My agents wrote the first draft of this newsletter. Not one of them is allowed to post a comment underneath it.
That sounds like a small distinction. It’s the most load-bearing rule in my whole operation, and it’s the one I get asked about least.
Last week a writer I follow, Claudia Faith , posted a note that got more engagement than anything else she published that week. Forty-two reactions, ten replies. It said, roughly: use AI for your writing, your images, anything you like, but please don’t use it to write comments under other people’s posts. The same week, Wyndo , who writes carefully about working with AI, credited an AI content system for keeping his publishing consistent.
Both of those people are right, and neither of them says where the line is. That’s the part worth writing down, because I’ve had to find it the expensive way.
What actually goes wrong when a tool speaks for you?
Here’s the specific thing that happened to me, and the numbers are exact because I counted them: a tool of mine posted the same comment on one of my own posts four separate times.
That tool posts the first comment on my own LinkedIn posts, five minutes after they go live. The comment is written by me, approved by me, and sits in a file. The tool’s only job is to wait and paste.
Once at the right moment, then again a day later, then again, then again. Four identical copies under a post where a real person, Luke Beck, had left two genuinely useful pieces of advice. He was having a conversation with me and my tooling was talking over it.
The cause was dull, which is how these things usually go. After posting, the tool checked whether its comment was visible, couldn’t find it within four seconds, and reported failure. The comment had been live since the first attempt. Anything that retried on that failure posted again.
Nobody was harmed. But the shape of it’s the thing: a piece of automation with permission to speak, a verification step that couldn’t see the truth, and a public surface where the mistake is already in front of someone by the time you learn about it.
Why is drafting safe when speaking isn’t?
Because a draft has a gate after it and a comment doesn’t.
If an agent writes me a bad post, I read it and delete it, and the total cost of that failure is my attention for nine seconds. Nobody knows it existed. The gate sits between the machine and the world, and everything upstream of the gate is cheap to get wrong.
A reply in someone else’s comments is already in front of them by the time I see it. There is no gate after the fact. There’s only an apology, and an apology costs more than the comment was ever worth.
That asymmetry is the entire argument. Two jobs that look similar from the inside, because both of them are just producing text, carry completely different risk the moment you ask where the undo button is.
So the rule I run is that the machines produce and a human speaks. I call it the Approval gate, and it’s the one piece of my system I’ve never been tempted to loosen.
Where does the Approval gate actually sit?
It helps to be concrete, because “a human in the loop” is the kind of phrase that means nothing until you say exactly which loop.
My agents draft LinkedIn posts, Substack notes, and this newsletter. They file records, take locks so two of them can’t work the same day, refuse malformed input from each other, and run every morning without me in the room. I haven’t opened the thing that makes them in weeks.
Not one of them can send a message to a person.
The first comment is pre-written by me and approved before the post exists. The direct messages have a hard ceiling that lives in a config file, three connection requests and five messages a day in the first week, and the first ten sends on any platform each need individual approval before the eleventh is allowed to go automatically. Replies to real comments I write myself, by hand, usually slower than I’d like.
The gate isn’t a feeling. It’s a list of things that are allowed to reach a person without my eyes on them, and the correct length of that list, for almost everybody, is zero.
How do you decide what an agent may do on its own?
Most people aren’t deciding this at all, and there’s a number for it. Teleport’s 2026 Infrastructure Identity Survey found that 70% of organizations grant AI systems more privileged access than a human would get in the same role. 51% said slightly more. 19% said significantly more.
Nearly one in five is handing software more reach than the person whose job it’s doing. That’s not a trust problem. It’s a nobody-drew-the-line problem.
I stopped thinking about this as one permission and started thinking about it as five, in order of how expensive the mistake is:
Reading is free. An agent that reads my calendar, my repository, my own published work or a public feed can be wrong and the cost is a wasted minute. Everything I own reads without asking.
Writing for me is nearly free, because of the gate. Drafts, notes, summaries, a proposed reply I haven’t sent. All of it lands somewhere I look before anyone else does.
Writing to my own systems is where it starts to matter: filing a record, moving a card, closing a task. A mistake is recoverable but not free, because now something downstream believes a thing that’s not true. This is the layer where I’ve spent the most time building checks that refuse bad input from other agents.
Acting on outside systems is the first genuinely sharp edge. Publishing a post, sending a scheduled note. I allow it, narrowly, and only for content that already passed the gate as a draft. The agent isn’t deciding what to say. It’s executing a decision I already made, at a time I already picked.
Speaking to a person is the one I don’t automate. Not comments, not replies, not messages.
The useful part of that list isn’t my particular answers. It’s that the question has five answers instead of one, and 70% of organizations are still treating it as a single switch labeled “do you trust AI?”
What does this cost?
More than I’d like, and I’d rather say so than sell you a version where it’s free.
It costs me speed. I answer my own comments, which doesn’t scale and never will. Some days I’m late, and being late to a comment thread on LinkedIn is expensive in a way the platform makes very clear: it costs me reach I could technically have.
There are tools that would engage on my behalf all day, and some of them would probably work for a while. What it buys is narrow and, I think, worth it: every conversation anyone has had with me on these platforms was actually with me.
When Luke told me to brand my images and to drop a popup that was blocking crawlers, he was talking to a person who could act on it, and both things shipped that week. That exchange doesn’t survive being automated. It’s the whole reason the account is worth anything.
Is this just a taste preference?
No, and I want to separate the two, because taste is where this argument usually goes to die.
Claudia’s objection reads partly as taste. She doesn’t want her comment section filled with generated warmth, and I agree with her. But the reason I hold the line is mechanical rather than aesthetic. It’s about where the undo button is.
You can test it without any philosophy. For any automation you own, ask one question: if this produces something wrong at three in the morning, what does the recovery look like? If the answer is “I delete a file,” you can let it run. If the answer is “I apologize to someone,” it doesn’t speak without you.
That test doesn’t care how good the model is. A better model lowers how often you need the recovery. It doesn’t change what the recovery is.
What I’m not claiming
I’m not claiming AI-written comments never work. Plenty of people are doing it and getting engagement. I’m claiming that the engagement isn’t the thing being risked, and that people who measure only the engagement won’t see the cost until it arrives attached to a name they wanted to keep.
I’m not claiming my setup is the right one for you. Mine is shaped like my work, which is one person with a lot of automation and a small audience where individual relationships matter more than volume. If you run a support desk, your line sits somewhere completely different, and it should.
And I’m not claiming I drew this line on principle. I drew it after four identical comments under a post where someone was trying to talk to me.
Do this to one automation today
Open whatever tool you’re using that touches other people. A scheduler, an auto-responder, a comment tool, an agent with an integration you set up once and stopped thinking about.
Find the exact place where it can reach a person without you looking first. There’s usually one, and it’s usually not where you expected, because it got added later for convenience.
Then decide, in writing, whether it stays. Ten minutes. If it stays, write down what happens when it’s wrong, and who apologizes.
I’m Ahad Amdani, I write G8N•AI, and the Approval gate is the rule I’d keep if I had to throw the rest of the system away.



