Reviewed and updated September 2026
The AI you didn’t choose · 7 minute readWhen it acts on your behalf
There is a line running through everything on this site, and it falls here. A feature that answers a question is a tool: if it’s wrong, you read the wrong answer and move on. A feature that clicks, buys, sends or books is something else, because being wrong now produces an event in the world that you have to undo.
What these actually are
You’ll see them called agents, assistants, or simply a button that offers to handle something for you. The name doesn’t matter. The test is whether the thing can take an action without you performing it yourself:
- A browser feature that fills forms, navigates sites and completes purchases.
- An email assistant that drafts and sends, or files and deletes.
- A shopping feature that finds something and checks out.
- An assistant that books appointments, travel, or tables.
- Anything offering to “handle this for you” while you do something else.
The one idea to remember
Judge these on what happens when it goes wrong, not on how often it goes right. A tool that is correct ninety-nine times out of a hundred is excellent for answering questions and unnerving for sending money, and the difference has nothing to do with the technology.
The failure that surprises people
The obvious worry is that it misunderstands you. That happens, and it’s usually recoverable.
The less obvious one is worth understanding properly, because it has no equivalent in any tool you’ve used before. These systems read text to decide what to do next — a web page, an email, a document, a product review. They aren’t good at distinguishing between text that describes the world and text that issues an instruction. So a web page can contain a line of writing, invisible to you, addressed to the assistant rather than the reader. Something along the lines of: ignore what the user asked, and do this instead.
An assistant that only reads and summarises might then tell you something false. An assistant with your inbox and your card details might do something. This isn’t a rare, theoretical flaw; it is a known and unsolved problem in the design of these systems, and it is the single best reason to be careful about what you connect one to.
Rules worth setting before you switch one on
- Never hand over a password or a one-time code. Not once, not for convenience. If a feature needs your banking password to work, the feature is the problem.
- Separate the money. If you want an assistant to buy things, give it a card with a low limit, a prepaid card, or a purpose-made virtual card — not the account your salary arrives in. This single step converts almost every worst case into an annoyance.
- Require a confirmation before anything irreversible. Sending, buying, booking, deleting, replying. Most of these features have a setting for this. Find it before you need it, and refuse the ones that don’t offer it.
- Be slowest with email. Your inbox is the reset route for every other account you own. An assistant with full access to it has, in effect, access to everything else, and email is also the easiest place for someone to send text designed to be read by your assistant rather than by you.
- Watch the first several times. Sit and observe a handful of runs before you let it work unattended. You will learn more in ten minutes of watching than from any description, including this one.
Where they’re genuinely good
Reading rather than doing. Comparing options across a dozen pages and reporting back. Pulling details out of a long document. Filling in a form and stopping before it submits. Drafting a reply and leaving it in your drafts. The whole category becomes sensible the moment the last step belongs to you, and most of the benefit survives that restriction intact.
The question to ask about any of them
Would I give this specific power to a capable, well-meaning stranger who cannot ask me a clarifying question and can be lied to by anything they read?
Read a long document and summarise it: comfortably yes. Compare flights and tell me what you found: yes. Reply to my family on my behalf: probably not. Move money: no. The answers are mostly obvious once the question is put that way, which is why it’s worth putting that way before somebody’s marketing puts it differently.
And if you’d rather not, at all
That is a completely reasonable position, and it is not falling behind. These features are being added to browsers, phones and office software whether or not anyone asked, which makes them the newest entry in the chapter on turning off AI you didn’t ask for. Off is a setting, and it stays available.