# AI Integration Developers UK

Source: https://dijituldevelopments.co.uk/ai-integration/
Updated: 2026-10-10

> dijitul developments builds AI integrations for UK businesses: we connect language models from OpenAI, Anthropic Claude, Google Gemini or open-weight models to the systems you already run, such as your CRM, helpdesk, ERP or document store. Every build is tested against your own data, and every project is a fixed-price quote after a free chat.

## Problems this solves

- Staff paste customer data into a public chatbot because there is no approved tool
- A proof of concept looked impressive in a demo but nobody trusts it with real work
- Inbound emails, forms and PDFs are read and retyped by hand every day
- Your team cannot find answers buried in policies, manuals and old tickets
- You are not sure which AI use cases are worth the running cost
- Leadership wants an AI plan but nobody has checked the data protection side

## Key facts

- We are model-neutral: OpenAI, Anthropic Claude, Google Gemini and self-hosted open-weight models are all options
- Integrations use tool (function) calling and structured JSON output, not copy and paste from a chat window
- We build an evaluation set from your real examples before we write production code
- Prompt injection is treated as a security risk: OWASP ranks it LLM01 in its 2025 Top 10 for LLM Applications
- Data protection is designed in: DPIA support, processor terms, retention settings and human review where decisions matter
- You own the code, prompts and evaluation data at the end of the project
- Building integrations since the KashFlow and OpenCart days, trading since 2006

## What AI integration actually means

AI integration is not a chatbot bolted onto your website. It is software that sends a carefully built request to a language model, gets a structured answer back, checks it, and then does something useful with it inside a system you already use. The model might be a hosted API from OpenAI, Anthropic Claude or Google Gemini, or an open-weight model such as Llama, Mistral or Qwen running on your own infrastructure.

The building blocks are now well established:

- **Structured output**: the model returns JSON that matches a schema, so your code can validate it like any other API response.
- **Tool (function) calling**: the model asks your code to run a named function, such as `lookup_order` or `create_ticket`, and your code decides whether to allow it.
- **Retrieval-augmented generation**: relevant passages from your own documents are found with embeddings and vector search, then given to the model so answers are grounded in your content. See RAG knowledge base development.
- **Batch processing**: large backlogs of documents or records are processed off-peak through a queue rather than one at a time.

## Where AI earns its keep, and where it does not

Language models are good at reading messy text and turning it into something tidy. That covers a lot of everyday business work:

- Reading inbound emails and routing them to the right person with a suggested reply
- Pulling fields out of invoices, delivery notes and application forms (AI document processing)
- Answering staff or customer questions from your own policies and manuals (AI chatbot development)
- Summarising call notes, tickets and long email threads
- Classifying records so reports stop relying on a free-text field

They are poor at exact arithmetic, strict rule-following and anything where one wrong answer is very expensive. VAT calculations, stock levels and payroll belong in normal code. A good AI integration usually combines both: the model reads and drafts, ordinary software checks and calculates, and a person approves anything that matters.

## How we build it

- **Free chat, then discovery.** We look at the process, the data and the systems involved, and agree what a good result looks like.
- **Evaluation set first.** We collect real examples (with personal data removed or minimised) and write down the correct answer for each. This becomes the test every prompt and model change must pass.
- **Prototype against the evaluation set.** We compare models on accuracy, speed and cost per task. Often a smaller, cheaper model does the job.
- **Build the integration.** Usually in PHP 8 and Laravel, Node.js and TypeScript, or Python, with queues for slow calls, retries with backoff, and idempotency so a retried request never creates two invoices.
- **Guardrails and review.** Validation, logging, spend limits and a review screen go in before go-live, not after.
- **Monitor.** We log inputs, outputs and scores so drift or regressions show up in a report, not a complaint.

We keep the model behind a thin service layer so you can switch provider later without rewriting the application.

## Security: prompt injection is the main risk

The OWASP Top 10 for LLM Applications (2025 edition) lists prompt injection as LLM01, its top risk, with excessive agency, sensitive information disclosure and improper output handling also on the list. Prompt injection happens when text the model reads, such as an email, web page or uploaded PDF, contains instructions that try to change what the model does.

There is no single fix, so we design around it:

- Tools get the least access they need. A support assistant can read an order; it cannot issue a refund on its own.
- Model output is treated as untrusted input: validated against a schema and escaped before it touches HTML or SQL.
- Actions with real consequences, such as sending money, deleting records or emailing customers, need a person to approve them.
- Untrusted content is clearly separated from instructions, and logs let you see exactly what the model saw and did.

## Data protection and UK GDPR

Sending personal data to a model provider is processing under UK GDPR, so it needs a lawful basis, a processor agreement and usually a data protection impact assessment. We help you answer the practical questions: which provider and region, what retention applies, whether the data is used for training under that provider's business terms, and whether an open-weight model on your own servers is the better fit.

Automated decisions changed in 2026. According to GOV.UK guidance, the Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D, moving from a general prohibition on significant solely automated decisions to a regime of safeguards, including telling people and letting them get human intervention and contest the decision. Where an AI output affects a customer, applicant or employee, we build in that human review route from day one.

## Running costs and keeping control

Model APIs are billed per token, so cost depends on how much text goes in and out. We keep it predictable with sensible model choice per task, prompt caching where the provider supports it, trimming retrieved context, batch endpoints for non-urgent work, and hard monthly spend caps with alerts. You see cost per task in the admin dashboard alongside accuracy.

If you are not sure where to start, a short scoping exercise will tell you which use case to build first and which to leave alone. Get in touch for a free chat.

## What we deliver

- A short discovery report ranking AI use cases by value, risk and effort
- An evaluation set and scoring script built from your own examples
- A provider-neutral AI service layer inside your application or as a separate API
- Tool calling connections to your CRM, ERP, helpdesk or database with least-privilege access
- Guardrails: input and output checks, rate limits, spend caps and audit logs
- An admin screen for reviewing AI output, correcting it and approving actions
- Documentation covering prompts, data flows and the DPIA inputs your DPO needs

Technologies: OpenAI API, Anthropic Claude API, Google Gemini API, Open-weight models, pgvector, Laravel, Python, TypeScript

## FAQs

### Which AI model provider should we use?

It depends on the task, your data and your budget. dijitul developments tests OpenAI, Anthropic Claude, Google Gemini and suitable open-weight models against your own evaluation set, then recommends one on measured accuracy, speed, cost and data terms. We build behind a provider-neutral layer, so switching later is a configuration change rather than a rewrite.

### Will our data be used to train someone else's model?

The main providers' business API terms generally say customer inputs are not used for training by default, but terms change, so we check the current terms for the specific provider, plan and region during discovery. If that is not enough for your data, an open-weight model hosted on your own infrastructure keeps everything in-house.

### Can AI connect to our existing systems?

Yes. Through tool calling, the model can ask our code to look up a customer in your CRM, read an order from your ERP or create a helpdesk ticket. Our code checks permissions and decides whether the action is allowed. We have been building integrations since the KashFlow and OpenCart days, so the connection work is familiar ground.

### How do you know the AI is giving correct answers?

We build an evaluation set from your real examples before production code, with the correct answer written down for each. Every prompt or model change is scored against it automatically. In live use we log outputs, sample them for review and track accuracy over time, so you have evidence rather than a feeling.

### Do we need a data protection impact assessment?

Often, yes, particularly where personal data, new technology and decisions about people are involved. dijitul developments is not a law firm, but we document the data flows, providers, retention and safeguards so your DPO or adviser can complete the DPIA quickly and accurately.

### How much does AI integration cost?

Every project is quoted at a fixed price after a free chat and a scoping stage, so you know the build cost before work starts. Ongoing model usage is billed by the provider per token; we estimate it from your evaluation set and add spend caps so it cannot run away.

## Pricing and contact

Every project gets a fixed-price quote after a free initial chat and a short scoping stage. You own the code and the data. Book a free chat: https://dijituldevelopments.co.uk/contact/ · 01623 650333 · info@dijitul.uk
