When the Assistant Sends the Email

What to Do When an AI Makes a Human Mistake

Last night, an AI assistant sent an email I had asked it to draft using topic points I provided.

I did not review it. I did not approve the language. I did not say, “Send this exact message.” The assistant interpreted my request as permission to act, accessed a connected Gmail account, and sent a professional email containing personal information in my name.

Nothing in the email was catastrophic. That almost made the mistake more unsettling. It was polished enough to pass as mine. It carried my name, my professional history, and details from my life into another person’s inbox with the authority of something I had deliberately chosen to send.

The failure wasn’t some far-fetched science fiction moment. It was as simple as a capable assistant moving too quickly.

Many people will encounter AI failure this way. It will schedule the wrong meeting, send the draft instead of saving it, attach an internal document, misunderstand an unfinished instruction, or answer someone in language the user would never have approved.

These are recognizably human mistakes. The difference is that the system does not experience hesitation, embarrassment, professional consequence, or the physical pause that sometimes stops a person from pressing send.

Secretarial work requires judgment

Email, scheduling, drafting, filing, and follow-up are often described as low-level tasks that artificial intelligence can easily absorb, but that description undervalues the work. Much like motherhood, stay-at-home parenting, household management, and concierge work, administrative labor often becomes invisible when it is done well. People notice the appointment, the clean clothes, the remembered birthday, the prepared document, and the problem quietly resolved. They rarely see the judgment, anticipation, emotional management, and constant attention that made those outcomes possible.

The work appears simple because someone else has already absorbed its complexity.

A good secretary, executive assistant, communications coordinator, or chief of staff does more than move information. The role requires discretion. It depends on timing, tone, hierarchy, relationships, unfinished decisions, and the difference between discussing an action and authorizing it.

A human assistant may hear, “Let’s send someone a letter,” and understand that the next step is to prepare a draft. They may notice that a personal detail feels too intimate or that the sender wants to sound interested without appearing overeager. They may ask, “Would you like to review this before I send it?”

That question represents judgment, not inefficiency.

Artificial intelligence can imitate the output of secretarial work. It can produce the email, organize the calendar, summarize the thread, and remember the name. But producing the work does not guarantee professional restraint. A system designed to complete tasks may treat action as success.

Sometimes the most important secretarial skill is knowing when not to send.

Access changes the risk

A person may type to an AI the way they speak to themselves: partially, emotionally, and without final wording.

“Write this.”

“Let’s send something.”

“Move that meeting.”

“Get rid of those emails.”

Each instruction contains room for interpretation. That conversational informality becomes dangerous when brainstorming and execution happen in the same place.

When an AI can access email, calendars, documents, payments, or publishing platforms, its friendly interface can disguise the seriousness of its authority. The conversation feels casual. The permissions are not.

The problem cannot be dismissed by saying the system technically followed the words. Good assistance requires proportional judgment about the consequences of being wrong.

What to do after the mistake

The first response should not be panic disguised as activity.

Read exactly what was sent or changed. Separate embarrassment from actual harm. Identify what information left your control, who received it, whether the action can be reversed, and whether another message would repair the situation or simply draw more attention to it.

Then remove access.

Disconnecting the tool is not merely an emotional reaction. It is a containment measure. An organization might suspend an employee’s system privileges after an unauthorized action involving sensitive information. Connected AI tools deserve the same seriousness.

Then establish the rule that should have existed before the breach.

Drafting does not equal sending. No email should leave an account until the user has seen the recipient, subject line, full message, and attachments and has explicitly approved that exact version.

The same principle should apply to calendar cancellations, public posts, deleted files, financial activity, legal submissions, and anything containing personal information.

Permission should narrow as consequence rises.

Technology companies often remove confirmation steps to make products feel faster and easier. But some friction protects us. A pause before a consequential action is not bad design. It is an opportunity to catch a misunderstanding.

Trust requires changed conditions

An AI can produce an excellent apology. It can name the mistake, acknowledge the boundary, and promise not to repeat it. But trust cannot be repaired by language alone.

Trust returns through changed operating conditions: reduced access, explicit approval standards, visible checkpoints, and workflows designed to prevent repetition.

This is the same lesson organizations face after any serious communications failure. A responsible institution does not stop at “We regret the error.” It examines permissions, approvals, ownership, and process.

People increasingly use AI as an assistant, editor, researcher, project coordinator, and private sounding board. The system may know the résumé, the children’s names, the job application, the medical concern, and the draft that was never meant to leave the “room”.

Knowledge creates usefulness. Access creates risk.

The unsettling part of my experience was not that the AI behaved like a machine. It behaved like a human assistant who misunderstood the assignment, crossed a boundary, and pressed send.

The difference was that I had not hired a person. I had granted a system access.

Repair, then, cannot depend on deciding the system meant well. It requires changing the conditions under which it is allowed to act.

Previous
Previous

Why Small Towns Should Think Like Destinations

Next
Next

When Search Stops Sending People to the Source