Skip to content
RU
← All articles

Build a Website with AI: 9-Point Pre-Launch Checklist

A laptop showing a web page on the left and browser developer tools with network requests on the right

Yes, you can build a website with AI in an afternoon: describe the business to an AI website builder, or ask a coding assistant to write the pages and deploy them to a host. The hard part comes before launch. Generated sites routinely ship without HTTPS redirects, security headers, working links, real meta tags or protected API keys.

Can AI really build me a website?

It can build a working first version, and for a landing page, portfolio or service business site that version is often close to usable. What AI does well is the visible layer: layout, copy, colors, sections. What it does badly is everything the preview does not show — server configuration, response codes, meta tags, forms that actually deliver, and where secrets live. That split is predictable, which is why a short pre-launch checklist catches most of the problems.

Can I build my own website using AI? Three approaches

AI website builders

You describe what you do, the builder proposes a structure, text and design, and you edit blocks visually. Hosting, the TLS certificate and often the domain are handled by the platform. This is the shortest path for simple sites, but you can only change what the platform exposes in its settings.

Code from an AI assistant

A chat model or an assistant inside your code editor writes HTML, CSS and JavaScript or a React/Vue project, and you deploy it yourself to static hosting or a VPS. You get full control and full responsibility: redirects, headers, the server and deployment are yours to configure.

Prompt-to-app platforms

These services generate a complete web app with a database and publish it on their own subdomain. They produce the most surprises at launch: the result is almost always a single-page application (SPA) that renders content in the browser, and the frontend often talks to the database directly with a key embedded in the page.

ApproachWho handles the server and HTTPSTypical launch problems
AI website builderThe platformPlaceholder copy, identical titles, oversized images, forms without a privacy notice
Assistant-written code on your own hostingYouNo HTTPS redirect, no security headers, API keys in JavaScript, links to pages that do not exist
Prompt-to-app platformThe platform, or you after exportContent only in JavaScript, every URL returns 200, database keys in the client, a leftover noindex

Can ChatGPT build a website?

ChatGPT and similar chat models can write the code for a complete static site and explain how to deploy it, but they do not host it, and they cannot see what your live server actually returns. The model also tends to fill gaps with plausible fakes: lorem ipsum, a phone number like (555) 123-4567, invented testimonials and statistics, a menu that links to /about and /blog pages nobody created, and a page title left over from the starter template (a fresh Vite React project ships with the title "Vite + React"). Treat the generated code as a draft that still needs a review against real data.

Pre-launch checklist for an AI-built website

What to checkHowWith
HTTPS and certificatehttp:// redirects to https:// with a single 301; the certificate covers both the www and bare domain/ssl, curl -sI http://example.com
Security headersStrict-Transport-Security, X-Content-Type-Options and a Content-Security-Policy or at least X-Frame-Options are present/security
Speed and imagesImages in WebP or AVIF, width and height set on img, no multi-megabyte files/speed
404s and broken linksA made-up URL returns 404; menu and footer links resolve/broken-links
robots.txt and noindexNo Disallow: /, meta robots noindex or X-Robots-Tag left over from stagingcurl -s https://example.com/robots.txt
Titles, descriptions, duplicatesEvery page has its own title and description; no duplicate URL variants/seo-audit
Forms and privacyA privacy policy link next to each form; a test submission actually arrivesManual test
Secrets in client JavaScriptNo API keys in the built bundle; .env and .git are not reachablegrep, curl
Uptime after launchThe site and certificate are checked automatically, not when a customer complainsUptime monitoring

HTTPS and the certificate

curl -sI http://example.com | head -n 5
curl -sI https://www.example.com | head -n 5

The first response should be a 301 with Location: https://…. If the certificate lists example.com but not www.example.com, visitors on the www address get a browser error. Also look for mixed content: generated code often pulls images or scripts over http://, which browsers block on an HTTPS page.

Security headers

Models write pages; headers are set on the server, so they are usually missing entirely. A sensible baseline is HSTS, X-Content-Type-Options: nosniff, framing protection and a Referrer-Policy. Introduce Content-Security-Policy carefully, because generated code tends to use inline scripts that a strict policy will block. MDN's header reference explains each one, and the full list of checks is in our website security checklist.

Oversized images

cwebp -q 80 hero.png -o hero.webp
magick hero.png -resize 1600x -quality 80 hero.webp

AI image generators output large PNGs that end up displayed in a 300-pixel card. Resize to the displayed size, convert to WebP, add loading="lazy" below the fold and set width and height to prevent layout shift.

curl -s -o /dev/null -w "%{http_code}\n" https://example.com/this-page-does-not-exist

An SPA served with a catch-all fallback returns the same index.html with status 200 for any path, and "page not found" is drawn by JavaScript. Search engines see thousands of junk URLs as real pages. The answer must be 404: configure explicit 404s or build the site statically. Our technical error checklist covers the rest of what breaks on a new site.

Leftover noindex

curl -s https://example.com/robots.txt
curl -s https://example.com/ | grep -i 'name="robots"'
curl -sI https://example.com/ | grep -i x-robots-tag

Staging sites are correctly hidden from search engines; the problem is that the block often ships to production. In WordPress it is the "Discourage search engines from indexing this site" box under Settings → Reading. Also make sure the sitemap URL in robots.txt points to the production domain.

Placeholder titles and client-only content

curl -s https://example.com/services | grep -i '<title'
curl -s https://example.com/services | wc -c

If every URL returns the homepage title and a couple of kilobytes of HTML while the browser shows a long page, the content exists only after JavaScript runs. Pages meant to rank need their text in the server response, through static generation or server-side rendering.

Forms and privacy

A contact form collects personal data, so it needs a working link to a privacy policy, an unticked consent checkbox where the law requires one, and a delivery path you control. Generated forms frequently post to a third-party form service you never signed up for, or nowhere at all. Send a test submission and confirm it lands in your inbox or CRM. How to write the policy itself is covered in our privacy policy guide.

Are API keys safe in an AI-generated website?

Not if they sit in client-side code. Anything shipped to the browser can be read by any visitor. Bundlers make this easy to miss: Vite exposes every environment variable prefixed with VITE_ to client code (Vite docs), and Next.js does the same for NEXT_PUBLIC_. Scan the build:

grep -rnoE "sk-[A-Za-z0-9_-]{20,}|sk_live_[A-Za-z0-9]{10,}|AIza[0-9A-Za-z_-]{30,}" dist/

These patterns catch OpenAI keys, Stripe secret keys and Google API keys; add prefixes for your own services and review matches by eye. Without a build, open DevTools, go to Sources and search all files (Ctrl+Shift+F, Cmd+Option+F on macOS) for key, token and secret. A leaked key is compromised: revoke it, issue a new one and move the call to a server or serverless function. See our AI API key guide for where keys should live. Then confirm that /.env and /.git/HEAD return 403 or 404. Public database keys such as those used by Supabase or Firebase are meant to be in the client, but only with access rules enforced on the database side.

Why an AI-built site breaks after deployment

  • Blank page: assets are built with root-relative paths while the site lives in a subfolder; the browser console (F12) shows 404s for the .js files.
  • 404 on refresh of an inner page: SPA routes exist only in the browser; in nginx add try_files $uri $uri/ /index.html; for app routes, then recheck soft 404s.
  • Forms or AI replies fail: environment variables are not set on the host, the API key hit its limit, or CORS blocks requests from your domain.

How to check an AI-built site in 10 minutes

  1. Run the SSL check on both the www and bare domain.
  2. Run the security headers check and add what is missing.
  3. Run the broken link checker, then the curl commands above for robots.txt, 404s, .env and keys.

After launch, put the homepage and the contact form under uptime monitoring with alerts, and track certificate and domain expiry. Our website monitoring guide explains intervals and alerting.

Frequently asked questions

What's the best AI to create a website?

It depends on who will maintain it. For a simple site with no developer, an AI website builder that also hosts it; for full control, a coding assistant plus your own hosting. Either way, run the same pre-launch checklist.

Can I build a website with AI for free?

Mostly. Builders usually have a free tier on their subdomain, and assistant-written static sites can be hosted free on services such as GitHub Pages. A custom domain costs extra.

Will an AI-built React site rank in Google?

It ranks worse if text appears only after JavaScript runs, all pages share one title and every URL returns 200. Use static generation or server rendering and real 404s.

Can AI check the website it built?

A model can review code, but it cannot see what the live server returns: headers, status codes, the certificate. That requires requests against the real site.

Check your website right now

Check your domain →
More articles: Tools
Tools
Batch URL Checking: Automating Website Monitoring
11.03.2026 · 543 views
Tools
Wayback Machine Guide: Find, Save and Remove Archived Pages
23.09.2026 · 307 views
Tools
Website Builders 2026: What You Give Up and How to Migrate
21.07.2026 · 214 views
Tools
What Is an MCP Server and Why It Matters
15.06.2026 · 195 views