You mention tokens, what else is in your threat model? Is your AI functionality a custom model?
I am concerned that you haven’t adequately explored and mitigated security and reliability risks involved here before asking folks to YOLO your app into their critical infrastructure.