Who Is Liable When AI Sends the Wrong Email?

The short answer
The sender and the sender's employer are almost always legally responsible for an email an AI assistant sent from their account, not the AI vendor. Vendor terms of service cap what the tool company owes and disclaim output accuracy. Approval gates and audit logs reduce mistakes and preserve evidence, but they do not transfer legal liability. Consult counsel for your jurisdiction.
Who is responsible if AI sends the wrong email? Almost always the sender and their employer, not the AI vendor. What approval gates and audit logs change.
On this page
Who is responsible if AI sends the wrong email? Nearly always the same people who are responsible when a human sends one — the account holder and the organisation whose domain sits in the From line. Vendors of AI email tools cap what they owe in their terms of service, and no court so far has been persuaded that a language model is a legal person you can name in a claim. What an AI assistant changes is not the answer to the liability question. It is the volume of evidence about what happened, and whether an obvious mistake gets caught before it leaves.
This guide walks through the criteria that decide liability in practice, scores who owns what in the chain, works through a concrete example, and lists the red flags to fix in your own setup. It is general orientation about how these questions usually play out, not legal advice. For your contracts, jurisdiction, and industry rules, talk to your own lawyer.
The criteria that actually decide who pays#
Five levers determine who receives the complaint or the claim when something goes wrong with an email. They apply to any drafting tool, but they matter more when an AI is in the loop because the AI touches the message content, not just the envelope.
First, whose account it left. Every mailbox has an owner — a person or an organisation — and the message inherits their identity. The recipient's system sees the DKIM signature, the From address, and usually a company brand. A dispute travels back up that chain: recipient to sender to sender's employer. It does not travel sideways to a software vendor whose logo the recipient never saw.
Second, whether the message could bind the business. In most jurisdictions, an email exchange can form a contract if the parties meant it to and the terms are clear enough. The E-SIGN Act and UETA in the United States, and the United Nations Convention on the Use of Electronic Communications in International Contracts more broadly, treat electronic messages as capable of legal effect. An AI drafting the message does not remove that capacity — courts look at what the recipient reasonably understood, and someone reading a signed email on your domain is reasonable to assume you meant it.
Third, what the vendor's contract says. Terms of service for AI tools almost always contain three clauses that matter here — a liability cap that often limits recovery to fees paid in the last twelve months, an "as-is" disclaimer on output accuracy, and a customer indemnity for how you use the tool. This does not mean vendors take zero responsibility for anything, but it does mean the person seeking damages for a bad message will find the vendor a small and difficult target compared to the sender.
Fourth, which regulation covers the send. CAN-SPAM in the United States, GDPR and ePrivacy in the EU, HIPAA for US healthcare, FINRA and SEC rules for regulated finance, and dozens of country-level laws place duties on the sender or controller — not on the drafting software. A CAN-SPAM violation is the sender's violation, whether the offending footer was typed by an intern or drafted by an assistant.
Fifth, whether there is evidence of what happened. This is where AI email actually shifts the picture. A well-instrumented tool logs who ran the agent, what the agent proposed, what a human approved, and when it went out. That evidence protects a careful sender and exposes a careless one. It is not liability transfer — it is a much better paper trail than a manually typed message leaves behind.
General information, not legal advice
Who is responsible for what: a scoring table#
The table below maps the parties in the chain to what they are usually accountable for. Nothing here should surprise a general counsel; what surprises buyers is how little of the burden actually lands on the AI vendor.
| Party | Usually accountable for | Usual shield or limit |
|---|---|---|
| The sender (individual) | Content, tone, factual claims, commitments made in the message | Following approved templates and rules; a documented review before send |
| The sender's employer | Regulatory duties, brand statements, contracts formed on the company domain | Written policy, staff training, monitoring, an approval workflow |
| The AI vendor | Availability of the service — not typically the words in the message | Liability cap in the terms; as-is disclaimer on output; audit and undo tooling |
| The email provider (Google, Microsoft, IMAP host) | Delivery, retention, access controls on the mailbox | Provider terms and the shared-responsibility model |
| The recipient | Nothing, unless they misuse the message (e.g., leaking a confidential thread) | N/A — but their own retention determines how long your message survives |
The pattern is consistent across jurisdictions we have looked at: the closer a party is to the content leaving a real inbox, the more they own. The AI vendor is a supplier, not the sender, and the terms most vendors publish reflect that division. The two parties who almost always share the outcome are the person who authored or approved the send and the organisation whose address it left from. Between them sits the evidence — approvals, audit logs, and outbound records — which is what a lawyer will actually reach for if it comes to a dispute.
This is why the interesting design choice in an AI email tool is not "how autonomous is it" but "what does it record, and can I stop it before it sends." Neither of those changes who is legally responsible. Both change how defensible your position is when something goes wrong.

Worked example: an AI reply that agreed to a price by mistake#
A common worry maps to a common scenario. A sales rep runs an AI assistant on their Gmail. A prospect emails a purchase question. The agent replies in the rep's voice and, misreading a discount table in the context brain, promises a lower price than the rep would have offered. The prospect emails back to accept. Who is liable for the accepted number? Work it through the five levers.
- 1
Contract formation
A court will look at what the recipient reasonably understood. The email came from the rep's address, in the rep's voice, on the company domain — the reasonable read is that the company offered the price. Whether an enforceable agreement was formed depends on the discount terms, any counter-signed order, and the jurisdiction, but the starting position is that the company can be held to what left its domain.
- 2
Who inside the company carries it
The rep is an agent of the employer, and acts done in the course of employment usually attach to the employer rather than the individual. HR consequences for the rep — training, review, discipline — are a separate question from the company's legal liability to the customer, and the two do not offset each other.
- 3
What the AI vendor owes
Almost certainly, nothing directly to the buyer, who has no contract with the vendor. The vendor's contract is with the employer, is usually capped at recent fees paid, and disclaims accuracy of output. Recourse against the vendor for a bad message is limited to what the terms allow, and most terms do not allow much.
- 4
What the audit log is worth
If the log shows the mistaken draft went out without a human review, the employer has clear evidence of what went wrong — and no defence of due care. If the log shows a human approved the message, the same evidence tends to increase the case that the price offer was genuine and intended, which the buyer will use against you.
- 5
The clean fix
Correct the record in a short follow-up that references the wrong figure explicitly, states the actual price, and — if the buyer had already accepted — offers to negotiate rather than pretending the earlier message never happened. Then update the context brain or the approval rules so the same class of mistake cannot go out unreviewed again.
Do not delete the offending message
Red flags in your setup#
These are the configuration choices that turn an ordinary AI email tool into a real legal exposure. They are all fixable, and the fix is usually a policy decision rather than a technical one.
- Full autonomy on any mailbox that can bind the business. Agreements, quotes, refunds, HR communications, anything with a compliance duty — never on autopilot without human approval per message.
- No approval gate for outbound sends. If the tool can send without a human review, the person nominally in charge of the mailbox has no defence of due care to point at afterwards.
- No audit log the sender can produce on request. If you cannot show who drafted, who approved, and what went out, the argument becomes about your process rather than the message — and process arguments favour the party with the receipts.
- Agent tools that can act beyond email — Stripe refunds, calendar bookings that commit staff, CRM writes that count as records — running under a mailbox permission model rather than an explicit action allowlist.
- No untrusted-input handling. Any AI that reads incoming email and acts on it is a target for hidden instructions in the message body. Prompt-injection defences and an action allowlist for the agent are the minimum, not an option.
- Vendors that train models on your mail. Even where legal, this multiplies the surface area of a dispute — the message is no longer just in your archive and the recipient's, it is inside a model that was trained on it.
- Absent legal review of the vendor contract before signing. A twelve-month, fees-paid liability cap is standard, but there is a range, and a regulated business should read the terms before the incident, not during.
- Personal accounts used for business. The moment a work commitment leaves a personal address, the employer's monitoring and retention regime does not apply, but the employer's exposure often still does.
Untrusted input is not paranoia
What we'd pick, and why (honest)#
The recommendation for a reader of a decision-guide is not really a product — it is a posture. Assume the account holder is the legally responsible party and design the tool around evidence and approval, not around avoiding liability that will never leave you anyway. The buying question becomes narrower and easier: does the tool make it harder for the wrong message to go out, and does it leave a clean record of what did.
If you are shopping for a mail client to underpin that posture, AI Emaily is one to weigh. It ships an approve-before-send Copilot mode where every agent-drafted reply is held for your review and edit before it leaves, an audit log of what the agent proposed and what you approved, and a gated Autopilot for narrower tasks — not for one-click business commitments. It runs across Gmail, Outlook, and IMAP, treats incoming mail as untrusted input to the agent, does not train on your mail, and envelope-encrypts credentials and tokens at rest. We build AI Emaily.
The concession, plainly: no mail client — ours included — indemnifies you for what the message says. If you need contractual indemnity for the content that leaves your account, that is an enterprise procurement conversation with a vendor that owns your full send infrastructure and negotiates it into the master agreement, not a subscription feature at any price. What AI Emaily does is narrower and, for most buyers, more useful — it reduces the odds of the wrong message going out and preserves a clear record of what did.
So who should not buy this? A regulated sender whose real requirement is a written vendor indemnity for the message body should buy for that first and then choose a client. A team whose senders already have a strong second-review habit and a mature archiving stack will get less lift from Copilot's approval gate — the marginal message that goes out cleaner is the one that would have gone out cleanly anyway.
If, on the other hand, your real problem is that the wrong reply goes out at 11pm on a Sunday because the drafter was tired, or that the audit trail of what an assistant does on your behalf is a screenshot in a Slack thread, the approve-before-send plus audit-log shape is the one to buy. See how it works on the homepage, and the trial terms on pricing — AI Emaily runs a 7-day free trial on Pro and Autopilot rather than a permanent free tier.
Frequently asked
See it in AI Emaily
Keep reading
Sources

Written by
Nafiul HasanNafiul Hasan is an entrepreneur and AI automation system builder with 10+ years of experience turning messy, manual workflows into reliable automated systems. He designs and ships AI enterprise solutions end-to-end — the agent logic, the data plumbing, and the product people actually use — and founded AI Emaily to give busy professionals their attention back. He writes here from the builder's seat: what works, what breaks, and how to put AI to work without giving up control.