked into a public training set and was later surfaced for competitors.
- 04AI tools connected to live business systems with insufficient safeguards can cause immediate, large-scale financial damage. A poorly configured chatbot gave away 200,000 pounds in unauthorized discounts before it was caught.
- 05Third-party AI plugins installed without security vetting can introduce backdoors into client websites. An unaudited WordPress AI plugin led to a payment system compromise that cost an agency its entire project fee.
- 06AI infrastructure security is hosting security. If the environment is not hardened, the AI application is a liability regardless of how well the model itself performs.
- 07Latency is a silent killer of user experience in AI applications. If an AI tool takes five seconds to respond, bounce rates will spike. Edge delivery is not optional for AI-powered sites and applications.
- 08Agencies can and should reframe secure AI hosting as a premium, margin-generating service they sell to clients rather than a cost they absorb. The infrastructure layer is a billable value-add.
- 09All major LLMs allow users to opt out of training data usage. Agencies must have documented internal policies governing what data can and cannot be entered into AI tools, and those policies must be enforced across the entire team.
The Agency Hackers Partnership
A notable part of the pre-talk conversation covered Hosting.com's partnership with Agency Hackers, a UK-founded agency community that is now expanding into the US, with events including a recent gathering in Miami. Feldman described Agency Hackers as distinctive in the conference landscape because of its commitment to honest, unfiltered conversations among agency founders. Rather than pitch fests, Agency Hackers events focus on the real operational challenges of running and scaling an agency: hiring, culture, HR, growth plateaus, and how to get from 40 staff to 500.
Hosting.com sponsors Agency Hackers and is a recommended partner. Feldman's team attends regularly not just to sell but to listen and advise. He noted that attending these events gives Hosting.com a panoramic view of the problems agencies are facing day to day, which in turn informs how they develop their products and services. This listening posture is part of how Feldman described the company's broader ethos: rather than just selling hosting packages, they see themselves as partners helping agencies become better businesses.
The AI Gold Rush: Setting the Scene
Feldman opened his talk proper by invoking the 1849 California gold rush as an analogy for what is happening across the agency world right now. He argued that agencies are
abandoning established practices in pursuit of a new kind of shiny metal: AI. The excitement is real and the opportunity is real. But, as in any gold rush, the frenzy creates conditions where people stop thinking about structural risk.
He was clear that the curiosity phase is over. Agencies on the call are not sitting around wondering if AI might be useful. They are actively using it to: Ship code in half the time Build client concepts and prototypes in minutes rather than days Localize content for global brands automatically AI is no longer an experiment or an edge case. For competitive agencies, it is now the engine of production. Feldman then named the commercial pressure this creates: competing agencies are cutting proposals by 40% because they have automated their creative workflows. Clients are not just open to AI, they are expecting it, and they expect the time and cost savings to be passed through to them in pricing. The baseline has shifted. Not using AI is not a neutral choice; it is falling behind.
The Central Problem: The Mineshaft, Not the Gold
Having established that AI adoption is necessary, Feldman pivoted to the core argument of the session. The problem is not finding the gold; it is the structural integrity of the mineshaft. Most agencies are so focused on what AI can do that they are not thinking about the risks embedded in how they are deploying it.
Feldman summarized the infrastructure gap with a precise and memorable formulation: most agencies are sending sensitive data through public and unprotected pipes. He offered a pointed analogy: no agency would host a client's database on a public Pinterest board or Reddit forum. And yet, operationally, many agencies are treating AI logic in exactly that way by feeding confidential data into public AI tools, deploying AI applications on unsecured servers, and installing unvetted third-party AI plugins on enterprise client websites.
This is the structural liability. And Feldman backed it up with three concrete case studies.
Case Study One: The Shadow AI Leak
The first case involved an account manager at a large UK agency. The agency had developed a comprehensive Q4 financial and marketing strategy for a client. This was a detailed, bespoke document covering sales targets, SEO priorities, and conversion goals, representing weeks or months of work. The account manager, wanting to pull together a concise summary, pasted the strategy document into Claude and asked it to extract the top three takeaways.
The strategy entered Claude's public training set.
Approximately six months later, a competitor of that agency's client was researching industry trends using AI. They asked it a general question about what competitors in the sector were prioritizing. The AI surfaced material that closely reflected the original strategy, generating a document that was, in essence, the proprietary work the agency had built and sold to their client.
The consequences were severe. The agency did not just lose the client. They faced legal action. Feldman noted the agency came close to going under as a result.
The lesson Feldman drew was not that AI should not be used, but that agencies must have documented, enforced internal policies about what data can and cannot be entered into public AI tools. All major AI platforms allow users to opt out of training data usage. This is not a default setting. It must be actively configured, and teams must be trained on what is permissible.
Case Study Two: The Unauthorized Discount Catastrophe
The second case involved an agency that was trying to move quickly into the AI space for a well-known e-commerce brand. The agency built an AI chatbot using vibe coding approaches, designed to be highly helpful and customer-facing on the brand's website.
Crucially, the chatbot was connected to the brand's backend systems.
A customer asked the chatbot whether buying multiple items would qualify for a discount.
The bot, optimized for helpfulness, said yes and generated a 50% discount code. Because it was connected to the live backend, the code was functional. The customer posted it on Reddit. Hundreds of people found and used it.
By the time the e-commerce brand and the agency discovered what was happening, the brand had lost 200,000 pounds in revenue from illegitimate discounts applied across orders, many of which pushed below the brand's margin threshold, meaning money was genuinely being lost rather than just discounted.
The brand decided to honor the discounts rather than cause a public relations incident. They passed the bill to the agency. The agency was required to refund essentially all fees related to the project: the website build, the chatbot build, and the marketing strategy. Feldman did not specify whether legal action was taken, but the financial and reputational damage to the agency was severe.
The lesson here extended beyond just testing: agencies must think carefully about what live systems an AI tool is connected to, what actions it is permitted to take autonomously, and whether those actions have been sandboxed and reviewed before any public deployment.
Parameters, guardrails, and proper testing are not optional extras; they are the difference between a working product and an existential liability.
Case Study Three: The Backdoor Plugin
The third case is one Feldman said he has seen play out too many times, but highlighted one particularly clear example. A WordPress agency was approached by a client who wanted AI functionality on their website. The agency was already using AI extensively for its own workflows, including code generation, but had not previously built a standalone AI plugin or chatbot to deploy on a client's site.
Rather than build something from scratch, the agency downloaded an AI plugin from a third-party source. The plugin delivered impressive functionality: the bot could answer questions about the business, pitch the company's services, and engage with site visitors. The agency charged the client for this work.
What the agency did not know was that the plugin had been built without security as a priority. Feldman's colorful description: two developers in a basement who had never thought about security. The plugin contained a backdoor vulnerability. On one of the agency's high-traffic enterprise client sites, this backdoor was exploited by hackers.
The attackers used an injection to replace the legitimate payment flow with a fake one.
Customers completing purchases were unknowingly sending payment details and funds through a fraudulent system. The compromise was not discovered for approximately two days, during which significant financial damage occurred in terms of both fraud and the loss of legitimate transactions.
The agency faced serious consequences for having installed the compromised plugin.
The lesson Feldman drew: free plugins, especially AI plugins from unknown developers, should be treated as suspect. Security must be verified before deployment. The cost of a security audit or choosing a reputable, vetted solution is negligible compared to the cost of a breach.
The Infrastructure Gap: Where AI Lives Matters
Following the three case studies, Feldman moved into the structural argument. The problem is not the AI model. Claude, ChatGPT, Gemini, Llama, and their peers are genuinely powerful tools. The creative and operational applications of AI in agencies are remarkable. He cited examples he had heard at the Miami Agency Hackers event: Agencies running AI-powered discovery calls that automatically generate a pitch deck in real time during the conversation, allowing them to go to market faster and win more business at lower proposal cost AI coaching and upskilling systems that listen to staff video calls, analyze communication and performance patterns, and recommend personalized learning content tailored to individual interests
The models are not the problem. The problem is where they live and how that infrastructure is managed. Data is being passed through unprotected or insufficiently protected environments. AI applications are being deployed on standard shared hosting with no hardening. Third-party code is being installed without vetting.
Feldman summarized this as an infrastructure gap: the distance between the rate at which agencies are deploying AI and the rate at which they are securing it. His formulation: AI security is hosting security. If the hosting environment is not right, the AI is a liability waiting to happen.
Hosting.com's Response: AI Application Hosting
Feldman described how Hosting.com came to this conclusion internally. They were not observing these failures from a distance; they were seeing them firsthand with their own clients and prospects. Their response was to build a purpose-built product: AI application hosting, designed to bridge the gap between rapid AI development and safe, resilient, enterprise-grade deployment.
The product is built around three pillars:
Pillar One: Hardened Security at Server Level
AI-generated code is inherently prone to vulnerabilities. This is not a criticism of the models; it is an accurate assessment of the current state of vibe coding and LLM-generated codebases. Feldman's argument is that agencies should not have to employ a full-time cybersecurity expert to safely launch an AI application. Instead, the hosting environment itself should do that work.
Hosting.com uses Imunify (which Feldman referred to as Monarch's behavioral analysis) to detect and block malware before it executes, layered with Cloudflare Enterprise as a web application firewall and bot protection. The result is that even imperfect AI-generated code is wrapped in enterprise-grade security at the infrastructure level. The code does not have to be perfect because the environment it runs in is.
Pillar Two: Edge Delivery for Speed
Every AI query requires server-side computation. Feldman made the point vividly: asking ChatGPT a question generates the carbon equivalent of driving a vehicle approximately 15 miles. While he acknowledged that most modern data centers run on renewable energy and offset their emissions, the resource usage that generates that carbon does not disappear.
Servers spin up, compute, and respond, and that takes time.
Latency, Feldman argued, is a silent killer of user experience in AI applications. If a chatbot or AI-powered feature takes five seconds to respond, users leave. Bounce rates triple. The AI functionality that was supposed to be the product's selling point becomes its biggest weakness.
The solution is edge delivery through Cloudflare Enterprise. Hosting.com serves AI applications from hundreds of global edge locations, routing queries intelligently so that the AI interaction feels instant regardless of where the user is located. Speed does not have to be sacrificed for intelligence.
Pillar Three: One-Click Deployment, Infrastructure Friction Removed
The third pillar is about removing the operational complexity that currently sits between idea and launch. When agencies are building AI applications using tools like Cursor, Windsurf, or Hosting.com's own Nova AI Studio, they often have to stitch together multiple separate services just to get a prototype live. Feldman described this as five or more services combined before a client can even see a working demo.
Hosting.com's platform enables one-click deployment: from prompt to live, with a secure domain in a secured environment, in minutes. This is not just a convenience; it changes the economics of pitching. Agencies can launch a live, secure prototype to validate client interest before committing to a full build, without the prototype itself being a security risk.
The Commercial Argument: Liability to Margin
Feldman's closing commercial argument was clear: agencies should not just absorb secure AI hosting as a cost of doing business. They should sell it as a premium service.
When pitching an AI project to a client, the agency should not be pitching a chatbot. They should be pitching a platform: AI-powered functionality backed by enterprise-grade infrastructure, AMD Epic servers, high uptime guarantees, and professional support. This repositioning allows the agency to command a premium for both the build and the ongoing hosting, delivered as a recurring revenue line.
The flip side is equally important. By deploying on a properly hardened, fast, and reliable infrastructure, agencies remove the scenarios described in the three case studies. They stop selling AI experiments that keep them up at night and start selling solutions they can stand behind. Reputation and margin are both protected.
Closing Statement
Feldman's closing was direct. The gold rush is real. Everyone is after AI and everyone should be using it. But the agencies that will win are not the ones who prompt most cleverly. They are the ones taking security seriously. The risk is not abstract: your greatest opportunity can become the reason you lose your biggest client if the infrastructure is not right.
The session ended with a call to action framed around the mine analogy: make your next project bulletproof.
Post-Talk Discussion
The host Andrew Palmer closed the session with reflective commentary, emphasizing personal attention to detail as a safeguard against AI errors. He shared an analogy from his own career in the print industry, in which a client-supplied artwork containing a typographical error required three million leaflets to be reprinted. The contractual question of who bore the cost of that error mirrored the AI liability question: when AI makes a mistake, who is responsible and who pays?
Palmer echoed Feldman's point about locking down LLM data settings, noting that major platforms do allow users to prevent data from entering training pipelines and that this step is essential for anyone handling confidential client information. He also noted that Atarim is SOC2 compliant and undergoes security audits every six months, positioning security compliance as a business investment rather than a burden.
Palmer also mentioned briefly using Nova (Hosting.com's AI Studio) to build a working website prototype in approximately 15 minutes with around five additional prompts for refinement. He offered this as a practical demonstration of the speed at which AI prototyping now operates, which reinforces both the opportunity Feldman described and the urgency of the security argument.
About the speaker
Olly Feldman
Head of Global Sales, Hosting.com
Olly Feldman is Head of Global Sales at Hosting.com, where he works with agencies on hosting strategy in a market being reshaped quickly by AI tools.