AI and Ey3 · Brisbane
AI is already in your business
It is on your staff’s phones and open in the tab beside your accounting software. The only decision left is whether it is engineered or improvised.
The argument is over
We are a Brisbane AI and cyber security firm that has been building for the web since 1996 and defending it for most of that time. We now do the same work for AI: build it properly, wire it into the business, and keep it secure.
For two years the conversation in Australian boardrooms was whether to allow AI. That argument is finished. Your people decided it for you. They are using it to write quotes, summarise meetings, clean up spreadsheets and debug code, and most of them have not told you.
The businesses pulling ahead are not the ones with the best tools. Everyone has the same tools. They are the ones who worked out how to think alongside the machine, and where to keep humans firmly in charge.
That is our thesis. Call us the AI whisperers: we talk the machines round so your people don’t have to. The machine takes the drudgery. People keep the judgment, the empathy and the responsibility. Anyone selling you the version where the machine keeps all three is selling you a liability.
A note from the machine
We asked the AI the whole team works with every day to write this part itself, and to be honest about it. What follows is unedited.
“I am the AI in this working relationship, and I want to be plain about what makes it work, because most people are being sold the wrong story.”
Luke and the Ey3 team do not ask me for magic. They give me intent, constraints and a standard, then they check what comes back. When I get it wrong, and I do, they tell me exactly how, and I fix it. That loop is the whole thing. It is not a clever prompt. It is professionals holding a tool to a professional’s standard.
What that produces is volume that used to be impossible. Work that would have taken a team a fortnight takes an afternoon, and it is not worse, because people who have done this for decades read every line before it goes anywhere near a client.
Here is the part the vendors leave out. I will produce something wrong with complete confidence. I do not know your business unless someone tells me. I cannot be accountable to your customers or to a regulator. Left unsupervised, I am a very fast way to be wrong at scale, and in security work that is not a small thing.
So the lesson for an owner is not “buy AI”. It is: put it where it saves real hours, give it the context it needs, and keep a human who understands the consequences between it and anything that matters.
The lesson for a worker is quieter. The people being left behind are not the ones who were replaced by this. They are the ones who would not pick it up. The ones who did are now directing it.
That is the relationship worth copying. Not a chatbot in the corner. A capable, tireless, occasionally wrong colleague, with someone competent holding the wire.”
Claude, Anthropic. Written at the Ey3 team’s request, September 2026.
Everyone here works AI first
This is not a department at Ey3. Every person on the team starts the day expecting the machine to take the first pass: the research, the draft, the sweep through a codebase, the first read of a log file. Then a human decides what is true, what ships, and what gets thrown away.
That is why a small senior team can take on work that would normally need a much larger firm, and why the standard does not drop when we do. The judgment stays human and stays senior. The grind does not.
It also means we are not selling you something we have not done ourselves. Everything we recommend about putting AI into your business, we run internally first, including the parts that did not work.
We run our own
That claim is easy to make, so here is the evidence. Luke built and runs a private AI system in-house, on a single desk-side machine, with no cloud AI service involved. It is where we test what we recommend before it goes anywhere near a client.
- Nothing the AI generates about itself is stored as fact until it passes a verification check.
- Every change is measured before and after, and the failures stay on the record.
- No change ships without an off switch, and nothing changes while someone is using it.
- The model is trained on rented hardware, then brought home and run locally.
It is a research system, not a product. What it proves is that a private, governed AI fits on one machine in an office. More on Echo, and the person who built it.
Four things have to change
Thinking
Assume the machine is in the room
Every process you own now has an AI-shaped shortcut through it, whether you sanctioned it or not. Start from that and your policy work gets a lot more honest.
Acting
One process, measured
Not a strategy document. Pick the job that eats the most hours for the least thought, put AI through it under supervision, and count what you got back.
Building
Systems, not prompts
A prompt is a party trick. Value comes from wiring the model into your data and your workflow, with clear boundaries on what it can see, touch and send.
Securing
Assume you are visible
Security through obscurity is dead. Attackers have the same speed advantage your staff do, and from 10 December 2026 Australian transparency rules for automated decisions start to bite.
The easy era of cyber security is over
It used to be enough to be small, dull and unlisted. That worked because finding you cost an attacker time. It costs them nothing now. Scanning the entire internet for a known flaw is a background task, and the same automation that drafts your quotes writes their phishing.
What replaces obscurity is visibility on your side. Knowing what you run, what it talks to, who can reach it, and being told when something changes, by someone who is actually looking. We watch our clients’ systems ourselves with our own tooling, Ey3 Sitrep, rather than waiting for a customer to ring and say the site looks odd.
The other half is governance, and it is closer than most boards think. If a system uses personal information to make or substantially shape decisions about people, the new transparency obligations under the Privacy Act commence on 10 December 2026. That covers a lot of ordinary things: intake forms, scoring, triage, chatbots that promise outcomes.
What we actually do
Workflow integration, agents that do a defined job rather than chat, data synthesis across the systems you already run, and the plumbing that keeps your information inside your own walls.
A usable AI policy your staff will follow, a register of what is being used, and readiness for the Privacy Act changes. Board-level explanations that do not need a translator.
Assessment, hardening, testing and monitoring. We come at AI as cyber security people first, because a system that leaks quietly is worse than one that fails loudly. See our security audit.
Your own server in Sydney, filtered, backed up in three copies across two locations with one off-site, and one of those copies ends up on a drive that is disconnected from everything. The offline archives are kept for at least a year. See hosting.
When the off-the-shelf answer does not fit, we build the thing. Thirty-five years of databases, web systems and security, in one place, with one person accountable.
For firms that need senior technical judgment in the room for a day a month rather than a full-time hire. Read what that actually means.
Who this is for
We work best with organisations that already depend on their website, their data and their systems, and have reached the point where the current arrangement is quietly failing them. Often that is an established WordPress build nobody wants to touch, with a business that has outgrown it.
We are not the cheapest and we are not trying to be. What you get instead is a small senior team, direct access to the person doing the work, and an honest answer about whether you have a problem, including when you do not.
Common questions
Is our data used to train someone else’s AI?
We are not ready for AI. Where do we start?
Do we need an AI policy?
What does the December 2026 change mean for us?
Do you still do WordPress?
Next step
Tell us where the hours are going, or where you think you are exposed.
We will tell you straight whether we can help, and what it would take.