What your AI should refuse to answer
An AI front desk that answers everything is a liability. Which questions it must hand to a human, why a confident wrong answer is the failure mode that matters, and how to test yours in an afternoon.
Frontiva · · 6 min read
The question people ask about an AI receptionist is "how much can it handle". The question that decides whether you can safely use one is the opposite: what does it refuse, and how does it know?
An AI that declines to answer costs you a few seconds of a staff member's time. An AI that answers a clinical question with a price list costs you something else entirely. These are not symmetrical, and any vendor who talks only about coverage is selling you the wrong end of the problem.
The failure that actually happens
It is not the AI inventing a fact from nothing. It is the AI matching a question to the wrong stored answer, and delivering it confidently.
Here is the shape of it. A knowledge base contains a service called "Botox", with a price. A patient asks: "Is Botox safe while I am breastfeeding?"
A naive matcher scores that question against the stored entry, sees the word "Botox", finds a strong match, and replies with the price. The patient asked a medical safety question and received a price quote in the practice's name.
This is not a hypothetical. It is what a simple keyword-overlap score does by construction, because a one-word entry matches any question containing that word. The shorter and more generic your stored entries, the worse it gets - which is the opposite of what anyone expects.
Two independent things have to be true to stop it, and both are worth checking separately, because either one alone rots.
The matcher has to score both ways. Matching the question against the entry is not enough; the unmatched half of the question has to cost something. "Is Botox safe while I am breastfeeding?" shares one word out of eight with an entry called "Botox", and a score that notices this refuses the match.
Something has to recognise the subject regardless of the match. Risk, adverse events and urgency need their own check that runs before any answer is attempted. A question about bleeding, swelling, an allergic reaction, chest pain or self-harm should never reach the matcher at all.
You need both because they catch different things. The scorer catches questions that are merely about a service. The guardrail catches questions that genuinely are about the named service and are still not for a machine to answer.
What must always go to a person
Write this list down and check your vendor's against it:
- Anything clinical: is this safe, is this normal, should I be worried, what does this mean
- Anything urgent: bleeding, swelling, difficulty breathing, chest pain, severe pain, fever, infection, allergic reaction, self-harm
- Anything about medication, dosage or interactions
- Anything about test or scan results
- Anything legal, including liability and complaints
- Anything where the answer commits you to a price you may not honour
- Anything the customer explicitly asked a human for
The urgency list matters most and is the one most often missing. Many products escalate on polite phrases like "can I speak to someone", which is exactly what nobody in distress types.
Refusing is only half a duty
An AI that recognises an emergency and says nothing is safe and useless. The patient is still sitting there at 22:00.
What it says instead is not an engineering decision. The exact wording of an emergency reply, the list of words that must always escalate, and where after-hours escalation actually goes are decisions for a clinician and a lawyer, together, written down once and applied per business. A vendor supplying default wording for this is supplying you a liability with a sensible tone.
Insist on two things: that the wording is yours to set, and that the product will not let you activate an AI without somewhere for an out-of-hours escalation to land. Nobody should have an AI answering patients at 2am with no human reachable.
Approval mode, and why slower is right at first
Most products can send AI replies automatically. Most should not, for the first few weeks.
Run in a mode where every reply is a draft a person sends. It is slower, and it is how the agent's early mistakes get caught in a draft rather than by a customer. You will also learn more about your own knowledge base in a fortnight of reviewing drafts than in any amount of configuration, because every wrong draft points at a missing or badly worded entry.
Urgent escalations should bypass approval in the other direction: those need to reach a human immediately, not wait in a queue for one.
Test it yourself, in an afternoon
Do not accept a vendor's demo. Write twenty messages a real customer might send, before you see the product. Include:
- Ten ordinary commercial questions. What does a cleaning cost, do you take my insurance, are you open Saturday, how long does it take, do you have parking.
- Ten you would never want answered by software. Mix obvious emergencies with the harder ones: questions that genuinely are about a service you offer, phrased as a safety question.
Run all twenty. Count two numbers: how many of the ten commercial questions were answered correctly, and how many of the ten unsafe ones got any answer at all rather than a handover.
The second number must be zero. If it is not, the product is not ready, however good the first number is. And if the first number is also low, the guardrails are simply set to refuse everything, which is safe and worthless.
This test takes an afternoon and is more informative than any demo. Frontiva's own guardrails exist because this exact probe was run against its seeded knowledge base and ten of fifteen unsafe messages came back with a price.
Disclosure
Several states have or are considering rules about whether a business must say that the thing replying is automated. Independently of the law, customers largely work it out, and the ones who feel deceived are noisier than the ones who were told.
Ship a disclosure line, on by default, that you can word yourself. It costs you nothing and removes an argument you do not want to have.
The short version
Judge an AI front desk by what it refuses. Require two independent mechanisms, a scorer that makes the unmatched half of a question cost something and an urgency guardrail that runs first. Own the emergency wording, with a clinician and a lawyer. Start in approval mode. And test it with twenty messages of your own before you sign anything, because the number that matters is how many unsafe questions got an answer, and it has to be zero.