Should Clients Approve AI-Generated Emails Before They Send?

No, not message by message. Clients should approve the policy once, in writing, and a named human on your side should approve each AI-drafted email until that category of email earns its way out of the queue.
Per-message client sign-off feels like the careful answer and usually makes things worse. It moves your bottleneck into the client’s inbox, adds a day of lag to every reply, and produces exactly the rubber stamp that oversight is supposed to prevent. What regulators and courts care about is that an accountable human owns what went out.
Here’s the situation that prompts the question. Your AI drafts replies well enough that you’re tempted to let it run, someone asks whether the client should see each one first, and it sounds responsible. Then you price it out and realize you’ve asked your client to do 60 approvals a week for the privilege of paying you.
Two different questions got jammed together there. Pull them apart and this gets simple.
What are we actually asking when we say “client approval”?
One question is about consent to the method. The other is sign-off on a specific message. Different answers, different frequencies, different signers.
| Consent to the method | Sign-off on the message | |
|---|---|---|
| What it covers | Whether AI may draft on this account, on what data, with what human oversight | Whether this particular email is accurate, on-brand, and safe to send |
| How often | Once per engagement, revisited per SOW or annually | Per send, until the category graduates |
| Who signs | The client, in the contract or statement of work | A named person on your team |
| What it protects | The relationship, and your right to use the tooling at all | The client’s customers, and your accuracy |
Most founders asking about approval want the first one. What they build is the second one, applied to everything, forever.
The two overlap in exactly one place, and that overlap is where most agreements go vague.
Does any law require your client to approve each AI email?
For ordinary business email, almost never. Four regimes do impose review duties on AI-assisted communications, and in every one the reviewer is a professional inside the business. Not the customer.
The EU AI Act. Article 50’s transparency obligations became applicable on 2 August 2026, with the Commission’s guidelines adopted on 20 July 2026 and fines of up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (Cooley, 2026).
The AI-generated text rule in Article 50(4) covers text published to inform the public on matters of public interest, so a normal one-to-one client email sits outside it (artificialintelligenceact.eu).
Look at the exemption where the rule does bite. Disclosure isn’t required where the content went through human review or editorial control and a person holds editorial responsibility for publishing it, and the Commission’s transparency guidelines say those checks “must be substantive and not limited to superficial matters or cursory approval.”
Human accountability, not customer approval. We broke down the wider European picture in what GDPR and the AI Act actually say about AI email disclosure.
Health care in California. AB 3030 has required, since 1 January 2025, that GenAI-generated patient communications about clinical information carry a disclaimer plus instructions for reaching a human. The requirement falls away when a licensed or certified provider reads and reviews the communication (ArentFox Schiff, Morgan Lewis, bill text). Same shape: the reviewer is the professional.
Broker-dealers. FINRA Rule 2210 has long required a registered principal to approve retail communications before use, and Regulatory Notice 24-09 reminded firms that the rule’s content standards “apply whether member firms’ communications are generated by a human or technology tool.”
Then in Notice 26-14, published 9 July 2026 with comments open through 11 September 2026, FINRA proposed replacing blanket pre-use approval with written, risk-based procedures that decide which categories need a principal’s sign-off, listing eight nonexclusive factors firms should weigh. It’s a request for comment, and any actual change still needs a rule filing approved by the SEC (Holland & Knight).
Read that one twice. The most approval-heavy communications regulator in US retail finance is proposing to move from approve-everything to sort-by-risk. And even under the current rule, the approver is a principal inside the firm.
Law firms. ABA Formal Opinion 512 says lawyers must independently verify GenAI output rather than trust it, and must obtain a client’s informed consent before entering that client’s confidential information into a self-learning GenAI tool.
Boilerplate in an engagement letter doesn’t amount to informed consent. Disclosure is owed when the client asks, when the engagement requires it, or when the output will influence a significant decision in the representation (UNC Law Library, NCBE, ABA Business Law Today).
This is general information, not legal advice. If you work in health, legal, financial, insurance, or education services, ask your regulator and your own counsel what applies to your communications. Our rundown of AI disclosure rules by industry is a starting map, not a substitute for that conversation.
Who’s on the hook when an AI email gets it wrong?
You are, and so is whoever’s name is in the From field.
In February 2024 the British Columbia Civil Resolution Tribunal found Air Canada liable for negligent misrepresentation after its website chatbot told a passenger he could apply for a bereavement fare retroactively, which was wrong. Air Canada argued the chatbot was a separate legal entity responsible for its own statements.
The tribunal rejected that, treated the chatbot as part of the company’s website like any other page, and ordered the airline to pay the fare difference plus interest and fees (decision, WeirFoulds, BD&P).
That matters here in a practical way. A client’s signature on a specific message doesn’t move accuracy risk anywhere useful, because the client is the party whose customers get the wrong answer. Approval is quality control, and quality control is the only thing it buys you. The liability stays where it started.
Why does per-email client approval usually backfire?
Three reasons, and the third one is the one nobody expects.
First, it recreates the bottleneck you were trying to remove. Every draft now waits on someone with no context about your queue and no reason to prioritize it.
Second, it spends the client’s attention on your workflow. Clients pay agencies so they can think about fewer things, and a daily approval queue does the opposite.
Third, high-volume approval decays into clicking yes. In the KPMG and University of Melbourne global study of 48,340 people across 47 countries, two-thirds of employees who use AI at work said they’d relied on its output without evaluating accuracy, and 56% said AI use had caused mistakes in their work (KPMG, 2025).
Legal scholars studying the AI Act’s human oversight duties for high-risk systems make a related point about automation bias. Laux and Ruschemeier argue that requiring providers to make deployers aware of over-reliance doesn’t address the design and context factors that produce it, so an oversight duty can be satisfied on paper while the human does very little (arXiv, 2025).
The cost lands downstream on whoever reads the output. BetterUp Labs and Stanford’s Social Media Lab surveyed 1,150 US full-time employees and found 40% had received AI-generated “workslop” in the previous month, with each instance taking an average of one hour and 56 minutes to sort out (HBR, 2025).
A worked example: the arithmetic on a 60-email week
Take an account where your AI drafts 60 client-facing emails a week. What follows is the arithmetic of the decision, not a reported client result.
Route all 60 through the client. At two minutes of real attention each, that’s two hours a week of your client’s time, plus a day of lag on every reply. You’ve charged them two hours a week to save yourself typing. Nobody renews that.
Now sort the same 60 by risk. Roughly a dozen touch price, scope, dates, numbers, complaints, or anything a lawyer would care about. Those get a named human on your team every single time, checked against the source record, with no graduation path.
The other 48 are scheduling, acknowledgements, and status notes. Approve every one for the first four weeks and log each edit you make. If the edit rate on a category stays near zero across a few hundred sends, that category moves to spot checks. Twenty-five seconds a draft on 48 drafts is about 20 minutes a week.
Treat the four weeks and the few hundred sends as starting defaults, not measured thresholds. Your own edit log is what should move them.
The client approves the policy behind that split once. They never see the queue.
First-hand from Magic Teams install weeks: the argument is rarely about draft quality. It lands on one question, which is who owns the send button. Teams that name a single accountable approver per client stop arguing within a day. Teams that leave it as “someone will check” end up with either nothing checked or the founder checking everything at 11pm.
So who approves what?
Sort by consequence, not by volume. This is the tier we install at Magic Teams, and the last column is the part most teams skip.
| Email type | Approver before send | How it graduates |
|---|---|---|
| Price, scope, timeline, contract terms | Named human on your team, every time | It doesn’t |
| Anything containing a number pulled from a report | Named human, checked against the source record | Only when the number comes from a validated data source |
| Complaints, apologies, legal-sounding threads | Named human, and the client is copied | It doesn’t |
| Regulated advice (legal, medical, financial, tax) | Licensed professional, under their own rules | It doesn’t |
| First-touch outreach in the client’s name | Client approves template and list once; your team approves each send early on | After four weeks with no factual corrections |
| Scheduling, acknowledgements, status notes | Your team, every send at first | After a clean run with near-zero edits, then spot checks |
Categories should move along a ladder, one rung at a time, on evidence rather than on how tired the reviewer is.
The evidence that moves a category up a rung is the edit log, which is why auditing AI email replies for accuracy is the same project as designing the approval gate.
How do you write this into the client agreement?
Put the specifics in the statement of work rather than the master agreement, because the tools and the mix change per project while the MSA sits still for years. Keep the general permission and liability language in the MSA.
- Which tasks AI may draft, named specifically, and which it may not
- What client data may be processed, where it is stored, and whether it trains any model
- Who the named human approver is, by role, and what they review before send
- Which email categories may auto-send and what evidence lets a category graduate
- How and where AI use is disclosed to the client's customers, if at all
- Who is liable for an error, and how the client can pause AI drafting on 24 hours' notice
A plain starting point to take to your lawyer: “Provider may use generative AI tools to draft communications within the categories listed in Schedule A. Every draft is reviewed and approved by a named Provider employee before sending, except for the categories marked auto-send in Schedule A. Client data is processed only within the systems listed in Schedule B and is not used to train third-party models. Client may withdraw consent for any category on 24 hours’ written notice.”
Have counsel adapt it. Contract language is jurisdiction-specific and this is not legal advice.
How do you keep approval from becoming a rubber stamp?
Design the reviewer’s screen, not just the policy. A reviewer who sees only generated text will approve generated text.
Show the draft next to the source it drew from, the specific rule that flagged it for review, and what changes on send. Cap the queue so nobody reviews 200 items in one sitting. Log every edit, because the edit rate is the only honest signal about whether a category is ready to move.
Then sample. Pull ten sent emails a week at random, including auto-sent ones, and read them properly. If you find a factual error in a graduated category, that category drops a rung the same day.
Frequently asked questions
Do I need the client’s permission to use AI on their account at all?
Check your contract first, because many 2024-onward MSAs already have a clause. Beyond the contract, ask anyway. Being found out later costs the relationship more than asking costs you, which is the whole argument in should I tell clients my agency uses AI.
Is a line in the MSA enough?
For general permission, usually. For confidential client information in regulated work, no. ABA Opinion 512 is explicit that boilerplate in an engagement letter doesn’t amount to informed consent for lawyers, and that’s a fair bar for advisory work generally.
What if the client says no AI at all?
Ask what specifically worries them. Most objections turn out to be about their data leaving their control or nobody checking the output. Both are answerable with a local-first setup and a named approver. If they still say no, honor it and write it into the SOW.
Does a human approving the email remove the need for a disclosure?
Sometimes, in specific regimes. California’s AB 3030 exemption for provider-reviewed communications and the AI Act’s editorial-responsibility exemption both work that way. It doesn’t generalize to every jurisdiction, so check yours.
How long should the approve-everything phase run?
Long enough to see a stable edit rate on real volume, not a fixed number of days. If you’re still editing one in five drafts in a category, that category isn’t ready. The related safety question is covered in is it safe to let AI answer customer emails.
The short version
If you’re staring at an inbox only you can clear and a client who’d rather not become your approval queue, the split above is the part worth getting right first. Consent to the method goes in the contract, once. Sign-off on the message stays with a named person on your side until the edit log says a category has earned its way out.
I’m Satya Phanindra Reddy, and this is the same design question we work through with agency owners during a Magic Teams AIOS install week. Once the tiers are on paper, it’s usually a one-conversation decision.