AI reply drafts that leave blanks instead of inventing facts
An AI reply assistant should never fill in a fact it does not have. Where a draft needs an amount, a date or a policy detail, it should leave a visible blank for a person to complete, and the reply should not be sendable until every blank is filled. Email Digit’s drafts work that way, and the rule is enforced by the send button and on the server, not only in the instructions.
The failure that matters
A customer writes: “I returned the jacket two weeks ago and still have no refund.” An AI draft replies: “Sorry for the wait. Your refund of $84 will reach your card on Thursday.”
The draft reads well. But if the model chose the amount because it looked plausible, and the day because Thursday sounded reasonable, a customer now holds a written promise that nobody in your business made. Fluent, confident and wrong is the worst combination a reply can have, because it is the one most likely to be sent without a second look.
Language models are built to produce plausible text. Asking them nicely not to guess helps, but a request in a prompt is not a control. The control has to sit where the email leaves.
A rule worth adopting, with or without software
Split every reply into two kinds of content. Wording (the apology, the tone, the structure) can be drafted by anyone or anything. Facts (amounts, dates, order status, what your policy says, what you will do) must come from a person or a system of record. If your team drafts from templates, mark the facts as blanks in the template, so nobody can send one with last month’s numbers still in it.
If you are choosing an AI reply tool, four questions separate a convenience from a liability:
- What does the draft do when it lacks a fact: guess, or leave a marked gap?
- Is the gap enforced at send time, or only requested in the instructions?
- Can anything be sent without a person clicking Send?
- Do refunds, complaints and legal messages get a stricter path than routine ones?
A tool that answers all four well can still draft a poor reply. One that answers them badly can draft a convincing promise you never made.
How Email Digit drafts
When you ask for a suggested reply, the draft writer is told to state only facts given in the message or the context, and never to invent amounts, dates, order status, account balances, policy details or commitments. Where it needs one, it writes a placeholder instead:
Your refund of [[confirm: refund amount]] will be processed by [[confirm: refund date]].Then three things happen in the inbox:
- Each placeholder is listed above the reply box as a chip, under “Fill in 2 unverified details before sending”.
- The Send button stays disabled while any placeholder remains in the text.
- When the last one is replaced, the message changes to “All details confirmed · ready to send”.
The same check runs on the server against the text being sent, after any edits you made. A body that still contains a placeholder is refused, and this check has no override. The only way past it is to fill in the fact.
A second guard for risky replies
Nothing is sent automatically. Every suggested reply is a draft that waits for a person. On top of that, some replies need a second, deliberate confirmation before they go:
- the original message was flagged “Needs review”;
- it carries a risk flag, such as a legal threat, chargeback risk or churn risk;
- or the draft came from an escalation playbook: refunds and returns, complaints, billing and payment, contracts and legal matters, and press enquiries.
In those cases sending is refused until someone clicks “Send anyway” in a warning dialog that names the flags. The check runs on the server, so a script calling the API has to override it explicitly too; there is no quiet path around the human step.
One more safeguard covers teams: a reply can be answered once. If two people have the same message open, or someone clicks Send twice, the second attempt is told the reply was already answered. If delivery fails, the claim is released so a genuine retry works.
Limits
- The blank depends on the model noticing. The instruction is firm and the send check is strict, but if a draft states something specific without a placeholder, nothing marks it. Read a draft before you send it, especially anything with a number in it.
- Drafts use AI actions. A reply draft uses about 2 AI actions from your monthly allowance. Receiving replies does not, and classifying them draws on a separate monthly classification allowance.
- Override is possible for flagged replies. “Send anyway” exists because a person sometimes knows better. It asks for a deliberate choice; it is never the default.
For how the incoming message is read before any draft is written, see How to classify email replies, or how replies are read.