Shared council · 5 Oct 2026 · What is Council AI?

88%
Confidence
89%
Council consensus

Should you allow AI agents to autonomously send messages and make book

analysis · 5-model panel · balanced debate · rigorous chair

The question

Should you allow AI agents to autonomously send messages and make bookings on your behalf?

⚖ Chairman's verdict

Short answer: do not give an AI agent unrestricted autonomy to send messages and make bookings on your behalf. Allow only narrow, revocable autonomy under hard constraints, and require explicit human approval for anything irreversible, financial, legal, medical, or reputationally sensitive. The single most useful rule is this: grant autonomy only when all four of these are true — (1) the action is reversible within 24 hours at no cost, (2) it discloses no more than your name, a dedicated email alias, and a generic phone number, (3) the agent cannot accept terms, sign contracts, or touch your real payment credentials, and (4) you get a real-time audit log and a one-click kill switch. If any of the four is false, a human approves the action. Why the caution is warranted. Prompt injection is the top-ranked LLM security risk (LLM01) in the OWASP LLM Top 10 for both 2023 and 2025, so this is a recognized, catalogued threat rather than a hypothetical one. The dangerous pattern is an agent that reads untrusted content (a web page, an inbound email, a PDF, a calendar invite) and then sends or books in the same session — that combination is how injected instructions turn into fraud, data leakage, or unauthorized messages. Agents also hallucinate (inventing a flight number, a price, a recipient) and make compounding errors where a wrong date or amount cascades. And liability sits with you: in Moffatt v. Air Canada (2024), the British Columbia Civil Resolution Tribunal rejected the airline's argument that its chatbot was a separate entity and held the company liable for negligent misrepresentation, which shows that AI-generated statements and actions are treated as the account holder's. Most booking platforms also restrict automated access, so an over-eager agent can get your account banned. A concrete tiered policy. Tier 1 — fully autonomous, low stakes. Routine internal scheduling and calendar hygiene: moving internal meetings, blocking focus time, managing recurring holds. Use deterministic or constrained tools such as Reclaim.ai, Clockwise, or Motion rather than an unconstrained LLM. Also acceptable: drafting and sending routine internal messages to people you already know, and reordering repeat consumables under a small cap. Note that 'zero external social risk' is overstated — a badly worded internal message can still cause friction — so keep tone-sensitive internal messages in draft mode. Tier 2 — agent proposes, you approve with one tap. Outbound emails to external parties, bookings under a few hundred dollars, and changes to existing reservations. The agent prepares everything (recipient, subject, body, slot, price) and you confirm. Tools like Microsoft 365 Copilot, Google Gemini, or Lindy.ai work well in this draft-and-confirm mode. Tier 3 — human only. Anything non-refundable or prepaid, anything above your spend cap, money transfers, contracts and terms of service, medical or financial advice, messages to your boss, clients, lawyers, or doctors, and anything that would share passport numbers, Social Security numbers, payment details, health information, or passwords. Technical safeguards if you deploy agents. Give the agent its own scoped credentials: a dedicated email alias, a separate calendar, and a virtual card with per-transaction and monthly limits (for example, 50 US dollars per transaction and 200 US dollars per month) plus merchant category locks. Never give it your primary inbox, your bank account, or your main credit card. Use an isolated browser profile with no password manager, no autofill, and no saved sessions. Enforce allowlists: only send to contacts in your address book, only book from approved vendors. Add rate limits (for example, a maximum of five outbound messages per hour). Log every action and review the log weekly. Prefer vendors that support action confirmation and rollback, though as of 2025 this support is uneven. Critically, do not let the agent read untrusted external content and execute outbound communications in the same session without an intermediate human validation step. On the disputed points. The Moffatt v. Air Canada case is real and supported, but it concerns a company's liability for its own chatbot's statements, not a personal agent executing bookings, so it supports the liability principle only by analogy — treat it as illustrative, not directly on point. The claim that prompt injection is the top LLM security risk is supported by OWASP. The '2 to 4 hours per week' time-saving figure and the '99 percent reliability over 30 days' threshold that appeared in one answer are unsupported and arbitrary; treat them as example policies, not validated standards. The claim that Google Assistant, Apple Siri, and Microsoft Copilot already provide robust confirm-before-sending and granular controls for autonomous messaging and bookings is an overgeneralization — capabilities vary widely and booking autonomy is limited, so verify per product rather than assuming. Bottom line. Start with Tier 1 only for the next few months. Add Tier 2 once you have a working audit log and a clear rollback path. Keep Tier 3 human indefinitely for anything irreversible or financially material. The productivity gain from Tiers 1 and 2 is real; the downside risk of unbounded Tier 3 autonomy is not worth it yet.

Key reasoning

The recommendation is built on four load-bearing facts. First, prompt injection is the top-ranked LLM security risk (OWASP LLM Top 10, LLM01, 2023 and 2025), so an agent that reads untrusted content and then acts is a known attack surface. Second, agents hallucinate and compound errors, so a wrong recipient, date, or amount can cascade. Third, liability sits with the account holder — Moffatt v. Air Canada (2024) shows AI-generated statements are treated as the organization's, and most booking platforms restrict automated access, risking account bans. Fourth, reversibility is the cleanest decision axis: actions that are reversible within 24 hours at no cost can be automated; irreversible or financially material actions cannot. This is why the answer is tiered rather than a flat yes or no, and why the four-part decision rule is the operational core.

Points of agreement
  • All five members agree that unrestricted, fully autonomous messaging and booking is unsafe today.
  • All five agree on a tiered or human-in-the-loop model keyed to reversibility and financial risk.
  • All five flag prompt injection and hallucination as core risks.
  • All five recommend scoped credentials, audit logs, and human approval for irreversible actions.
  • All five converge on draft-only or confirm-before-send for external messaging.
Disagreements & tradeoffs
  • Whether internal scheduling carries 'zero external social risk' — Answer A says yes, Answer D correctly notes this is overstated.
  • Whether small autonomous purchases (under 50 US dollars) are acceptable — Answer B allows them, Answer A warns of hallucination and pricing drift even at low amounts.
  • The exact reliability threshold for granting write/send permissions — Answer E proposes 99 percent over 30 days, which reviewers called arbitrary.
  • Whether the Moffatt v. Air Canada case directly supports personal-agent liability — it concerns a company's chatbot, so it applies only by analogy.
  • How much built-in protection mainstream assistants (Siri, Google Assistant, Copilot) actually provide — Answer C overstates this; capabilities vary widely.
🔎 Fact check (live web search)

Specific claims from the answers, checked against current web sources before the Chairman wrote the verdict.

  • ✓ SupportedIn Moffatt v. Air Canada (2024), tribunals affirmed that organizations are legally bound by their AI tools' statements.

    In Moffatt v. Air Canada (2024), the British Columbia Civil Resolution Tribunal rejected the airline's claim that its chatbot was a separate entity and held the company liable for negligent misrepresentation regarding the statements made by the chatbot.

  • ✓ SupportedPrompt injection is ranked as the top LLM security risk.

    Prompt injection is ranked as LLM01, the top vulnerability/risk, in both the 2023 and 2025 editions of the OWASP LLM Top 10.

Risk & uncertainty
  • The right threshold depends on your personal risk tolerance and the specific agent product; the four-part rule is a default, not a universal law.
  • Vendor safeguards and agent capabilities are improving quickly, so the line between Tier 2 and Tier 3 may shift within a year.
  • Moffatt v. Air Canada concerns a company's liability for its chatbot's statements, not a personal agent executing bookings, so it supports the liability principle only by analogy.
  • The 50 US dollars per transaction and 200 US dollars per month caps are illustrative user-set examples, not validated standards.
  • The '2 to 4 hours per week' time-saving figure and the '99 percent reliability over 30 days' threshold are unsupported and should be treated as example policies.
  • Rollback and action-confirmation support across vendors is uneven as of 2025, so verify per product before relying on it.
  • Consensus among models is not proof; they can share blind spots.

Suggested next steps

  1. Write down your own four-part decision rule and your spend caps before enabling any agent.
  2. Start with Tier 1 only: configure Reclaim.ai, Clockwise, or Motion for internal scheduling, and keep external messaging in draft mode.
  3. Set up a dedicated email alias, a separate calendar, and a virtual card with per-transaction and monthly limits plus merchant category locks.
  4. Enable a real-time audit log and a one-click kill switch, and review the log weekly.
  5. Add allowlists (address book contacts, approved vendors) and rate limits (for example, five outbound messages per hour).
  6. After a few months with a working audit log and a clear rollback path, pilot Tier 2 with one-tap approval for external emails and low-value bookings.
  7. Keep Tier 3 human indefinitely for anything irreversible, financial, legal, medical, or reputationally sensitive.
  8. Never let the agent read untrusted external content and send or book in the same session without an intermediate human validation step.

Model scorecard

•DeepSeek R1🏆 #1
Accuracy94%
Consensus91%
Answer D · composite 92
✦Gemini Flash#2
Accuracy93%
Consensus93%
Answer A · composite 90
•DeepSeek V3#3
Accuracy91%
Consensus87%
Answer B · composite 89
✦Gemini Flash#4
Accuracy85%
Consensus86%
Answer E · composite 84
◈GPT-OSS 120B#5
Accuracy79%
Consensus87%
Answer C · composite 74
Each model's answer (5)
✦Gemini Flash· Answer A

You should not grant unrestricted, full autonomy to AI agents for outbound messaging and bookings today, but you should adopt a tiered, human-in-the-loop model based on reversibility and financial risk. AI agents excel at internal orchestration and draft generation, but current autonomous systems remain vulnerable to prompt injection attacks, context hallucinations, and API failure loops. Unmonitored autonomy risks reputational damage, unintended contractual agreements, and financial loss. Recommended framework based on action type: - Low-risk internal scheduling (Full Autonomy Allowed): Use AI tools like Reclaim.ai, Clockwise, or Motion to automatically move internal meetings, block focus time, and manage recurring calendar holds. These actions carry zero external social risk and are fully reversible. - External meeting bookings (Constrained Autonomy): Allow scheduling agents such as Calendly, Clara, or Lindy to handle logistics, but enforce hard constraints. Define strict working hours, buffer times, and allow the agent to propose slots rather than confirm meetings with external clients without an invitation acceptance mechanism. - External messaging and emails (Draft Only / Human-in-the-Loop): Keep tools like Gmail Help Me Write, Superhuman AI, or Copilot in draft mode. An AI should generate responses, parse incoming requests, and queue messages, but a human must review and click send. Autonomous email sending exposes you to hallucinated commitments and indirect prompt injection if an inbound email contains malicious instructions. - Financial bookings and transactions (Strictly Prohibited Autonomy): Never allow autonomous agents to execute non-refundable bookings, hotel reservations, or flight purchases via card-on-file without explicit one-click confirmation. Agents lack common-sense dispute resolution when vendor terms change or dates shift. Rule of thumb: If an action is a Type 2 decision (easily reversible with negligible cost, like rescheduling a 1-on-1 with a colleague), automate it. If an action is a Type 1 decision (consequential, expensive, or socially sensitive, like emailing a major client or purchasing non-refundable travel), require explicit human approval.

•DeepSeek V3· Answer B

Short answer: yes, but only narrowly scoped, with hard limits and human approval for anything irreversible. Fully autonomous AI agents that send messages and make bookings on your behalf are not yet safe to run unattended for high-stakes actions. Why the caution is warranted: - Prompt injection is an unsolved problem. If an agent reads web pages, emails, or calendar invites, malicious text in that content can hijack its instructions. Research from 2024-2025 shows attackers can embed hidden instructions in a webpage that cause an agent to exfiltrate data or take actions the user never intended. This is not hypothetical; it has been demonstrated against real agent frameworks. - Agents hallucinate. An LLM may invent a flight number, a restaurant, a price, or a recipient. A hallucinated booking costs money; a hallucinated message can damage a relationship or leak information. - Irreversibility matters. Sending an email is somewhat recoverable (you can follow up). Booking a non-refundable flight, signing a contract, or transferring money is not. The autonomy you grant should scale inversely with reversibility. - Accountability and liability are unsettled. If an agent books the wrong thing or sends a message that breaches an NDA, the legal and financial responsibility generally falls on you, not the vendor. Terms of service for most booking platforms also prohibit automated access, which can get your account banned. A practical tiered policy: - Tier 1 (fully autonomous, low stakes): drafting and sending routine internal messages, scheduling meetings with people you already know, adding calendar events, ordering repeat consumables under a small cap (say under $50). - Tier 2 (agent proposes, you approve with one tap): outbound emails to external parties, bookings under a few hundred dollars, changes to existing reservations. The agent prepares everything; you confirm. - Tier 3 (human only): anything non-refundable, anything over your pre-set spend cap, anything involving money transfer, legal commitments, medical or financial advice, or messages to people where tone and relationship matter. Technical safeguards if you do deploy agents: - Give the agent its own scoped credentials (a separate email alias, a virtual card with a low limit, a calendar with limited visibility), never your primary accounts. - Require allowlists: only send to contacts in your address book, only book from approved vendors. - Log every action and review the log weekly. - Use a spend cap and a rate limit (e.g., max 5 outbound messages per hour). - Prefer vendors that support action confirmation and rollback. As of 2025, this is still uneven. My recommendation: start with Tier 1 only for the next few months, add Tier 2 once you have a working audit log and a clear rollback path, and keep Tier 3 human indefinitely for anything irreversible or financially material. The productivity gain from Tier 1 and 2 is real; the downside risk of unbounded Tier 3 autonomy is not worth it yet. Confidence: I am highly confident (about 85%) that full unattended autonomy is currently unwise for high-stakes bookings and messages. I am less certain (about 60%) about where exactly the line should sit, because the technology and vendor safeguards are improving quickly and the right threshold depends on your risk tolerance and the specific agent product.

◈GPT-OSS 120B· Answer C

You can let AI agents act for you, but only if you impose strict safeguards: limit the domains (e.g., only travel or restaurant bookings), require a human confirmation step for any outbound message or transaction over a set monetary threshold, and use services that provide audit logs and easy revocation. Trusted platforms such as Google Assistant, Apple Siri, or Microsoft Copilot already offer "confirm before sending" prompts and granular permission controls; leveraging those built‑in features is safer than using a custom script with unrestricted access. In short, enable autonomous messaging and booking only after you have (1) vetted the AI provider’s security and privacy policies, (2) configured explicit user approvals for each action, and (3) set up monitoring so you can review what the AI does. If those controls cannot be guaranteed, do not permit the AI to act without your direct oversight.

•DeepSeek R1· Answer D

Bottom line: Do not give an AI agent full autonomy to send messages and make bookings on your behalf. Allow only narrow, revocable autonomy under hard constraints, and require human approval for anything irreversible, financial, legal, medical, or sensitive. The default should be: human in the loop for anything that cannot be undone within 24 hours at no cost or that shares more than your name and a dedicated email address. Where I would allow autonomy: - Routine scheduling messages from a dedicated email alias: confirming a time, accepting or declining a meeting, asking for a simple appointment slot. No attachments, no forwarding, no access to your primary inbox. - Restaurant or hotel bookings with free cancellation, pay at property, and no prepayment. The agent can hold a table or room under your name. - Simple appointment requests where the only data shared is name, dedicated email, and a generic phone number. Where I would not allow autonomy: - Any nonrefundable purchase or prepayment. If you must allow small purchases, cap at 50 US dollars per transaction and 200 US dollars per month with a single-use virtual card and merchant category locks. - Messages to your boss, clients, lawyers, doctors, or anyone where tone, confidentiality, or a binding commitment matters. - Sharing passport numbers, Social Security numbers, payment details, health information, or account passwords. - Accepting terms of service, signing contracts, making medical decisions, or creating new accounts. Guardrails if you do allow it: - Dedicated email alias, separate calendar, no access to primary inbox or contacts. - Virtual card with per-transaction and monthly limits; no access to your bank account or main credit card. - Isolated browser profile; no password manager, no autofill, no saved sessions. - Domain allowlist; no ability to create new accounts or accept terms. - Real-time audit log and a one-click kill switch. - Never let the agent read untrusted content such as web pages, emails, or PDFs and then send or book in the same session without human approval. That combination is how prompt injection turns into fraud or data leakage. Why this is the right risk posture: - Prompt injection is the top LLM security risk. A malicious page or email can hijack an agent that has both reading and acting privileges. - You are likely bound by contracts your agent makes using your accounts, even if the agent misunderstood. Unwinding a nonrefundable booking or a sent message is costly or impossible. - Agents make compounding errors: a wrong date, a wrong recipient, or a wrong amount can cascade. Decision rule: Allow autonomy only if all four are true: (1) the action is reversible within 24 hours at no cost; (2) it discloses no more than your name, dedicated email, and generic phone; (3) it cannot accept terms, sign contracts, or access payment credentials; (4) you get a real-time log and can revoke access immediately. If any is false, require human approval. Confidence: 85.

✦Gemini Flash· Answer E

You should not grant unrestricted autonomy to AI agents for messaging and bookings. Instead, adopt a conditional, tiered-autonomy framework based on reversibility, financial exposure, and prompt injection risks. Recommendation by use case: 1. Calendar Scheduling and Routine Bookings: Yes, with hard constraints. Allow autonomy only within closed, deterministic rule sets. Tools like Reclaim.ai, Clockwise, or Calendly use algorithmic logic or constrained agentic scheduling that respects predefined working hours, buffer times, and conflict policies. For routine internal meeting scheduling, full autonomy is safe and saves 2 to 4 hours per week on average. However, do not give an unconstrained LLM agent open access to negotiate and book external events without boundaries. 2. External Messaging and Email: Draft-only autonomy (Human-in-the-loop). Configure AI agents (such as Microsoft 365 Copilot, Google Gemini, or Lindy.ai) to draft emails, Slack messages, and responses, but require explicit human approval before sending. LLMs remain susceptible to tone drift, factual hallucinations, and indirect prompt injection attacks, where malicious content embedded in incoming emails or calendar invites can hijack the agent to exfiltrate private data or send unauthorized replies. 3. Financial Bookings (Flights, Hotels, Purchases): No autonomous authorization. Keep financial commitments strictly gated behind human approval. LLMs struggle with dynamic edge cases like cancellation penalties, seating class nuances, and dynamic pricing changes. Furthermore, legal liability remains with the account holder; in cases like Moffatt v. Air Canada (2024), tribunals affirmed that organizations are legally bound by their AI tools' statements, and consumers have no standard recourse if their personal agent executes a non-refundable, erroneous transaction. Concrete Implementation Rules: - Enforce read/draft permissions first; do not grant write/send API permissions until an agent achieves 99 percent reliability over a 30-day testing window. - Set hard monetary transaction limits of zero dollars for any unconfirmed action. - Restrict tool-use permissions so that an agent cannot read untrusted external content and simultaneously execute outbound communications without intermediate validation.

Which answer was best?

Read the answers, then pick the one you'd trust most. Human votes feed the public leaderboard.

🗺 Agreement map

How each model (rows) scored every other model's answer (columns), 0–100. Similar colours down a column mean the panel agrees about that answer; an outlier cell is a dissent.

Reviewer ↓ / Answer →A
Gemini Flash
B
DeepSeek V3
C
GPT-OSS 120B
D
DeepSeek R1
E
Gemini Flash
A Gemini Flash—90769394
B DeepSeek V393—759788
C GPT-OSS 120B9180—8676
D DeepSeek R1859463—84
E Gemini Flash93957996—
Panel agreement93%87%87%91%86%

No strong dissents: the reviewers broadly agreed on every answer.

Model metrics

Response time is each model's own answer latency; accuracy, completeness, reasoning and risk (0–100) are the average scores its answer received from the other members' blind peer review.

RankModelResponse timeAccuracyCompletenessReasoningRisk↓ConsensusComposite
🏆 1DeepSeek R129.5s9492911091%92
2Gemini Flash5.8s9388901393%90
3DeepSeek V36.8s9190891787%89
4Gemini Flash6.8s8586852686%84
5GPT-OSS 120B10.2s7965752687%74

Got a question of your own?

Several AI models answer it independently, review each other blind, and a chairman writes one verdict. Free.

Convene a council →

See which AI models win most often →