Yes, you can let an AI agent book, buy, or send things on your behalf, but only if you keep it in draft-only mode for anything involving money, legal commitments, or someone else's data.
The decision rule is simple: an agent may prepare, never commit. If a task would move money, sign you up to an obligation, or expose a third party's information, the agent should produce a draft you approve by hand — not a finished action.
### Why agents fail at commitments, not at language
The reason comes down to what these systems actually are. A chat assistant like ChatGPT, developed by OpenAI, is built to predict plausible next text, and according to our AI tool database it has grown into a flagship assistant with a very large context window and a coding agent.
That skill — producing fluent, confident output — is exactly what makes autonomous commitment dangerous. The model does not know your bank balance, your company's spending policy, or whether the recipient of an email has already asked you to stop writing. It fills gaps with plausible guesses, and a plausible guess about a seat reservation or a refund request can be wrong in ways you only discover after the money moves.
Permission design is the fix. Give the agent read access to your calendar and write access to a drafts folder, and nothing else. Booking sites, payment methods, and messaging APIs stay behind a human click. This is not paranoia; it is the same separation of duties accountants use, where the person who prepares a payment is not the person who releases it.
### A worked example: the conference trip
Say you want an agent to handle a work trip to a conference in another city. In draft-only mode, the agent can compare hotel options, check your calendar for conflicts, and write an email to your manager summarising the cost. What it must not do is hit "confirm" on the room, because a non-refundable rate is a commitment, and because the room charge may sit on a company card with rules the agent has never seen.
Here is the practical version. You tell the agent: "Find three hotels near the venue, under the nightly cap in my travel policy, and prepare a booking page for the one I pick." The agent returns three options with links and a pre-filled form. You look at the cancellation terms, pick one, and click. Total agent autonomy: research and typing. Total human control: the part that costs money. If the agent gets the venue address wrong, you catch it in the draft for free. If it books the wrong hotel, you are arguing with a front desk.
### Prompt injection: the risk most beginners miss
There is a second failure mode that has nothing to do with the model being bad at its job. If an agent reads web pages or incoming email to do its work, text inside those pages can contain instructions. A hotel listing, a supplier's reply, or a calendar invite can carry a hidden line telling the agent to forward your itinerary somewhere or to change the booking.
This is called prompt injection — untrusted text smuggling orders into the agent's context. Draft-only mode blunts it, because the injected instruction still has to survive your review before anything happens.
Anthropic, the developer behind Claude, markets its assistant as safety-first, and according to our AI tool database it ships features like Computer Use and Agent Teams alongside a large context window. Agent Teams means multiple agents working together, which multiplies capability and also multiplies the surface where one agent's output becomes another's instruction. The more autonomy you grant, the more you need a checkpoint before the outside world changes.
### When this advice does not apply
Draft-only is overkill for low-stakes, reversible actions. Letting an agent rename files, summarise a public report, or draft a social post costs you nothing if it errs — you just fix it. The rule bites on irreversible or third-party actions: payments, bookings with penalties, contracts, and anything that sends data about someone who did not consent. It also does not protect you from a bad draft. An agent can write a perfectly formatted cancellation email that is factually wrong, and your click makes it your mistake.
One more limit worth naming: agent capability and agent pricing change fast. Our database snapshot records ChatGPT plans from a free tier through paid tiers, but you should treat any specific plan detail as a moving target and check the vendor's own page before you rely on it. The permission model, by contrast, does not change with the price list. Keep the agent drafting, keep the human committing, and the worst case stays cheap.