Search our shop

JFK Løvlien's Nexus, a custom AI agent for business, answering a customer enquiry live on a website at night
ai agents1 min read October 8, 2026

What a Custom AI Agent for Business Actually Does.

There is an AI in the corner of this page. It is not a support widget and not a script, it is the product, running live, and you can try to break it right now. What is actually underneath a custom AI agent, what it refuses to do on purpose, and how to tell whether your business needs one yet.

What a Custom AI Agent for Business Actually Does.

Not a chatbot. Not a demo. A system that answers, qualifies and writes, on your own infrastructure.

There is an AI in the bottom right corner of this page. It is not a support widget and it is not a script. It is the product this page is selling, running live, and you can ask it something hard right now. That is the honest way to describe a custom AI agent for business: not by listing what it could do, but by leaving one switched on where people can break it. This post is what is actually underneath, what it refuses to do on purpose, and how to tell whether your business needs one yet.

TL;DR
  • Nearly every business leaks money in the same four places. The build is different every time. The problem is not.
  • A chatbot follows a decision tree. An agent reasons from your actual business and handles the objection it has not seen before.
  • Every deployment is three things: a public agent, a private workspace for the owner, and ownership of the code.
  • It cannot spend money, delete data or execute code. Those are not settings, they are the shape of the build, and they are why prompt injection has nothing worth stealing.
  • Real estate, trades, corporate and professional services each lose money differently. The fix is shaped to the leak, not to the industry.
  • $100 for an hour, $4,999 plus $299 a month for a build, from $9,999 for enterprise. Sometimes the honest answer is the hour.

Table of Contents

The Four Leaks

I have now scoped builds for property agencies, trades, clinics, professional services and corporate teams, and the same four things come up every time.

Enquiries answered too slowly. Not unanswered. Answered on Tuesday, when they arrived on Saturday night. By then the person has booked with whoever picked up.

The same question answered for the thousandth time. Do you cover my area. What is included. How long does it take. Every one of those answers already exists, and a person is retyping it.

Work produced by hand that could be produced to a pattern. Quotes written at ten at night. The report rebuilt every Monday. Five thousand product descriptions that each need to be different.

Knowledge that exists in exactly one head. Usually the founder's. It goes on holiday, and eventually it retires.

A property agency has all four. So does a one van plumber and so does a corporate department with nine layers of sign off. The build is different every time. The problem is not.

There is a question I ask on every call that gets to the truth faster than any requirements document: what part of your week would you hand over if you could? People answer that honestly and immediately, and the answer is almost never what they said they wanted when they got in touch.

The private owner workspace inside a custom AI agent for business, built by JFK Løvlien for strategy and market data

Why This Is Not a Chatbot

A chatbot follows a decision tree somebody drew. It can handle the questions that person thought of. The moment a customer phrases something sideways, or asks two things at once, or raises an objection that is not on the tree, it falls back to "let me connect you with a human", and everybody's time has been wasted including the customer's.

An agent reasons. It holds your documents, your pricing, your policies, your history and the awkward edge cases, and it works out what this particular person is actually asking. It handles a real objection rather than deflecting it. It writes original content in your voice. It can be wired to live data you define, so it tells you what moved in your market rather than waiting to be asked.

The difference shows up most clearly in what happens when someone is rude, confused or testing it. A script breaks. A system that reasons stays useful.

It also matters where it runs. A shared platform means your conversations and your data sit in somebody else's product. Every build here is deployed on your own infrastructure, isolated, with nothing pooled and nothing used to train anything.

Public, Private, Owned

Every deployment has the same three parts, whatever the industry.

Public. The agent on your website or in your location. It sells, answers and recommends around the clock, in your voice, and it works out which enquiries are worth your attention rather than forwarding all of them.

Private. A workspace only you reach, behind a passphrase or biometric access. This is the half nobody asks for and the half that usually gets used most. Content creation, strategy, market data, competitor tracking, the first draft of everything. Same system, different job, and it does not answer to customers.

Owned. It runs on your hosting, under your keys, in your repository, on your domain. Cancel the subscription and everything stays yours and keeps running.

That third one is not a courtesy. It is the difference between a tool and a tenancy.

What It Cannot Do, On Purpose

Most AI security talk is about making the model behave. That is the wrong layer to fight on.

Prompt injection is the attack that matters here, and it sits at the top of the OWASP Top 10 for large language model applications for good reason. The mechanism is simple: an attacker puts instructions somewhere the model will read them, and the model cannot reliably tell instructions from data, because both arrive as text in the same stream. Hidden text in a web page, a crafted message, an instruction buried in a document. You cannot train this away completely, and anyone who tells you their prompt is clever enough to resist it has not thought about it hard enough.

So the answer is not to make the agent resist temptation. It is to make sure there is nothing worth tempting it with.

A Nexus cannot spend money. It cannot delete or alter records. It cannot execute code. It has no open browser a visitor can steer toward a page of their choosing. Live market data is gathered on a schedule by the system itself, not by a stranger asking it to go and look at something. Strip the capability and the worst case for a successful injection is that the agent says something it should not have, which is embarrassing rather than expensive.

On top of that sits IRONCLAD, ten layers covering injection defence, bot protection, client isolation and API abuse prevention. But the layers are not the argument. The argument is that there is no money, no database and no shell at the other end of them.

This is also why I will not build an agent with payment or deletion rights, however the request is framed. The capability is the vulnerability.

A custom AI agent for business by JFK Løvlien, running on the owner's own infrastructure with isolated data and keys

What It Looks Like In Your Industry

Real estate. Buyers look at night and at weekends, which is exactly when agents are not working. Response speed decides who gets the lead more often than price or skill does. The agent answers properly at 2 AM from the real portfolio, sorts serious buyers from browsers, and gets viewings into a calendar without phone tag. The build nobody asks for and most of them end up wanting is automatic area and market reports, so you arrive at a door with something worth saying.

Trades and contractors. You cannot answer the phone with both hands inside a boiler. The caller does not leave a message. They ring the next number and book with whoever picks up, and that happens all week. No statistics needed here, because every contractor recognises his own week in that sentence. The fix answers every call and message, works out whether it is a real job, takes the details and puts it in the diary while you keep working.

Large corporate. What they fear is not cost. It is data leaving their control, an incident with their name on it, and a procurement cycle that takes nine months. The answer is a narrow, contained first build on their own infrastructure that proves value without betting the department. Internal process automation and turning data into readable reporting are less glamorous than customer facing work, far easier to approve, and where the returns actually show up.

Professional services. Lawyers, accountants, consultants and architects sell hours, so anything that returns hours is directly revenue. Reading and summarising documents, drafting the first version of everything, answering the client questions that do not need a partner, finding what is buried in the archive. Confidentiality is not a feature in this sector, it is the condition of entry, which is why isolation comes first in the conversation.

Regulated industries get one more rule written into the build. In property it answers from the agency's own listing data and never invents a figure. In law and finance it routes and informs and does not give advice. In a clinic it handles logistics and never touches clinical judgement. The full list by industry is here.

What You Actually Own

The code. The infrastructure it runs on, which is your own hosting account, your repository, your domain and your API key. The knowledge base built out of your business.

The $299 a month keeps it maintained and current. Your business changes, prices move, products launch, policies get rewritten, models get deprecated. A system nobody updates becomes a system that confidently gives last year's answers, which is worse than no system.

What the subscription does not do is keep it switched on. Cancel and everything stays yours and keeps running. There is no kill switch, because there is nothing for me to switch off. You are paying for maintenance, not for permission.

What It Costs

$100 for an hour. One focused call. You describe the business, I say where I think the money is leaking and what shape a fix takes. You leave with a direction whether or not you build anything. Book it here.

$4,999 plus $299 a month for a full Nexus. One to two weeks from kickoff to live. Knowledge base, system prompt, security, styling, and testing against real questions rather than convenient ones.

From $9,999 for enterprise. Multi agent systems, deep integrations, automation across a whole operation, multi location rollouts. Scoped before anything is quoted. Start there.

Running costs sit in your own accounts, typically $10 to $30 a month depending on traffic. You can see the spend and you control it.

How To Tell If You Need One Yet

Three honest tests.

Can you name the leak? If you can say "I lose jobs because I cannot answer the phone on site" or "my team rewrites the same report every Monday", you are ready. If the answer is "everyone is doing AI", you are not, and a build will disappoint you.

Would fixing it pay for itself inside a year? For a property agency catching a handful of extra weekend leads, obviously. For a one van operation, a $4,999 build is a serious outlay and often the honest recommendation is the hour on a call instead. I would rather say that than take the money.

Is there someone to keep it true? Not a technical person. Someone who notices when the pricing on the website is wrong. A system is only as current as the business is willing to keep it.

If you are unsure, the fastest way to find out costs nothing: ask the agent in the corner of this page what it thinks about your situation. It will tell you if the answer is that you do not need one yet. I built it that way deliberately, because a client who buys the wrong thing is a refund with extra steps.

Summary

  • A custom AI agent for business addresses the same four leaks in nearly every company: slow enquiries, repeated questions, handmade work, and knowledge trapped in one head.
  • A chatbot follows a tree. An agent reasons from your real business and handles what the tree never anticipated.
  • Every build is public agent, private owner workspace, and ownership of the code.
  • It cannot spend money, delete data or execute code. Prompt injection is defused by removing the capability, not by trusting the model's judgement.
  • Real estate, trades, corporate and professional services leak differently, and regulated sectors get hard rules written into the build.
  • Cancel the subscription and everything stays yours and keeps running. You pay for maintenance, not permission.
  • $100 for an hour, $4,999 plus $299 a month for a build, from $9,999 for enterprise. Sometimes the right answer is the hour and nothing else.

JFK Løvlien

JFK Løvlien is the founder of JFKAISLAY and the builder behind Nexus, a custom AI agent platform for businesses, and Jane SEO, an AI SEO agent for Shopify. He writes the Feeder Series thrillers and is building an iPhone game in their world. Norwegian entrepreneur, AI builder, and Shopify operator based in Santos, Brazil. Runs four live e-commerce stores. 100,000+ products optimized. Built production AI systems from scratch. Runs on Claude Max 20x.

Frequently Asked Questions

What is a custom AI agent for business?

A system built for one company that answers customers in that company's voice, qualifies real enquiries, creates content, and gives the owner a private workspace for strategy and market intelligence. It is trained on your business, deployed on your infrastructure, and it is not a template with your logo on it.

How is this different from ChatGPT with a custom prompt?

A custom prompt gives you a general model with instructions. This gives you a system: your knowledge base, your guardrails, your data sources, isolated hosting, security built for the job, and behaviour that is tested against the questions your customers actually ask. The model is one component.

Can an AI agent be hacked into doing something harmful?

Prompt injection is a real and largely unsolved problem, and it is the first entry in the OWASP Top 10 for LLM applications. The defence here is architectural. The agent cannot spend money, delete data or execute code, and it has no open browser a visitor can direct. A successful injection gets an unhelpful answer, not a transaction.

How long does it take to build?

One to two weeks from kickoff to live deployment. That covers the knowledge base, the system prompt, security implementation, styling and testing against real questions.

What happens if I cancel the subscription?

Everything stays yours and keeps running. The code, the hosting, the keys and the knowledge base are already in your accounts. The subscription buys maintenance and updates, not the right to keep using it.

Does it work for a business that is not e-commerce?

Yes, and most of the interesting builds are not. Property, trades, clinics, professional services and corporate teams all have the same four leaks. Only the shape of the fix changes.

Can I see one working before I buy?

You already are. The agent in the corner of this page is a Nexus. Ask it something difficult, try to catch it out, ask it about a business it has never heard of. That is the demo, and it is the product.

What if I just want advice rather than a build?

Then book the hour. It exists for that. Plenty of those calls end with a direction and no build, which is a result rather than a failure.

Share