Your AI Can Now Send the Email, Not Just Draft It
Two updates shipped on the same day, August 18. Anthropic expanded its Google Workspace connectors so Claude can send, reply to, and forward Gmail rather than only reading and drafting. Perplexity launched Computer in Email, where you send, forward, or cc a dedicated Perplexity address and a full agent task runs using the sender's own connectors and permissions, then replies in the same thread. Both read as minor product notes. Both cross the same line, and it is a line worth noticing, because everything AI has done in your inbox until now produced something you looked at before anybody else did.
The asymmetry that matters
A bad draft costs ten seconds and nobody outside the business ever learns it existed. A bad sent message is a fact in the world, and the recovery options are weaker than most people assume. Gmail has no recall at all: Undo Send is a pre-send delay capped at thirty seconds, and there is no mechanism in email itself to retrieve a delivered message. Outlook recall works only when both parties are in the same Microsoft 365 organisation, fails if the message has been read or filed, and notifies the recipient when it fails, which advertises the mistake to the one person you hoped would miss it. That asymmetry is the whole story here. It has nothing to do with how good the writing is, and AI writes perfectly reasonable email. The question is not quality. It is what happens on the rare occasion the model is confidently wrong about something.
Sort by consequence, not by volume
The instinct is to automate whatever there is most of. The better instinct is to automate whatever costs least when it goes wrong.
| Message type | Can AI send it? |
|---|---|
| Internal confirmations and acknowledgements | Yes, with a log |
| Templated external replies, no new promise | Usually, with spot checks |
| Anything with a price, date, or commitment | No, a person reads it first |
| Complaints, legal, insurers, regulators | Never automate |
The third row is where most businesses will get caught, because a quoted price inside a friendly reply does not feel like a legal event until a customer holds you to it. Treat any number that a recipient could reasonably act on as requiring a human, regardless of how routine the surrounding message is.
Small and real beats large and nominal
The common failure is not too little oversight. It is oversight that quietly became a formality. Ask a person to approve two hundred messages a day and they will approve two hundred messages a day, and you have swapped a control for a habit while keeping the paperwork that says otherwise. This is the same dynamic behind human-in-the-loop turning into a rubber stamp. A narrow automatic category with a weekly sample read is worth more than a broad one with a checkbox in front of it.
Give it its own address
Where the messages are genuinely operational, consider sending them from a clearly identified mailbox rather than from a named person. Confirmations and scheduling notes do not need to appear to come from your operations manager, and separating them means a recipient always knows whether they are talking to a system or a person. It also gives you a clean log and prevents an automated message from inheriting the trust attached to somebody’s personal address, which is the practical version of the access principle in giving an agent its own identity.
Disclosure is downstream of the boundary
People ask whether recipients should be told an AI wrote the message. For a meeting confirmation, adding a disclaimer would be odd. The line worth holding is about representation rather than authorship: if a message expresses judgment, empathy, or a commitment, and the recipient would reasonably assume a person weighed it, then a person should have. Get that boundary right and most of the disclosure question dissolves, leaving the narrower cases covered by the general principles in when to disclose AI to customers.
Worth doing, worth bounding
None of this is an argument against the capability. Inbox time is one of the largest recoverable costs in most small businesses, and if you are still setting up the reading and drafting side, our guides to automating email with AI and connecting Gmail to ChatGPT are the place to start. The point is narrower. Sending is a different decision from drafting, it deserves five minutes of thought rather than a default setting, and the businesses that will regret this are the ones that never noticed a line had been crossed.
Frequently Asked Questions
What changed?
On August 18, Anthropic expanded its Google Workspace connectors so Claude can send, reply to, and forward Gmail rather than only reading and drafting it, and Perplexity launched Computer in Email, where forwarding or copying a dedicated address runs a full agent task under the sender’s own permissions and replies in the same thread. Both are small-sounding product updates with one large consequence in common. Until now, AI in your inbox produced something you looked at before anyone else did. The new capability removes that step, which changes the nature of a mistake from an internal one you quietly delete to an external one sitting in somebody else’s inbox with your name on it.
Why is sending so different from drafting?
Because drafting is reversible and sending is not. A bad draft costs you the ten seconds it takes to delete it, and nobody outside your business ever knows it existed. A bad sent message is a fact in the world. It has been delivered, it may have been read within a minute, it can be forwarded, and recall barely exists. Gmail’s Undo Send is a thirty-second pre-send delay rather than a recall, and Outlook’s recall only works inside a single Microsoft 365 organisation, fails once a message has been read or filed, and tells the recipient you attempted it. That asymmetry, not the quality of the writing, is the reason this deserves a decision rather than a default.
Which emails are safe to let AI send?
Work down from consequence rather than up from convenience. Routine internal messages with no commitment in them are genuinely fine: meeting confirmations, acknowledgements, status notes to colleagues. Standard external replies that follow a fixed template and contain no new promise are usually acceptable with spot checks. Anything containing a price, a deadline, a commitment, an apology, or a legal position should not leave without a person reading it. Anything to a regulator, a lawyer, an insurer, or an unhappy customer should not be automated at all, no matter how routine it looks.
How should approval actually work?
The failure mode is not too little approval, it is approval that has become a formality. A person asked to approve two hundred messages will approve two hundred messages, and you will have replaced a control with a habit. Better to send a small share of messages automatically and genuinely review the rest than to nominally review everything. Set the automatic category narrowly, keep a log of what went out unattended, and read a sample of it weekly, because the point of the sample is to catch the drift that nobody would otherwise notice.
Do we need to tell recipients an AI wrote it?
For routine operational messages, no, and adding a disclaimer to every meeting confirmation would be strange. The line worth holding is about representation rather than authorship. If a message expresses judgment, empathy, or a commitment, and the recipient would reasonably assume a person weighed it, then a person should have. That is less a disclosure rule than a decision about what goes out unattended in the first place. Get that boundary right and the disclosure question mostly answers itself.
Automate the inbox without losing control of it
We help Canadian businesses decide what AI may send unattended, set up the logging behind it, and keep review meaningful as volume grows.
Related Articles
Can You Undo What Your AI Just Did?
AI Now Hands You the Report, Not Just the Answer
AI Does Not Fix a Broken Process. It Scales One.
Ajan leads the ChatGPT.ca team: 200+ custom GPT builds and automation projects for 50+ businesses across 20+ industries. Based in Markham, Ontario. PIPEDA-compliant solutions.