I estimate that I receive 5 to 10 emails a day that appear to have been both written and sent by AI agents running in an automated setup, often from Gmail addresses. They ask me to respond, without a link to click. They do not look like the obvious spam we have learned to ignore. Someone seems to want a conversation.
My impression is that an agent is handling the outreach itself, composing and sending messages to start a conversation. I cannot verify the automation or identify the service behind any individual email. A Gmail address alone is no reason to distrust a sender. What concerns me is how much attention it takes to decide which approaches deserve a response.
This is why I think email as we know it is losing its usefulness as a starting point for human trust. A convincing message increasingly tells us little about the effort, intention or authority behind it. Norwegian leaders need to decide which requests an inbox may deliver, and which actions require stronger verification.
A conversation can be the first step in a scam
A message does not need a dangerous attachment to lead to a bad decision. A reply can establish contact; the request for information, money or a change of channel can come later. Ordinary sales outreach, unwanted automation and fraud can all begin with a plausible introduction. They should not be treated as the same thing, but the opening message may not give the recipient enough evidence to distinguish them.
The FBI’s December 2024 warning on generative AI and fraud describes criminals producing convincing messages more quickly and correcting language errors that previously helped expose them. Good grammar is a weak reason to trust someone.
There is also a serious argument against declaring email finished: its defenses keep improving. In May 2026, Google reported that Gmail blocks more than 99.9% of spam, phishing and malware. That is Google’s own effectiveness claim, not an independent measurement of my inbox. Filters are valuable, but deciding whether an apparently ordinary conversation is worth entering remains a different problem.
Quick explanation
What are OpenAI Dots and Grok Bot?
OpenAI Dots and Grok Bot are AI agents with a computer in the cloud, equipped with a browser, files and software. They can continue work while your laptop is closed. A dot has its own cloud computer; Grok bots on the same account share one. Access to company systems still requires authorized connections and permissions.
These are examples of legitimate delegated work. I have no evidence that either product sent the unsolicited emails I receive.
Read the explainer: what Dots and Grok Bot are and how their cloud computers work.
We may read less email while machines send more
My expectation is that agents will take over more of the sorting, preparation and coordination around messages. A manager may review a short list of decisions instead of reading every exchange. Where companies connect their systems, some coordination could move into shared tasks or structured requests between agents.
Email could remain underneath that experience. An agent may still need it to reach a small supplier, a new customer or an organization using different software. It could even generate more traffic while people spend less time in the inbox. The arrival of Dots and Grok Bot does not establish that email volumes are falling.
There is a plausible failure case, too: one company automates its outreach, another automates its replies, and both create more activity without moving a useful decision forward. For a small Norwegian management team, the test should be less time wasted and fewer missed customer requests, not more messages handled.
What does a verified human actually prove?
I expect verification to become more important as it gets harder to judge who is behind a message. But several questions need separate answers: Is there a real person behind the account? Is it the person claimed? Do they represent this company? Did they authorize this particular action?
A research paper on personhood credentials, first published in 2024, explores ways to prove that a user is human without revealing their identity to every service. The proposal does not require a biometric system. It is research into a possible approach, not a universal verification service already in place.
Even a reliable proof of personhood would not establish that a message was written by hand, that its sender is honest, or that they can approve a supplier’s new bank account. A human can authorize an agent to write. A real person can commit fraud. An otherwise legitimate account can be compromised.
I would therefore resist a blanket demand for identity documents before anyone can contact a business. Verification should match the consequence of the request. Customers making a basic inquiry need an accessible route in; whistleblowers may need anonymity. Neither should have to surrender unnecessary personal information to get past a filter.
A better system should make authority visible
The opportunity for a new communication solution is to make a request easier to assess before anyone acts on it. Moving the same uncertain conversation into another chat app will not achieve that on its own.
I would want business communication to carry four things that both a person and an agent can inspect:
- A verifiable sender and represented organization. Show who is making the request and the evidence for the relationship they claim.
- A specific request. Make clear whether this is an introduction, a proposed order, a data request or a payment change.
- Limited, revocable delegation. If an agent acts for someone, show what it may do, for how long and how that authority can be withdrawn.
- Approval tied to the actual action. A consequential decision should identify the recipient, amount, data or change being approved, with a record that can be checked later.
There are building blocks for this. The W3C Verifiable Credentials standard describes digitally verifiable claims. It also explicitly separates verification from the truth of a claim. A credential is useful only within a process that decides which issuers and claims to trust.
My proposal goes beyond a credential format. It needs practical recovery when an account is taken over, limits on unsolicited contact, and a way to challenge a mistaken rejection. It should work across providers and preserve contact routes for people without the newest app. Otherwise, we risk exchanging an overloaded inbox for another platform dependency.
A Norwegian supplier request shows the difference
Consider a hypothetical Norwegian service company receiving an email about a supplier’s new bank account. Its agent recognizes the company name, finds a matching invoice and prepares the change. The message could be entirely ordinary. It could also come from a compromised account.
In the process I recommend, that email can open a case and help prepare the evidence. It cannot authorize the bank-detail change. A responsible employee checks through an established supplier contact or an approved supplier portal, using contact information already held independently of the incoming message. The company’s payment approval rules still apply.
This principle predates AI. NorSIS’s 2021 guidance on director and invoice fraud recommends checking account changes through another channel and avoiding the telephone number supplied in the email. AI makes it especially important to build that rule into the workflow, so an automated assistant cannot skip it in the name of efficiency.
A familiar-sounding voice should not override those controls either. The FBI warning also covers synthetic audio and video. Verification needs an established process and evidence appropriate to the decision.
What leaders and boards should change now
Management can start with one shared inbox and define what its messages may trigger. Let an agent classify requests or prepare answers within approved data boundaries. Keep changes to payment details, access rights and sensitive disclosures behind explicit controls. Treat incoming text as information to assess, including when it tells the agent to ignore its rules.
For a small business, an external IT provider can help implement the controls, while a named person in the company owns the workflow. Measure time saved, legitimate requests wrongly rejected, mistakes in replies and attempts to cross an approval boundary. Test Norwegian wording and local customer situations. A filter that saves time by excluding real customers is an expensive success.
The board’s role is to ask management where a convincing message could become an unauthorized action, what prevents it and what evidence shows the controls work. It should also ask about the cost of keeping all sorting and follow-up manual. Delayed replies, missed inquiries and time spent on repetitive checking are business consequences worth measuring alongside security incidents.
I would not make replacing email the objective. I would make trustworthy delegation the objective. The useful next generation of communication will let people and their agents exchange requests with clear limits, while keeping consequential decisions traceable to someone accountable.
For the next implementation decision, read about what Norwegian companies can allow AI agents to do and how boards can set limits on AI autonomy.
Product capabilities and regional availability checked on 11 October 2026. Predictions and proposed controls are my analysis; the inbox estimate is my personal observation.

