The post has been translated automatically. Original language: Russian
Everyone is adding AI now, but half of the projects end up with an expensive toy that doesn't affect the metrics. We share our practice on how to approach this in an engineering way.
1. First the task, then the technology
Not "let's screw up the AI", but "what specific pain will it cover". AI really pays off where there is routine, volume, and text: support, application processing, content generation, and knowledge base search. If the task is solved by ordinary logic or a simple script, do not complicate it.
2. Don't train your model. Use the API
A common mistake of early teams is to try to "train a neural network." In 99% of cases, this is unnecessary and ruinous. Take ready-made LLMs through the API (Anthropic, OpenAI, Google, etc.), and use according to your specifics: industrial engineering — correctly formulated instructions close most cases; RAG (retrieval-augmented generation) — connecting your knowledge base/documents so that the model responds to your data rather than "hallucinating"; Fine-tuning — only when everything else has already been squeezed out and a stable narrow format is needed.
3. Keep the person in the loop
Especially at the start: the AI prepares a draft/response, and the human confirms it. This protects against errors in client communications and gives you the data on which the system becomes more accurate.
4. Consider the cost and speed from the first day
Two parameters that kill AI features in the product: the price per request and the latency. Practice: cache duplicate answers, choose a model for the task (don't take the top one where the easy one is enough), set limits. The same feature on a "cheap" and "expensive" model may differ significantly in cost with the same result.
5. Set limiters (guardrails)
AI in a product without a framework = risk. Minimum: filtering of unwanted input/output, clear boundaries of "what the assistant doesn't talk about", folback on a live person, logging for error analysis.
6. A quick start in a week, not a quarter
A working approach: take one narrow scenario (for example, AI answers to the 20 most frequent customer questions), assemble a prototype on the API in a few days, test it on real requests, measure the effect, and only then scale. A small working case is more useful than a large "AI-platform" plan in a presentation.
A short checklist before implementation: ✅ there is a specific task with a measurable metric The API + prompt/RAG path has been chosen, rather than learning from scratch , the cost of the request and latency are calculated , there is a man in contour and guardrails You start with one narrow scenario
Крупные утечды — в новостях, но малый бизнес теряет данные тише и чаще. Причём почти всегда не из-за хитрых хакеров, а из-за простых недосмотров. Разбираем пять самых частых и как их закрыть без бюджета на безопасность.
1. Один пароль на всё и без второго фактора
Самая частая причина. Один и тот же пароль в почте, CRM и соцсетях — взломали одно, получили всё. Что делать: разные сложные пароли (менеджер паролей это решает) и обязательно двухфакторная аутентификация на почте и ключевых сервисах.
2. Общие аккаунты «на всех»
Когда вся команда сидит под одним логином, вы не знаете, кто что сделал, и не можете отозвать доступ у одного человека. Заводите отдельные доступы каждому — это и безопасность, и прозрачность.
3. Уволился сотрудник — доступы остались
Классика: человек ушёл, а его доступ к почте, таблицам и соцсетям остался. Заведите простой чек-лист офбординга: что отозвать при уходе каждого. Пять минут работы против большого риска.
4. Фишинг и невнимательность
Большинство утечек начинается с письма «оплатите счёт» или «подтвердите вход». Правило: не переходить по ссылкам из неожиданных писем, проверять адрес отправителя, не вводить пароли по ссылкам из сообщений. Обучите этому команду — это дешевле любой защиты.
5. Нет резервных копий
Данные теряют не только из-за взлома, но и из-за случайного удаления или сбоя. Настройте регулярный автоматический бэкап важного (клиентская база, документы, контент) — и проверьте, что из него реально можно восстановиться.
Проверка на сегодня: включён ли второй фактор на рабочей почте, есть ли у каждого свой доступ, и восстановите ли вы данные, если завтра потеряете доступ к основному аккаунту. Три «нет» — три задачи на эту неделю.
Главное: безопасность малого бизнеса — это не про дорогие системы, а про базовую гигиену. Закрыв эти пять дыр, вы снимаете большую часть реальных рисков.
💬 С какой из этих проблем сталкивались вы? Поделитесь в комментариях 👇