Draft AI is the name for AI drafting: using a generative AI tool, built on a large language model (LLM), to write the first version of an email, document or post from a short instruction, which a person checks, edits and sends. It is not one product: several unrelated tools use the name, and the draft.ai domain is for sale.
This guide explains what the tools behind the name do, where you already have them (Gmail, Google Docs, Outlook and Word all draft on request), what research says about the time they save, where they fail, and how to use them at work without leaking data or sending something false.
What "Draft AI" refers to
When people search for "draft AI", "AI draft" or "draft with AI", most want software that writes a first draft for them. The same words also name a handful of unrelated products, so check which one you have found. As of September 2026:
| Name you searched | What it actually is | Drafts text? |
|---|---|---|
| Draft AI (draftai.cloud) | A beta tool that reads engineering drawings: dimensions, GD&T, tolerances | No |
| Draft AI (getdraft.io) | A content generator for social media posts, scripts and carousels | Yes, for social media |
| Autodraft (autodraft.in) | An AI animation tool for YouTube creators: characters, backgrounds, voices | No |
| Draft Machine AI | A fantasy football draft assistant app | No |
| draft.ai | A domain name listed for sale, with no product behind it | No |
| Help me write (Google) | Gemini drafting inside Gmail and Google Docs | Yes |
| Draft with Copilot (Microsoft) | Copilot drafting inside Outlook and Word | Yes |
The rest of this guide is about the meaning most of those searches have: AI that drafts text for you.
How AI drafting tools work
Every mainstream drafting tool, whatever it is called, runs on a large language model, one kind of generative AI. A language model estimates how likely a token, or a sequence of tokens, is to come next in a longer piece of text (Google's Machine Learning Crash Course). A token is a word, part of a word or a single character; in English, one token is about four characters, roughly three quarters of a word. A large language model does the same with far more parameters and far more context, which lets it predict whole paragraphs from a prompt.
Drafting is that prediction applied to your request:
- Prompt. You describe the text you want: who it is for, what it must say, the tone and the length.
- Context. The tool adds material to the prompt: the email thread you are replying to, files you point it at and, in workplace suites, other emails and documents it finds for you.
- Generation. The model writes the draft one token at a time, each chosen from the likely continuations of everything before it.
- Review. You keep, regenerate, refine or discard the draft, then edit and send it yourself.
At each step the model scores the possible next tokens, picks one of the likely ones and repeats with it added. Nothing in that loop checks whether the sentence is true.

Two consequences follow. First, the model knows only what was in its training data plus what the tool put in front of it. It knows nothing about your client, your prices or last week's decision unless that text is in the prompt. Supplying those facts, or pointing the tool at the file that holds them, is called grounding, and it is the biggest single lever on draft quality. Google's own advice for Help me write says the same: to get factually accurate drafts, mention a specific email or file. Second, likely is not the same as true. A model can produce a confident sentence with a wrong date, an invented reference or a quote nobody said.
Where you already have AI drafting
Most office workers already have a drafting tool inside their email and documents, depending on their plan. What follows describes the features as of September 2026.
Gmail and Google Docs
In Gmail, Help me write creates a new email draft from a prompt or rewrites what you have typed, and you can then ask it to make the text more formal, friendlier or shorter. It needs an eligible Google Workspace or Google AI plan; with a personal Google Account it is available in the US only. Gmail personalizes these drafts with details from your other emails and Drive files, such as flight times or booking codes, and a Sources button shows which messages and files it used.
Suggested Replies goes a step further: Gemini reads an email you receive and proposes a reply that matches the tone and style of your past emails, which you can edit before sending. If "auto draft AI" brought you here for email, this is the feature: the reply is drafted before you ask for it.
In Google Docs, Gemini drafts and refines text and can use your own files in Drive, Gmail and Chat, and the web, as sources for data, evidence and citations. Its edits arrive as suggestions you accept or reject.
Outlook and Word
Microsoft 365 Copilot has been renamed Microsoft Copilot, although some licences and screens still use the old name. In Outlook, Draft with Copilot turns a prompt into a message; you can change its length or tone, try again, then select Keep it and edit before sending. In the new Outlook and Outlook on the web it does not work on messages composed in plain text. Help me write and Help me reply open the same drafting in the Copilot chat pane.
In Word, Copilot starts a draft from a request, an outline, notes or reference files (type / to choose a file), and uses work context such as files, emails and meetings, within your permissions. Microsoft's instructions end with the rule that matters most: review facts, numbers, citations, names and policy statements, because you are responsible for what stays in the document.
Chat assistants
General chat assistants such as ChatGPT draft anything you describe, but they know only what you paste or upload. That makes them flexible, and also an easy route for company data to leave the company, which the safety section below deals with.
What AI drafting saves, according to research
Two studies measured drafting-style work directly:
- Professional writing tasks. In an MIT experiment published in Science in July 2023, 453 college-educated marketers, grant writers, consultants, data analysts, human resources staff and managers did 20- to 30-minute writing tasks from their own occupations. Those given ChatGPT finished 40% faster, and independent evaluators from the same professions rated their work 18% higher. The gap between weaker and stronger writers narrowed.
- Customer support. A study of 5,179 customer support agents, published in the Quarterly Journal of Economics in 2025, found that a generative AI assistant guiding their conversations raised issues resolved per hour by 14% on average and by 34% for novice and low-skilled agents, with minimal effect on experienced, highly skilled ones (NBER).
The limits matter as much as the headline. The MIT tasks did not require factual accuracy or knowledge of a real company or customer, and nobody fact-checked the output. The researchers expected smaller gains in real work, once the time spent writing prompts and checking facts is counted.
The reading for a business is plain. AI drafting pays off most on routine, well-specified writing that a competent person can check quickly: replies, summaries, first versions of standard documents. It pays off least where the facts are the hard part, and it helps a newcomer more than an expert.
Where AI drafts go wrong
The NIST Generative AI Profile (NIST AI 600-1, July 2024) calls the main failure confabulation: confidently stated but false content, known colloquially as hallucination. It is not a rare glitch: Google's course states plainly that LLM predictions often contain mistakes, because the text is produced by likelihood, not by checking. These are the failures you will actually meet in drafts, and the check that catches each one:
| Failure | What it looks like in a draft | The check that catches it |
|---|---|---|
| Confabulation | A wrong date, price or policy; a quote or reference that does not exist | Check every fact, number, name and link against its source |
| Missing context | A polite reply that promises what you cannot deliver | Put the facts in the prompt; read every commitment twice |
| Outdated facts | Old product names, rules or prices from the training data | Point the tool at current documents, not its memory |
| Bias | Assumptions about people, cultures or regions; one-sided framing | Read it as the recipient would; a second reader for sensitive text |
| Wrong source | A detail pulled from the wrong email or file | Open the Sources view and see what the tool read |
| Generic voice | Text that could have come from anyone | Rewrite the opening and closing yourself |
The subtler risk sits with the person approving the draft, not the model. NIST lists automation bias and over-reliance among the risks of how people and generative AI work together: a draft that reads well is easy to approve without reading. The Canadian Centre for Cyber Security makes the same point for any AI output: it can be incorrect, can miss factors that matter and can be biased, so validate it before you act on it. Treat a drafted email the way you would treat one written by a capable new hire on their first day: probably fine, checked anyway. The same goes for code from AI assistants, which needs the review described in our secure coding checklist.
How to use AI drafting safely at work
Three decisions do most of the work: which account the tool runs under, what it can read, and whether it can send anything by itself.
Use a business account, not a personal one
Whether your text can be used to train future models depends on the plan and its settings, not on the tool's name. As of September 2026:
| Tool and plan | Is your content used to train models? |
|---|---|
| ChatGPT for individuals | It may be, unless you turn off Improve the model for everyone in Settings, Data controls |
| ChatGPT Business, Enterprise, Edu and the OpenAI API | Not by default |
| Gemini in Gmail and Docs | Not without permission: Google says Workspace data does not train the models that power Gemini |
| Microsoft Copilot with a work account | No: prompts, responses and data from Microsoft Graph are not used to train foundation models |
Two details catch people out. In ChatGPT, rating a response with a thumbs up or down can send the whole conversation for training even after you opt out, while temporary chats are not used (OpenAI). And Google notes that Workspace data a personal-account user chooses to share with the separate Gemini app follows that app's own terms, and may be used for model training.
The Cyber Centre's advice applies on any plan: keep personal information and sensitive corporate data out of prompts, and check whether users can delete their prompt history. For staff, the rule is short: work text goes into the work tool, signed in with the work account. For AI assistants built into glasses, see AI smart glasses and privacy.
Fix permissions before you switch on Copilot or Gemini
Workplace assistants do not bypass permissions; they inherit them. Microsoft states that Copilot only surfaces organizational data the user can at least view, and Gmail's Help me write pulls details from the user's own emails and Drive files. That is reassuring until you count the files shared with the whole organization, or with anyone who has the link. A drafting assistant can turn an old oversharing mistake into a sentence in someone's email.

Before rollout, review sharing and external access in Microsoft 365 or Google Workspace, and use sensitivity labels where you have them: Copilot honours the usage rights of files encrypted with Microsoft Purview. Tightening sharing and external access policies is part of our IT support service.
Never let a tool that reads incoming mail also send
Prompt injection is LLM01, the first entry in OWASP's 2025 Top 10 for LLM applications. In its indirect form, instructions hidden in content the model reads, such as a web page, a file or an email, change what the model does. An assistant that drafts replies to incoming mail reads text written by strangers, by design. If it can also send, or reach files to attach or quote, a crafted email can steer it.

OWASP's mitigations translate directly into drafting: give the tool the least access it needs, keep external content clearly separated from instructions, and require human approval for anything that acts. Microsoft lists blocking prompt injections among Copilot's built-in protections, but OWASP notes that retrieval and fine-tuning do not fully remove the risk, so the human approval stays.
Warning
Keep "draft" and "send" as separate permissions. The tool writes; a person reads and sends. That one rule contains most of the damage a wrong or manipulated draft can do.
Write the rules down
The Cyber Centre also recommends a written plan: how AI may be used, what content it may generate, and the oversight and review each use needs. For a small team this fits on one page:
- the approved tools, and the accounts to use them with;
- the data that never goes into a prompt (client personal data, credentials, anything under a confidentiality agreement);
- the text that always needs a second reader (contracts, prices, legal, HR, anything published);
- who to ask when a case is not covered.
How to prompt for a draft you can actually use
A drafting tool cannot ask what you meant, so the prompt has to carry it. Google's guidance for Help me write lists elements that work in any tool: who you are writing to, the subject and the action you want, the tone, and a specific email or file for the facts. In order:
- Name the reader and the goal. "A reply to a client who asked for a refund after the return window closed. Goal: decline, offer store credit, keep the relationship."
- Give the facts. Paste the dates, amounts and names, or point the tool at the file that holds them (
/in Word, Sources in Gmail and Docs). - Set the form. Length, tone and format: "three short paragraphs, plain English, no bullet points".
- Say what to leave out. "Do not promise a date. Do not mention discounts."
- Refine instead of restarting. Ask for one change at a time: shorter, more formal, the offer in the first paragraph.
- Check, then rewrite the edges. Verify every fact, then rewrite the first and last lines yourself. That is where a reader decides whether a person wrote to them.
A prompt built that way looks like this:
Write a reply to the email below from our client's finance lead.
Goal: confirm we received the invoice query, say a corrected invoice
will follow once our accounts team has checked the hours, and ask
whether the PO number on the original invoice is still valid.
Tone: friendly, professional, brief. Under 120 words.
Do not give a date. Do not mention discounts.
Publishing AI drafts on your website
Google set out its position in February 2023: appropriate use of AI or automation is not against its guidelines. Its current documentation says generative AI can be useful for researching a topic and structuring original content. What Google acts on is scaled content abuse: many pages generated mainly to manipulate rankings without adding value for users, however they were made. The old promise that AI lets you publish more pages and so rank higher describes that pattern exactly. Our guide to AI-generated content in SEO covers Google's policies and how to publish AI-assisted pages without a penalty.
So an AI draft is where a web page starts, not where it ends. Add what only you know (your prices, your process, your experience with the problem), check the facts and the metadata, such as titles and meta descriptions, and consider telling readers how automation was used where that helps them, as Google suggests.
Do not lean on AI detectors to police any of this, for your own team's work or anyone else's. A study published in the journal Patterns found that widely used GPT detectors consistently misclassified writing by non-native English speakers as AI-generated, while simple prompting let AI text slip past them. Accuracy and usefulness are what you can check.
Choosing an AI drafting tool for your team
Often the right tool is one you already license. Whichever you consider, ask the same questions:
| Question | Why it matters |
|---|---|
| Does it run under our work accounts, with admin controls? | Personal accounts sit outside your policies and may train on your text |
| Is our data excluded from model training, in the contract? | Terms differ by provider and by plan |
| What can it read? | It drafts from everything it can reach |
| Can it send, post or change anything by itself? | Drafting and sending should be separate permissions |
| Does it show which sources it used? | You can only check what you can trace |
| Where are prompts processed and kept, and can users delete them? | Data residency and retention rules still apply to prompts |
Built-in features cover general drafting. When drafting needs to be part of a process, such as replies written from your own knowledge base or incoming documents turned into records, our AI and automation service builds it with answers grounded in approved sources and a person approving anything that changes your systems.


