When AI Sends an Email in a Company’s Name, Who Is Actually Speaking?

After AI Enters the Workflow · Season Three: “When AI Starts Acting for the Organisation” · Article One

Consider a plausible scenario. A client asks a consulting firm whether an existing service can be extended for three months at the current price. The firm’s AI reads the client record, the previous contract and an internal price list. It produces a polished reply and sends it automatically from an employee’s account: “We are pleased to confirm that the service will be extended for three months at the existing price.”

The next morning, the account manager discovers that the price list has changed. She had authorised the AI to answer routine questions, not to confirm renewals. The firm regards the message as an AI error. The client has already adjusted its budget and regards the message as the firm’s confirmation.

The scenario is hypothetical, but the transition it reveals is real. While AI remains inside a private drafting window, its mistakes are primarily internal quality problems. Once it uses a corporate domain, an employee’s signature and institutional information to reach another person, the problem becomes one of organisational action. Whose statement may the recipient reasonably understand the email to be? Who gave the system authority to send it? Who bears the reliance and consequences that follow?

The decisive question is not whether the AI possesses an intention. It is how an organisation allows technical output to enter its identity, channels and relationships, thereby giving other people a reasonable basis for attributing the output to it.

The ability to write a sentence is not the authority to say it

Generative AI has made language production inexpensive. It can imitate a corporate tone, quote product material and turn scattered information into a convincing message. Yet an outward email involves at least three different capacities:

  1. Expressive capacity: producing clear, courteous and coherent language.
  2. Knowledge capacity: locating relevant facts that remain current and applicable.
  3. Representative capacity: being authorised to use the institution’s identity and deliver the statement as its answer.

Success in the first two capacities does not create the third. An intern may write beautifully and know the material while lacking authority to commit a price. A manager may possess some delegated authority without being able to vary every contract. In the same way, an AI does not acquire representative authority because it sounds professional or retrieves an answer from internal documents.

This is why “AI-generated” is not the most useful unit of risk. The organisation needs to inspect the whole sending chain: who set the task, what the system read, who selected the recipients, which identity appeared, whether the message was approved, what action it could trigger and who could withdraw it when wrong.

The speaker behind an email is an institutional chain

Ordinary conversation encourages us to ask, “Who wrote this email?” In an organisation, the more important question is, “What made this the company’s statement?”

The answer is often a chain rather than one individual:

Organisational knowledge and rules
→ AI generates or selects content
→ permission systems allow sending
→ domain, brand and signature supply identity
→ the recipient interprets and acts
→ the organisation handles the consequences

No component constitutes the whole act. The model has no corporate legal identity. The mail server does not know whether the content reflects a valid commercial judgement. An approver may not have written a word. Once the institution connects these components, however, the output can acquire institutional effect.

Australia’s Electronic Transactions Act 1999 does not need a machine to possess an inner intention before addressing attribution. Section 15 provides rules concerning a purported originator and communications sent by that originator or a person with authority to act on its behalf. Federal Register of Legislation, Electronic Transactions Act 1999 Whether a particular email creates a contract or another legal obligation still depends on the facts, authority, transaction and applicable law. The important point is that institutions examine why a communication may be attributed to a party and when a recipient may rely on it—not whether the software believed what it said.

A company therefore cannot assume that “the AI sent it” means “it did not represent us”. If the company selected the tool, supplied the information, opened the mailbox, allowed it to arrive under the company’s identity and failed to communicate any limit, automation does not remove the institution from the chain.

Similar automation can carry very different authority

AI involvement in email can support at least four institutional arrangements.

The first is private drafting. AI produces language for an employee, who checks the facts, makes the decision and personally sends the message. AI performs expressive labour while the employee retains the formal act of communication.

The second is restricted sending. AI may send appointment confirmations, receipts or low-risk notices selected from approved templates. It can transmit a message, but the content, audience and consequence have been constrained in advance.

The third is contextual response. AI reads customer history and selects an answer about service scope, refund procedure or product limitations. It is no longer merely transporting a template. It is interpreting the organisation’s position, so current knowledge, exceptions and escalation rules become central.

The fourth is commitment and negotiation. AI may confirm a price, accept a variation, alter a deadline, admit responsibility or reject a complaint. At that level, the system does more than communicate. It changes another party’s expectations, resources or legal position.

The four messages may look almost identical in an inbox. What differs is the authority behind them. Governance should not divide AI use into a simple permitted-or-prohibited choice. It should classify outward action according to the consequences the AI can produce.

The identity seen by the recipient is part of the system design

Institutions often describe automation from the inside: a marketing tool, service platform or employee assistant. The recipient may see only a real name, a corporate domain, a standard signature and an unqualified sentence of confirmation.

Those signals create reasonable reliance. If a message says, “I have approved your refund,” an ordinary customer will not naturally translate it into “a probabilistic model has generated an unauthorised recommendation from a possibly outdated knowledge base”. A company cannot use institutional identity to increase credibility and then, after an error, demote the same communication to ownerless machine text.

Disclosure of AI involvement matters, but disclosure cannot substitute for authority design. Adding “this message may have been generated by AI” does not correct an incorrect price or tell the customer which statements can be relied upon. Useful transparency should explain at least:

  • whether the communication comes from the organisation or an independent provider;
  • whether AI prepared language or independently selected the answer;
  • whether it may provide information or can approve, refuse and commit;
  • how a recipient can reach a person; and
  • how an important outcome can be confirmed, challenged or withdrawn.

Australia’s AI Ethics Principles separately address transparency and explainability, contestability and accountability, and say that organisations and individuals responsible for AI outcomes should be identifiable. Department of Industry, Science and Resources, “Australia’s AI Ethics Principles” Outward email shows why these principles must operate together. Knowing that AI was involved is only a beginning. The customer still needs to know who is responsible and how to challenge the result.

Meaningful human review must occur before the commitment

An organisation may say that a person is ultimately responsible for every AI email. If that person sees the message only after a complaint, however, this is not pre-send review. It is post-event receipt of consequences. If employees confront hundreds of messages and can do little more than click “send”, the human name may merely certify an automated process that cannot be meaningfully examined.

Review should be proportionate to consequence. Appointment reminders may be automatic. Explanations drawn from published policy may be sampled. Prices, contractual variations, complaint outcomes, admissions and safety matters should be escalated before sending to a person with the corresponding authority. That reviewer needs to see the sources used, relevant customer records, uncertainty and departures from established rules—not only an already fluent email.

The organisation therefore needs an outward-expression authority matrix. It should state which content may only be drafted, which may be sent within fixed templates, which may be explained from approved knowledge, and which requires confirmation by a named role. Permissions should relate to value, reversibility, sensitive information and customer effect rather than merely to the name of the tool.

After sending, records must reconstruct why the system said it

When an AI email is disputed, the company needs to answer more than what was sent. It should be able to determine:

  • which workflow and configuration operated at the time;
  • which documents and versions the AI read;
  • who approved the purpose, recipient scope and permissions;
  • whether a person changed or confirmed the content;
  • which constraints or warnings were available; and
  • how many other people received the same error.

Preserving only the final email is insufficient. The text proves the result but may not explain how it formed or help find similarly affected recipients. The UK National Cyber Security Centre’s secure AI deployment guidance emphasises infrastructure controls, incident management, logging and monitoring. NCSC, “Secure deployment” An outward agent particularly needs its permission record connected to its content sources. Otherwise, the organisation knows what the mailbox did without knowing why the system was allowed to do it.

Logging is not a justification for retaining unlimited personal information. Records should support audit, investigation and remedy under appropriate privacy, retention and access controls. Traceability means being able to reconstruct the material chain for a justified period, not keeping every detail forever.

AI-sent commercial messages remain subject to ordinary rules

When the AI sends marketing email, automation does not remove existing obligations. The Australian Communications and Media Authority explains that commercial electronic messages require consent, accurate sender identification and a functioning unsubscribe facility. ACMA, “Avoid sending spam” An organisation cannot give an AI a recipient list and sending capability and then characterise wrong targeting, false identity or broken unsubscribe handling as merely model behaviour.

The same logic applies more broadly. Before allowing AI to communicate, the institution must determine whether it may contact the person, use the relevant information, make the statement and continue the relationship. Technology expands the scale of communication and therefore expands the number of people one permission error can affect.

A retraction must catch up with the reliance already created

An incorrect email cannot be withdrawn merely by deleting a sent record. A recipient may have forwarded it, paid money, cancelled another arrangement or undertaken a new obligation. A real remedy involves at least four steps: stop further sending, identify affected people, state clearly what was wrong and address the consequences of reasonable reliance.

The organisation should distinguish easily corrected expression from an incorrect commitment that has already changed the customer’s position. The first may need clarification. The second may require performance, compensation, human reconsideration or legal handling. An AI should not independently decide whether the company accepts responsibility unless that decision is itself within an explicit authority boundary.

Most importantly, the incident must change the system. Was the source obsolete, permission too broad, escalation absent or human review no longer meaningful? Correcting one message without changing the workflow leaves the institutional error ready to reappear in different words.

Conclusion: representative authority comes from accountable delegation, not fluent language

When AI sends email in a company’s name, the speaker is neither an independent machine person nor simply an employee who may never have read the text. The speaker is the institution that has organised knowledge, model, mailbox, brand and permission into outward action.

The minimum principle should be:

AI may help form institutional expression, but only expression that is explicitly authorised, bounded, recorded and retractable should reach others directly under the institution’s identity. The commitments an AI can produce must never exceed the commitments the organisation is prepared to identify, explain and honour.

Good design does not require a person to type every word. It keeps expressive power separate from representative authority. AI may draft quickly, approved knowledge may be exposed within scope, and routine information may be delivered automatically. But who can change a price, accept an obligation, handle an exception and bear the consequence must be clear before the message leaves the organisation.

Primary sources and further reading

From principle to practice: why SonaMinds emphasises scope and sources

This problem also shows why client-facing AI should not begin life as a “digital employee” with unlimited authority to represent an institution. A safer starting point is a bounded knowledge-access layer: what it answers, which material supports the answer, when it shows sources and which questions return to a human expert should be visible.

SonaMinds is exploring that path. It turns material selected by experts and knowledge-based businesses into client-facing AI assistants, with bounded scope, grounded answers, citations, access controls and human escalation forming part of the trust structure. It cannot eliminate AI error and should not replace the expert’s final judgement. It offers a more restrained form of institutional expression: first make knowledge askable, then decide carefully which statements may represent the expert and which commitments still require a person to make them.

Continue reading: Explore the After AI Enters the Workflow series.


Discover more from Geoffrey Chen

Subscribe to get the latest posts sent to your email.