Human in the Loop for AI Outbound Agents
Drafting is cheap to redo and a sent message is spent. Where an outbound AI agent needs a person, why queue review fails at volume, and what to ask a vendor.
By Harinderpal Hanspal on July 2026. Updated October 2026
OWASP tells builders to require human approval before an agent takes a high-impact action, and its example is posting content. For outbound, that means a person approves what reaches a prospect, with the recipient's status in view, while research and drafting run alone.
An outbound agent can research an account, enrich the contact record, score the lead and draft a message without anyone watching. Each of those steps can be redone. The next one cannot. A sent email sits in someone's inbox, and the agent that wrote it cannot reach in and pull it back.
What the guidance says about outward actions
OWASP's 2025 list names "excessive agency" as risk LLM06 and advises requiring a human to approve high-impact actions before they are taken. Its own example is a content app that should include an approval routine before posting (OWASP GenAI Security Project, LLM06:2025). Sending to a prospect is the same shape of action.
The legal duty does not move to the software, either. The FTC's CAN-SPAM guide says a sender cannot contract away its responsibility, and that each separate violating email can carry a penalty of up to $53,088, the figure in the guide as adjusted for inflation (FTC, August 2023, edited January 2024).
On the governance side, Deloitte's survey of 3,235 senior leaders in 24 countries (fieldwork August to September 2025) found that only one in five companies has a mature model for governing autonomous agents (Deloitte, State of AI in the Enterprise 2026).
The market has produced at least one public dispute. In March 2025 TechCrunch reported allegations that 11x, a vendor of AI sales agents, had claimed customers it did not have. ZoomInfo said its one-month trial found the product performed significantly worse than its own sales development reps. 11x disputed the reporting (TechCrunch, 24 March 2025). That is one vendor and a set of allegations. It does not show how autonomous outreach performs as a category.
How people gate outreach today, and where it leaks
Two patterns dominate. One is a review queue: the agent drafts, a person reads each message and clicks approve. The other is send-then-sample: the agent sends freely and someone audits a slice afterward.
The queue has a throughput problem and a vision problem. A person approving every message moves at the speed of their attention, so volume pushes reviewers toward a quick yes. Anthropic reported in March 2026 that users of its coding tool approve 93% of permission prompts, and built classifiers to reduce what it called approval fatigue (Anthropic Engineering, 25 March 2026). That is a different tool and a different population, but the pattern transfers: a gate that asks about everything is a gate people stop reading.
The vision problem is subtler. A reviewer who sees only the draft cannot see that the address unsubscribed last week, that a colleague already wrote to the same account on Monday, or that the claim in the second paragraph came from a stale record. Approving prose is not approving a send.
Then there are the side doors. A queue guards the route it was built for. An API call, a second channel added later, or a worker that was never meant to be reachable can send without ever touching it. And if the agent can raise its own autonomy level, the person was only ever advisory.
The sturdier design puts the policy outside the agent, in code the agent cannot edit, and runs the same checks on every route that can reach a transport.
Questions to ask before an agent writes to your prospects
- Which actions run unattended, and which wait for a person? Is sending on the second list?
- What does the approver see: the draft, or the recipient, the consent status and the prior contact history?
- Does every route out, including the API and any second channel, pass the same checks?
- Who can raise the agent's autonomy, and can the agent do it for itself?
- When a person is on the boundary, how many messages per hour can they actually read?
- Does a decision to allow, hold or refuse leave a record on every path, not only the scheduled one?
Drawn from the OWASP LLM Top 10 (2025), the FTC's CAN-SPAM guide (August 2023, edited January 2024), Anthropic Engineering (25 March 2026), Deloitte's State of AI in the Enterprise 2026 and TechCrunch (24 March 2025), all read on 6 October 2026. No figure here is a measurement of ours.
Related notes
- Where to put the human in an AI agent's work: approve the write, not the draft
- AI agent unsubscribe: a suppression list is only as fresh as the send
Related insights
- Why buyers rate AI autonomy before they rate accuracy
- Why an AI agent that acts needs different validation
Related paper: Governing agents in production: what to ask before an agent acts