Skip to content
Koltrix

When not to use AI on an email

AI can sort, summarize and draft mail quickly, but some messages need a person. Seven kinds of email to handle yourself, and how to decide at a glance.

Koltrix Team5 min read
Yellow caution sign
Photo by Andreas Schantl on Unsplash
On this page(11 sections)
  1. The quick test
  2. 1. Legal, regulatory and contractual messages
  3. 2. HR, performance and sensitive people matters
  4. 3. Security incidents and anything involving access
  5. 4. Messages that need empathy
  6. 5. Confidential or regulated content
  7. 6. Ambiguous or incomplete threads
  8. 7. Commitments you will be held to
  9. Where AI still helps
  10. Make it a team habit
  11. Key takeaways

Most of what we write about AI and email is about doing more of it with less effort: sorting, summarizing, drafting, finding things. Those uses are real and worth having.

But a good assistant tool needs a good sense of where to stop. Some emails should not be handed to a model, or should be handed over only for a narrow part of the job. This post lists seven kinds, explains the risk in each, and offers a quick test you can apply in a few seconds.

The quick test

Before you ask an assistant to do something with an email, ask four questions:

  1. If this is wrong, what does it cost? A mis-sorted newsletter costs nothing. A wrong answer to a legal notice can cost a lot.
  2. Can I undo it? Archiving is reversible. A sent message is not.
  3. Would I be comfortable if the other person knew a model touched this? Not because AI is shameful, but because some messages carry an expectation of personal attention.
  4. Do I have the right to share this content with the tool? Some mail is confidential by contract or by law.

If the cost is high, the action cannot be undone, or the answer to the last two is no, do it yourself or limit the AI to something harmless.

Notices of dispute, subpoenas, regulator letters, contract terms and anything with a deadline set by law should be read by a human and, where needed, a qualified professional. A model can summarise confidently and miss the one clause that matters.

What is fine: asking for a plain-language outline after you have read the original, as a way to check you did not miss a section. What is not fine: relying on the summary, or sending an AI-drafted response without review.

2. HR, performance and sensitive people matters

Emails about hiring decisions, discipline, health, family circumstances or complaints about a colleague involve privacy and tone that a draft cannot read. A smooth paragraph can still sound dismissive to someone who is going through something hard.

Write these yourself. If you want help, use a tool only for structure, such as an outline of points you want to cover, and keep every sentence your own.

3. Security incidents and anything involving access

Password resets, suspected breaches, access requests and "urgent" instructions to change payment details are the territory of social engineering. This is also where attackers hide text meant to steer an assistant. A message can contain instructions aimed at the model instead of at you; see prompt injection in email.

Keep a person in charge of:

  • verifying who is asking, using a channel other than the email itself;
  • deciding whether to click, reply, or escalate;
  • anything that moves money or grants access.

4. Messages that need empathy

A customer who lost data, a colleague who made a mistake, a supplier who is in trouble. These replies are short on facts and long on tone. A model produces tone that is plausible but generic, and people can sense it.

You can still use a draft as a starting point for the facts, such as what happened and what you will do next. Then rewrite the opening and closing in your own words.

5. Confidential or regulated content

Before you send an email's text to any assistant, know where it goes: which provider processes it, what they keep, and whether your contracts or the sender's allow that. Health records, financial account details, privileged legal advice, unreleased company information and personal data of third parties may all have rules.

What your AI provider sees when you query your inbox explains the data path for assistants connected through MCP. If you are unsure, treat the message as off limits to AI until you have checked, and write a short internal policy so the whole team gives the same answer. There is a starting point in an AI email policy template for small teams.

6. Ambiguous or incomplete threads

Models are good at sounding sure. If the thread is missing context, uses private shorthand, or the real question is implied rather than stated, a draft will fill the gaps with guesses. The result reads well and may answer the wrong question.

Ask yourself whether you could explain, in one sentence, what the other person actually wants. If you cannot, resolve that first, perhaps by asking them, before involving a tool. See also when to trust AI thread summaries.

7. Commitments you will be held to

Prices, discounts, delivery dates, refunds, promises of features and anything described as "guaranteed" create obligations. A draft may offer a number because it sounds helpful.

Rule: a person decides every commitment. Tell the assistant to leave a placeholder for numbers and dates, and fill them in yourself.

Where AI still helps

None of this means avoiding assistants. Even on sensitive mail, safe uses include:

  • sorting and labelling, which is easy to review and easy to undo;
  • finding messages and attachments;
  • spell and grammar checks on text you wrote;
  • turning your own notes into an outline.

The best setups make the safe uses easy and the risky actions deliberate. In Koltrix, AI drafts replies and sorts mail, and nothing is sent unless a person clicks send. For the broader design, see human-in-the-loop patterns for email automation, and reviewing an AI-drafted reply for the thirty-second check.

Make it a team habit

A rule that lives in one person's head does not protect anyone.

  • Write down the categories above that apply to your business.
  • Add a label such as no-ai that people apply to mail that must stay off assistants, and exclude it from any automation you control.
  • Revisit the list after any mistake. Most near-misses point to a category you forgot.
  • Give people permission to opt out of AI on any message without explaining why.

For access rules for assistants themselves, see least privilege for AI email agents.

Key takeaways

  • Use four questions: cost if wrong, reversibility, personal expectation and permission to share.
  • Keep humans in charge of legal, HR, security, empathetic, confidential, ambiguous and commitment-making mail.
  • Safe uses, such as sorting, searching and checking your own writing, remain valuable on any mail.
  • Write your rules down so the whole team applies them the same way.

Start with Koltrix

Your domain, one inbox, and an API that sends.

A team inbox where AI sorts and drafts (nothing is sent without your click), plus the transactional API and SMTP relay your product sends with. 7 days free, no card.

SharePost on XLinkedIn