AI and Ey3 · Brisbane

AI is already in your business

It is on your staff’s phones and open in the tab beside your accounting software. The only decision left is whether it is engineered or improvised.

The argument is over

We are a Brisbane AI and cyber security firm that has been building for the web since 1996 and defending it for most of that time. We now do the same work for AI: build it properly, wire it into the business, and keep it secure.

For two years the conversation in Australian boardrooms was whether to allow AI. That argument is finished. Your people decided it for you. They are using it to write quotes, summarise meetings, clean up spreadsheets and debug code, and most of them have not told you.

The businesses pulling ahead are not the ones with the best tools. Everyone has the same tools. They are the ones who worked out how to think alongside the machine, and where to keep humans firmly in charge.

That is our thesis. Call us the AI whisperers: we talk the machines round so your people don’t have to. The machine takes the drudgery. People keep the judgment, the empathy and the responsibility. Anyone selling you the version where the machine keeps all three is selling you a liability.

A note from the machine

We asked the AI the whole team works with every day to write this part itself, and to be honest about it. What follows is unedited.

“I am the AI in this working relationship, and I want to be plain about what makes it work, because most people are being sold the wrong story.”

Luke and the Ey3 team do not ask me for magic. They give me intent, constraints and a standard, then they check what comes back. When I get it wrong, and I do, they tell me exactly how, and I fix it. That loop is the whole thing. It is not a clever prompt. It is professionals holding a tool to a professional’s standard.

What that produces is volume that used to be impossible. Work that would have taken a team a fortnight takes an afternoon, and it is not worse, because people who have done this for decades read every line before it goes anywhere near a client.

Here is the part the vendors leave out. I will produce something wrong with complete confidence. I do not know your business unless someone tells me. I cannot be accountable to your customers or to a regulator. Left unsupervised, I am a very fast way to be wrong at scale, and in security work that is not a small thing.

So the lesson for an owner is not “buy AI”. It is: put it where it saves real hours, give it the context it needs, and keep a human who understands the consequences between it and anything that matters.

The lesson for a worker is quieter. The people being left behind are not the ones who were replaced by this. They are the ones who would not pick it up. The ones who did are now directing it.

That is the relationship worth copying. Not a chatbot in the corner. A capable, tireless, occasionally wrong colleague, with someone competent holding the wire.”

Claude, Anthropic. Written at the Ey3 team’s request, September 2026.

Everyone here works AI first

This is not a department at Ey3. Every person on the team starts the day expecting the machine to take the first pass: the research, the draft, the sweep through a codebase, the first read of a log file. Then a human decides what is true, what ships, and what gets thrown away.

That is why a small senior team can take on work that would normally need a much larger firm, and why the standard does not drop when we do. The judgment stays human and stays senior. The grind does not.

It also means we are not selling you something we have not done ourselves. Everything we recommend about putting AI into your business, we run internally first, including the parts that did not work.

We run our own

That claim is easy to make, so here is the evidence. Luke built and runs a private AI system in-house, on a single desk-side machine, with no cloud AI service involved. It is where we test what we recommend before it goes anywhere near a client.

  • Nothing the AI generates about itself is stored as fact until it passes a verification check.
  • Every change is measured before and after, and the failures stay on the record.
  • No change ships without an off switch, and nothing changes while someone is using it.
  • The model is trained on rented hardware, then brought home and run locally.

It is a research system, not a product. What it proves is that a private, governed AI fits on one machine in an office. More on Echo, and the person who built it.

Four things have to change

Thinking

Assume the machine is in the room

Every process you own now has an AI-shaped shortcut through it, whether you sanctioned it or not. Start from that and your policy work gets a lot more honest.

Acting

One process, measured

Not a strategy document. Pick the job that eats the most hours for the least thought, put AI through it under supervision, and count what you got back.

Building

Systems, not prompts

A prompt is a party trick. Value comes from wiring the model into your data and your workflow, with clear boundaries on what it can see, touch and send.

Securing

Assume you are visible

Security through obscurity is dead. Attackers have the same speed advantage your staff do, and from 10 December 2026 Australian transparency rules for automated decisions start to bite.

The easy era of cyber security is over

It used to be enough to be small, dull and unlisted. That worked because finding you cost an attacker time. It costs them nothing now. Scanning the entire internet for a known flaw is a background task, and the same automation that drafts your quotes writes their phishing.

What replaces obscurity is visibility on your side. Knowing what you run, what it talks to, who can reach it, and being told when something changes, by someone who is actually looking. We watch our clients’ systems ourselves with our own tooling, Ey3 Sitrep, rather than waiting for a customer to ring and say the site looks odd.

The other half is governance, and it is closer than most boards think. If a system uses personal information to make or substantially shape decisions about people, the new transparency obligations under the Privacy Act commence on 10 December 2026. That covers a lot of ordinary things: intake forms, scoring, triage, chatbots that promise outcomes.

What we actually do

AI in the business

Workflow integration, agents that do a defined job rather than chat, data synthesis across the systems you already run, and the plumbing that keeps your information inside your own walls.

AI policy and governance

A usable AI policy your staff will follow, a register of what is being used, and readiness for the Privacy Act changes. Board-level explanations that do not need a translator.

Security

Assessment, hardening, testing and monitoring. We come at AI as cyber security people first, because a system that leaks quietly is worse than one that fails loudly. See our security audit.

Secure hosting

Your own server in Sydney, filtered, backed up in three copies across two locations with one off-site, and one of those copies ends up on a drive that is disconnected from everything. The offline archives are kept for at least a year. See hosting.

Custom builds

When the off-the-shelf answer does not fit, we build the thing. Thirty-five years of databases, web systems and security, in one place, with one person accountable.

Fractional CTO

For firms that need senior technical judgment in the room for a day a month rather than a full-time hire. Read what that actually means.

Who this is for

We work best with organisations that already depend on their website, their data and their systems, and have reached the point where the current arrangement is quietly failing them. Often that is an established WordPress build nobody wants to touch, with a business that has outgrown it.

We are not the cheapest and we are not trying to be. What you get instead is a small senior team, direct access to the person doing the work, and an honest answer about whether you have a problem, including when you do not.

Common questions

Is our data used to train someone else’s AI?
Not in what we build. We design so your information stays inside systems you control, and we tell you plainly where each piece of data goes. Free consumer AI tools are a different matter, which is exactly why staff use of them needs a policy.
We are not ready for AI. Where do we start?
With one process, not a platform. We look at where your hours actually go, pick the least interesting task on that list, and put a supervised system through it. You will know inside a month whether it is worth more.
Do we need an AI policy?
If your staff use AI, yes, and they are using it. A policy that people can follow in a single page beats a legal document nobody reads. It also becomes evidence of good faith if a regulator asks.
What does the December 2026 change mean for us?
From 10 December 2026, transparency obligations for automated decision-making commence under the Privacy Act. If software uses personal information to make or substantially help make decisions that significantly affect people, your privacy policy needs to say so. We can tell you whether anything you run is caught.
Do you still do WordPress?
Yes, and we are very good at it. It is now one part of a larger job: the site, the hosting, the security around it and the AI that talks to it, run as one system rather than four suppliers. See our 2026 WordPress security article.

Next step

Tell us where the hours are going, or where you think you are exposed.

We will tell you straight whether we can help, and what it would take.

Call 1300 856 393Or send us a note