An organization receives a quote for a very simple informational website: tens of thousands of yen upfront, plus a monthly maintenance fee.
Looking only at the pages, the obvious reaction is:
“Couldn’t generative AI build this in an afternoon?”
That reaction is often reasonable. Copy, layout, responsive design, simple forms, and basic code can now be produced much faster than before.
But saying “I could build this myself” can open a different future:
“Great. Then can you do it?”
At that moment, a small website project can quietly evolve into a lifetime appointment as the unofficial web administrator.
1. The key distinction: production cost and responsibility cost are not the same thing
Generative AI has dramatically reduced the labor needed for production.
It can draft copy, propose structure, write page code, adjust layouts, and generate revisions.
That part is genuinely cheaper and faster.
But an organization’s vendor fee may include much more than production:
- collecting and reconciling requirements
- receiving change requests
- deploying changes
- managing domains and encryption certificates
- keeping backups
- applying updates and security fixes
- recovering from outages
- answering “the site looks broken” messages
- documenting the system for future staff
- accepting contractual responsibility for support
So the organization is not necessarily buying only web pages.
It may also be buying the right to hand the annoying parts to someone else.
2. What AI really made cheaper
For a small informational site, AI is extremely effective at reducing routine production work.
It can accelerate:
- site outlines
- headings and copy
- visual variations
- responsive layouts
- basic page code
- common edits
- content cleanup
- simple deployment automation
So if someone hears only “a few simple pages for a large upfront fee,” it is natural to question the price.
The mistake is treating build time and contract value as identical.
AI might generate the code in thirty minutes.
It does not automatically eliminate next month’s requests to change office hours, replace staff information, fix a form, or explain why the site is unavailable.
The code got faster.
The requester did not disappear.
3. What a vendor may actually be selling
A finished screen hides a lot of work.
For an organizational site, the vendor may be responsible for several layers.
Requirements and coordination
Someone has to decide what belongs on the site and reconcile conflicting requests.
Organizations rarely speak with one voice. One person remembers one decision, another remembers a different one, and a committee may reverse both.
Hosting and release management
Someone manages the domain, certificates, hosting, configuration, and recovery process.
Maintenance and security
Software components need updates and vulnerabilities need attention.
The U.S. National Institute of Standards and Technology treats software security as a lifecycle issue rather than something that ends when development is finished.[1]
Its patch-management guidance also describes patching as preventive maintenance and a cost of operating technology.[2]
Incident response
When the site is down, the contact form fails, or a layout breaks, someone must receive the report, diagnose it, and restore service.
Handover
When staff change, ownership of the domain, credentials, procedures, and contracts must not vanish with one individual.
A website does not turn into a statue when it launches.
Launch is when its life as a maintained system begins.
4. A monthly maintenance fee means nothing without scope
A monthly fee is not automatically cheap or expensive.
If it covers little more than keeping a hosting bill paid, it may look excessive.
If it includes the following, it is a different product:
- hosting and domain administration
- backups
- software updates
- security work
- uptime monitoring
- first-line incident response
- small content edits
- support for staff questions
- restoration work
- migration assistance when the contract ends
CISA has repeatedly argued that technology providers should take ownership of customer security outcomes rather than pushing all security burden onto customers.[3]
The useful question is therefore not merely:
“How much per month?”
It is:
Who is responsible for what, to what extent, and how quickly?
5. Self-building works especially well when the site is truly yours
A personal site has a beautifully simple structure.
- decision maker: you
- builder: you
- person who breaks it: you
- person who repairs it: you
- person who bears the loss: you
Everything points to the same person.
If you break the design at midnight, you can decide that fixing it tomorrow is acceptable.
You can choose how much downtime is tolerable, how many backups are enough, and which annoying features should simply be removed.
That is an ideal environment for AI-assisted building.
If you do everything yourself, you can also accept all the responsibility yourself.
Decision rights and accountability are aligned.
6. The worst structure for someone else’s organizational site
The dangerous version looks like this:
- person doing the work: you
- people making decisions: other people
- people requesting changes: several
- person blamed when something goes wrong: somehow you
- compensation: possibly goodwill
This is not mainly a technical problem.
It is a triangle from hell made entirely of concentrated responsibility.
“Can you change just one sentence?”
“Can you add just one photo?”
“AI makes that instant, right?”
Each task may genuinely take only a few minutes.
The hard part is who approved the change, who verifies it after release, who rolls it back if wrong, and whether all future requests now come to the same volunteer.
A five-minute edit can quietly become a five-year support arrangement.
7. Easier production can actually increase the number of requests
There is a small paradox here.
When every change required a paid vendor request, people often bundled requests together.
When a nearby person has AI and can “fix anything quickly,” the organization may start thinking:
“This should be easy, right?”
Time per request falls.
The number of requests rises.
Once production stops being the bottleneck, the bottleneck moves to approvals, communication, prioritization, explanation, and accountability.
AI may make code ten times faster.
It does not make a committee decide ten times faster.
The machine enters the future.
The meeting stays exactly where it was.
8. To judge a quote, inspect the scope before the number
Do not evaluate a web quote only by counting pages.
Check at least these items.
Initial build
- number of pages
- copywriting scope
- design depth
- mobile support
- contact forms
- editing tools
- member or login features
- content migration
- accessibility work
- basic search visibility setup
Ongoing maintenance
- hosting and domain fees
- backup frequency
- software and security updates
- uptime monitoring
- incident contact method
- response time
- how many content edits are included
- pricing for new photos or pages
- third-party service costs
End of contract
- who owns the domain
- whether source files are handed over
- whether administrator access is transferable
- whether another vendor can take over
- whether the site survives cancellation
If very little is included and the fee is still large, asking “what exactly are we paying for?” is reasonable.
If maintenance, recovery, updates, and handover are clearly included, that is no longer the same product as “a few pages of code.”
9. When self-building fits, and when outsourcing fits
AI-assisted self-building fits better when:
- there is essentially one decision maker
- downtime would not cause serious harm
- updates are infrequent
- little sensitive or member data is involved
- you can back up and restore the site yourself
- you can remove troublesome features instead of supporting them forever
- you are willing to remain responsible for maintenance
Outsourcing becomes more valuable when:
- many stakeholders are involved
- incorrect public information could damage trust
- regular updates are required
- someone must answer support requests
- security work must continue over time
- the site must survive staff turnover
- an outage needs a clearly accountable responder
Do not decide only by technical difficulty.
Ask:
When this fails, who answers the phone?
10. People may be paying less for code than for the person whose name is attached to the problem
AI has absolutely reduced the cost of producing websites.
That should put pressure on old production methods and pricing that assume every page still requires large amounts of manual work.
But it does not follow that all website vendors are now unnecessary.
Maintenance, updates, recovery, coordination, support, security, and handover remain.
For your own site, doing everything yourself can be perfectly rational.
You accept the responsibility because it is yours.
For someone else’s organization, however, saying “AI can build this quickly” can accidentally become an unpaid permanent support contract.
Sometimes paying an external vendor is rational even when the pages themselves are easy to generate.
You are not necessarily buying expensive HTML.
You may be buying a world in which someone other than you answers the late-night message: “The website won’t open.”
References
- NIST, Secure Software Development Framework (SSDF) Version 1.1: https://csrc.nist.gov/pubs/sp/800/218/final
- NIST, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology: https://csrc.nist.gov/pubs/sp/800/40/r4/final
- CISA, Under the Digital Radar: Defending Against People’s Republic of China’s Nation-State Cyber Threats to America’s Small Businesses: https://www.cisa.gov/news-events/news/under-digital-radar-defending-against-peoples-republic-chinas-nation-state-cyber-threats-americas


