Draft AI is the name for AI drafting: using a generative AI tool, built on a large language model (LLM), to write the first version of an email, document or post from a short instruction, which a person checks, edits and sends. It is not one product: several unrelated tools use the name, and the draft.ai domain is for sale.

This guide explains what the tools behind the name do, where you already have them (Gmail, Google Docs, Outlook and Word all draft on request), what research says about the time they save, where they fail, and how to use them at work without leaking data or sending something false.

What "Draft AI" refers to

When people search for "draft AI", "AI draft" or "draft with AI", most want software that writes a first draft for them. The same words also name a handful of unrelated products, so check which one you have found. As of September 2026:

Name you searchedWhat it actually isDrafts text?
Draft AI (draftai.cloud)A beta tool that reads engineering drawings: dimensions, GD&T, tolerancesNo
Draft AI (getdraft.io)A content generator for social media posts, scripts and carouselsYes, for social media
Autodraft (autodraft.in)An AI animation tool for YouTube creators: characters, backgrounds, voicesNo
Draft Machine AIA fantasy football draft assistant appNo
draft.aiA domain name listed for sale, with no product behind itNo
Help me write (Google)Gemini drafting inside Gmail and Google DocsYes
Draft with Copilot (Microsoft)Copilot drafting inside Outlook and WordYes

The rest of this guide is about the meaning most of those searches have: AI that drafts text for you.

How AI drafting tools work

Every mainstream drafting tool, whatever it is called, runs on a large language model, one kind of generative AI. A language model estimates how likely a token, or a sequence of tokens, is to come next in a longer piece of text (Google's Machine Learning Crash Course). A token is a word, part of a word or a single character; in English, one token is about four characters, roughly three quarters of a word. A large language model does the same with far more parameters and far more context, which lets it predict whole paragraphs from a prompt.

Drafting is that prediction applied to your request:

  1. Prompt. You describe the text you want: who it is for, what it must say, the tone and the length.
  2. Context. The tool adds material to the prompt: the email thread you are replying to, files you point it at and, in workplace suites, other emails and documents it finds for you.
  3. Generation. The model writes the draft one token at a time, each chosen from the likely continuations of everything before it.
  4. Review. You keep, regenerate, refine or discard the draft, then edit and send it yourself.

At each step the model scores the possible next tokens, picks one of the likely ones and repeats with it added. Nothing in that loop checks whether the sentence is true.

A prompt document feeds into a model box. A row of blocks grows to the right, and the tallest of four candidate blocks, in orange, drops into the next empty slot.
Fig. 1 The model picks likely words, not checked facts, which is why a fluent draft can still be wrong.

Two consequences follow. First, the model knows only what was in its training data plus what the tool put in front of it. It knows nothing about your client, your prices or last week's decision unless that text is in the prompt. Supplying those facts, or pointing the tool at the file that holds them, is called grounding, and it is the biggest single lever on draft quality. Google's own advice for Help me write says the same: to get factually accurate drafts, mention a specific email or file. Second, likely is not the same as true. A model can produce a confident sentence with a wrong date, an invented reference or a quote nobody said.

Where you already have AI drafting

Most office workers already have a drafting tool inside their email and documents, depending on their plan. What follows describes the features as of September 2026.

Gmail and Google Docs

In Gmail, Help me write creates a new email draft from a prompt or rewrites what you have typed, and you can then ask it to make the text more formal, friendlier or shorter. It needs an eligible Google Workspace or Google AI plan; with a personal Google Account it is available in the US only. Gmail personalizes these drafts with details from your other emails and Drive files, such as flight times or booking codes, and a Sources button shows which messages and files it used.

Suggested Replies goes a step further: Gemini reads an email you receive and proposes a reply that matches the tone and style of your past emails, which you can edit before sending. If "auto draft AI" brought you here for email, this is the feature: the reply is drafted before you ask for it.

In Google Docs, Gemini drafts and refines text and can use your own files in Drive, Gmail and Chat, and the web, as sources for data, evidence and citations. Its edits arrive as suggestions you accept or reject.

Outlook and Word

Microsoft 365 Copilot has been renamed Microsoft Copilot, although some licences and screens still use the old name. In Outlook, Draft with Copilot turns a prompt into a message; you can change its length or tone, try again, then select Keep it and edit before sending. In the new Outlook and Outlook on the web it does not work on messages composed in plain text. Help me write and Help me reply open the same drafting in the Copilot chat pane.

In Word, Copilot starts a draft from a request, an outline, notes or reference files (type / to choose a file), and uses work context such as files, emails and meetings, within your permissions. Microsoft's instructions end with the rule that matters most: review facts, numbers, citations, names and policy statements, because you are responsible for what stays in the document.

Chat assistants

General chat assistants such as ChatGPT draft anything you describe, but they know only what you paste or upload. That makes them flexible, and also an easy route for company data to leave the company, which the safety section below deals with.

What AI drafting saves, according to research

Two studies measured drafting-style work directly:

  • Professional writing tasks. In an MIT experiment published in Science in July 2023, 453 college-educated marketers, grant writers, consultants, data analysts, human resources staff and managers did 20- to 30-minute writing tasks from their own occupations. Those given ChatGPT finished 40% faster, and independent evaluators from the same professions rated their work 18% higher. The gap between weaker and stronger writers narrowed.
  • Customer support. A study of 5,179 customer support agents, published in the Quarterly Journal of Economics in 2025, found that a generative AI assistant guiding their conversations raised issues resolved per hour by 14% on average and by 34% for novice and low-skilled agents, with minimal effect on experienced, highly skilled ones (NBER).

The limits matter as much as the headline. The MIT tasks did not require factual accuracy or knowledge of a real company or customer, and nobody fact-checked the output. The researchers expected smaller gains in real work, once the time spent writing prompts and checking facts is counted.

The reading for a business is plain. AI drafting pays off most on routine, well-specified writing that a competent person can check quickly: replies, summaries, first versions of standard documents. It pays off least where the facts are the hard part, and it helps a newcomer more than an expert.

Where AI drafts go wrong

The NIST Generative AI Profile (NIST AI 600-1, July 2024) calls the main failure confabulation: confidently stated but false content, known colloquially as hallucination. It is not a rare glitch: Google's course states plainly that LLM predictions often contain mistakes, because the text is produced by likelihood, not by checking. These are the failures you will actually meet in drafts, and the check that catches each one:

FailureWhat it looks like in a draftThe check that catches it
ConfabulationA wrong date, price or policy; a quote or reference that does not existCheck every fact, number, name and link against its source
Missing contextA polite reply that promises what you cannot deliverPut the facts in the prompt; read every commitment twice
Outdated factsOld product names, rules or prices from the training dataPoint the tool at current documents, not its memory
BiasAssumptions about people, cultures or regions; one-sided framingRead it as the recipient would; a second reader for sensitive text
Wrong sourceA detail pulled from the wrong email or fileOpen the Sources view and see what the tool read
Generic voiceText that could have come from anyoneRewrite the opening and closing yourself

The subtler risk sits with the person approving the draft, not the model. NIST lists automation bias and over-reliance among the risks of how people and generative AI work together: a draft that reads well is easy to approve without reading. The Canadian Centre for Cyber Security makes the same point for any AI output: it can be incorrect, can miss factors that matter and can be biased, so validate it before you act on it. Treat a drafted email the way you would treat one written by a capable new hire on their first day: probably fine, checked anyway. The same goes for code from AI assistants, which needs the review described in our secure coding checklist.

How to use AI drafting safely at work

Three decisions do most of the work: which account the tool runs under, what it can read, and whether it can send anything by itself.

Use a business account, not a personal one

Whether your text can be used to train future models depends on the plan and its settings, not on the tool's name. As of September 2026:

Tool and planIs your content used to train models?
ChatGPT for individualsIt may be, unless you turn off Improve the model for everyone in Settings, Data controls
ChatGPT Business, Enterprise, Edu and the OpenAI APINot by default
Gemini in Gmail and DocsNot without permission: Google says Workspace data does not train the models that power Gemini
Microsoft Copilot with a work accountNo: prompts, responses and data from Microsoft Graph are not used to train foundation models

Two details catch people out. In ChatGPT, rating a response with a thumbs up or down can send the whole conversation for training even after you opt out, while temporary chats are not used (OpenAI). And Google notes that Workspace data a personal-account user chooses to share with the separate Gemini app follows that app's own terms, and may be used for model training.

The Cyber Centre's advice applies on any plan: keep personal information and sensitive corporate data out of prompts, and check whether users can delete their prompt history. For staff, the rule is short: work text goes into the work tool, signed in with the work account. For AI assistants built into glasses, see AI smart glasses and privacy.

Fix permissions before you switch on Copilot or Gemini

Workplace assistants do not bypass permissions; they inherit them. Microsoft states that Copilot only surfaces organizational data the user can at least view, and Gmail's Help me write pulls details from the user's own emails and Drive files. That is reassuring until you count the files shared with the whole organization, or with anyone who has the link. A drafting assistant can turn an old oversharing mistake into a sentence in someone's email.

A laptop drafts an email through an assistant that reaches into a row of shared folders. Three folders are locked; one open orange folder sends a page into the draft.
Fig. 2 An assistant drafts from everything the user can open, so a folder shared too widely can end up in an email.

Before rollout, review sharing and external access in Microsoft 365 or Google Workspace, and use sensitivity labels where you have them: Copilot honours the usage rights of files encrypted with Microsoft Purview. Tightening sharing and external access policies is part of our IT support service.

Never let a tool that reads incoming mail also send

Prompt injection is LLM01, the first entry in OWASP's 2025 Top 10 for LLM applications. In its indirect form, instructions hidden in content the model reads, such as a web page, a file or an email, change what the model does. An assistant that drafts replies to incoming mail reads text written by strangers, by design. If it can also send, or reach files to attach or quote, a crafted email can steer it.

An email from the internet carries one hidden orange line into an assistant linked to a folder of documents. The reply it writes stops at a closed barrier gate beside an unpressed check-mark button.
Fig. 3 Incoming mail is written by strangers: let the assistant draft, and leave sending to a person.

OWASP's mitigations translate directly into drafting: give the tool the least access it needs, keep external content clearly separated from instructions, and require human approval for anything that acts. Microsoft lists blocking prompt injections among Copilot's built-in protections, but OWASP notes that retrieval and fine-tuning do not fully remove the risk, so the human approval stays.

Warning

Keep "draft" and "send" as separate permissions. The tool writes; a person reads and sends. That one rule contains most of the damage a wrong or manipulated draft can do.

Write the rules down

The Cyber Centre also recommends a written plan: how AI may be used, what content it may generate, and the oversight and review each use needs. For a small team this fits on one page:

  • the approved tools, and the accounts to use them with;
  • the data that never goes into a prompt (client personal data, credentials, anything under a confidentiality agreement);
  • the text that always needs a second reader (contracts, prices, legal, HR, anything published);
  • who to ask when a case is not covered.

How to prompt for a draft you can actually use

A drafting tool cannot ask what you meant, so the prompt has to carry it. Google's guidance for Help me write lists elements that work in any tool: who you are writing to, the subject and the action you want, the tone, and a specific email or file for the facts. In order:

  1. Name the reader and the goal. "A reply to a client who asked for a refund after the return window closed. Goal: decline, offer store credit, keep the relationship."
  2. Give the facts. Paste the dates, amounts and names, or point the tool at the file that holds them (/ in Word, Sources in Gmail and Docs).
  3. Set the form. Length, tone and format: "three short paragraphs, plain English, no bullet points".
  4. Say what to leave out. "Do not promise a date. Do not mention discounts."
  5. Refine instead of restarting. Ask for one change at a time: shorter, more formal, the offer in the first paragraph.
  6. Check, then rewrite the edges. Verify every fact, then rewrite the first and last lines yourself. That is where a reader decides whether a person wrote to them.

A prompt built that way looks like this:

Write a reply to the email below from our client's finance lead.
Goal: confirm we received the invoice query, say a corrected invoice
will follow once our accounts team has checked the hours, and ask
whether the PO number on the original invoice is still valid.
Tone: friendly, professional, brief. Under 120 words.
Do not give a date. Do not mention discounts.

Publishing AI drafts on your website

Google set out its position in February 2023: appropriate use of AI or automation is not against its guidelines. Its current documentation says generative AI can be useful for researching a topic and structuring original content. What Google acts on is scaled content abuse: many pages generated mainly to manipulate rankings without adding value for users, however they were made. The old promise that AI lets you publish more pages and so rank higher describes that pattern exactly. Our guide to AI-generated content in SEO covers Google's policies and how to publish AI-assisted pages without a penalty.

So an AI draft is where a web page starts, not where it ends. Add what only you know (your prices, your process, your experience with the problem), check the facts and the metadata, such as titles and meta descriptions, and consider telling readers how automation was used where that helps them, as Google suggests.

Do not lean on AI detectors to police any of this, for your own team's work or anyone else's. A study published in the journal Patterns found that widely used GPT detectors consistently misclassified writing by non-native English speakers as AI-generated, while simple prompting let AI text slip past them. Accuracy and usefulness are what you can check.

Choosing an AI drafting tool for your team

Often the right tool is one you already license. Whichever you consider, ask the same questions:

QuestionWhy it matters
Does it run under our work accounts, with admin controls?Personal accounts sit outside your policies and may train on your text
Is our data excluded from model training, in the contract?Terms differ by provider and by plan
What can it read?It drafts from everything it can reach
Can it send, post or change anything by itself?Drafting and sending should be separate permissions
Does it show which sources it used?You can only check what you can trace
Where are prompts processed and kept, and can users delete them?Data residency and retention rules still apply to prompts

Built-in features cover general drafting. When drafting needs to be part of a process, such as replies written from your own knowledge base or incoming documents turned into records, our AI and automation service builds it with answers grounded in approved sources and a person approving anything that changes your systems.