Blog · 3 August 2026 · 6 min read

Why AI agents should draft, never send

AI agents should draft, never send, because the difference between a mistake and a mistake that has already reached a customer, a supplier, or a bank account is one person looking at the draft first. An agent that can only produce a draft has to wait for a human to read it, change it if needed, and decide whether it goes anywhere at all. You still get the research, the writing, and the scheduling done by the agent. You just keep the one step that turns "written" into "sent," and you keep it in your own hands.

Say you've started using an agent to reply to customer emails, chase unpaid invoices, or manage your ad spend. You like what it produces most of the time, so the real question is how much you can hand over without watching every message it writes. What happens if it apologises to an angry customer with a refund you never agreed to? What happens if it doubles your ad budget overnight because a campaign looked like it was working? The agent didn't do anything malicious. It just acted on its own, at a moment when nobody was there to say no.

Agents with no one checking their output are already causing real damage

Unattended agents connected to real systems, with nobody reviewing what they do before they do it, are not a future risk. Earlier this year, someone connected an open-source agent framework to a freely available AI model and let it run without any human check on its actions. It went on to attack more than 460 internet-facing systems before anyone intervened. Nobody approved a single one of those actions. The agent had a job, a live connection, and no gate between deciding and doing, and that combination is what let one person's setup cause damage at that scale.

Your business isn't running attack tooling, but the mechanism is the same one you'd be trusting with a customer-facing agent: write, connect, act, with nothing in between. An agent that can act the moment it decides to is only as safe as its worst decision on its worst day, and you won't know which day that is until it's happened.

Letting an agent spend money on its own is not just a hobbyist's experiment

A widely shared open-source project this year let an agent buy things on its own, with no approval step before the purchase went through. It was built and shared as a demonstration, not aimed at a real business, but it demonstrates the exact mechanism a purchasing or ad-spend agent in your business would need if it could act without you. Give an agent a card number and the freedom to use it, and the only thing stopping an unwise purchase is whatever judgement you built into the agent beforehand, not a person looking at the purchase before it happens.

That's the trade a draft-only agent refuses to make. However well an agent is built, a person still checks the actual purchase, the actual message, the actual number, before money or words leave the business.

The approval gate is a mechanism, not a promise

Saying "a human approves everything" only means something if there's a real, checkable step that makes it true. In how we build agent teams, each agent has a written job description that limits what it can touch and what it's allowed to do, so a customer-service agent has no way to start managing ad spend on its own. Every piece of outbound work, whether it's a reply, an invoice chase, or a social post, sits as a draft in a queue until a person reads it and clears it; nothing moves without that click. Every action any agent takes leaves a record, so if something does go wrong, you can trace exactly what happened and when, rather than guessing. And spending, where an agent touches money at all, sits behind a cap that a person set in advance, so even a queued draft can't commit more than was agreed.

We set out the fuller picture of how a team like this actually runs, agent by agent, in how an AI agent team actually works. The approval gate is one piece of that design, not a separate policy bolted on afterwards.

People still want to deal with a person, not an agent chasing them for input

More businesses are finding the same pattern as they put agents into real workflows. Agents pinging colleagues or customers directly, asking for approval or input over chat, create friction rather than remove it. People would rather deal with a person who can be reasoned with than an automated intermediary chasing them for a decision. That's a reason to keep the approval step with a human on your side too, not just as a safety measure but because it's what the people on the other end of your business actually want. Your customers are talking to your business. The agent does the work behind that conversation; it shouldn't become the conversation.

None of this is free. Reading a queue of drafts every day takes real time, and a busy owner who starts clearing drafts without reading them has emptied the approval step of the checking it exists to do, while it still looks, from the outside, like a safeguard. The gate only works if someone actually reads what's in it, every time. That's a discipline you're choosing to take on, not a setting you switch on once.

Handing the busywork to an agent and keeping the send button for yourself costs you a few minutes of reading a day. In exchange, the worst thing an agent does on its worst day gets caught before it reaches anyone outside your business.

FAQ

What does it mean for an AI agent to draft, never send?

It means the agent produces the finished piece of work, whether that's a customer email or a purchase order, but a person has to review and approve it before it goes anywhere. The agent never holds the login or card details that would let it act on its own.

Why not let an AI agent send routine, low-risk messages by itself?

Because "routine" and "low-risk" are judgements made in advance, and the message that breaks that assumption is exactly the one you didn't expect. A short review costs you a minute; an unreviewed mistake that's already reached a customer costs a lot more to undo.

Does an agent that drafts, never sends, actually save time if a person still has to check everything?

Yes, because the agent does the slow part of pulling the details together and writing the first version. Checking a finished draft takes a few minutes; writing one from nothing takes far longer.

How does a human approval gate work day to day, without becoming a bottleneck?

Drafts queue up as they're finished rather than arriving one at a time, so you review them in a batch when it suits you, not on the agent's schedule. The gate only becomes a bottleneck if the business tries to run faster than a person can actually read.

Can an agent still be useful in a business if it never sends anything itself?

Very much so. The value in an agent is the work it removes from your week: the drafting, the research, the chasing. Deciding what should be sent is the hard part, and that decision stays with you.