Harlyn
LEARN · THE ETHICS OF SPEAKING FOR SOMEONE

What should an AI say in a meeting on your behalf?

The question sounds like a product question. It is actually an ethics question, and almost nobody building in this category has answered it in public. So here is our answer, stated plainly enough to be disagreed with.

An AI speaking on your behalf should say three kinds of things and refuse everything else: what you told it to say, what your own systems establish as fact, and the honest admission that a question belongs to you. That is the entire license. Everything interesting about building a meeting delegate follows from taking that license seriously.

Why the default has to be silence

When a chatbot guesses wrong, a user gets a bad answer and knows who to blame: the bot. When an AI speaking as your representative guesses wrong, the room hears you. A wrong figure becomes your wrong figure. An improvised opinion becomes your position. A casual "that should be fine" becomes a commitment your client remembers and you never made.

This asymmetry means a delegate cannot be built the way assistants are usually built, where helpfulness is the prime directive and the model reaches for the best available answer. A delegate needs the opposite disposition: a short allowlist of what it may assert, and a default of deferral for everything outside it. Not "answer unless risky." Defer unless authorized.

We call this the conservative delegate posture, and in practice it means the AI in the room is frequently saying some version of "that one is for Nick, let me get it to him." Which sounds like a limitation until you watch it happen in a live meeting, where it reads as something else entirely: discipline. The delegate that declines to speculate about next quarter is the same delegate whose CRM numbers you can trust, and attendees grasp that connection immediately.

The three things it may say

What you briefed it to say. Your update, your questions, your stated positions on the agenda. This is the delegate as messenger, and the bar is fidelity: your words, your framing, delivered at the right moment rather than read into a void. A briefing should also separate what is speakable from what is context. Harlyn's briefings have an explicit internal section, material the delegate uses to understand the meeting but never volunteers, because a delegate that cannot keep background as background will eventually negotiate against you with your own information.

What your systems say. Facts from your connected tools, spoken because someone asked: where the renewal stands, what was promised last month, when the contract went out. This is where a delegate earns its seat, answering in about a second from the CRM instead of generating a follow-up email. But notice the boundary: the tool answer is a fact lookup, not an interpretation. "The deal shows Contract Sent, $50K, closing mid-July" is delegate territory. "I think it will close" is not, because you did not think it aloud and the delegate should not think it for you.

That it does not know, and who does. The most important sentence in the delegate's vocabulary is the deferral. Done badly, deferral is a dead end: "I can't answer that" and the question dies in the room. Done well, it is a handoff: the delegate says whose question it is, sends it to that person immediately, and if the answer comes back while the meeting is still running, speaks it into the room with attribution. "Nick just got back to me on that" turns an absence into a nine-second delay. And when no answer comes in time, the question arrives in the owner's recap, so deferral never silently loses anything.

The two things it must never do

Commit you. Agreement is the most dangerous speech act in a meeting because it is cheap to say and expensive to unwind. A delegate should treat every request for commitment, budget, timeline, scope, a simple "can you have it by Friday?", as automatically out of scope unless you explicitly pre-authorized that exact commitment in the briefing. The safe sentence exists and it costs nothing: "I'll take that to Nick and you'll have an answer today."

Perform being you. A delegate represents you; it should never impersonate you. It appears under its own name with your name attached, discloses that it is an AI before it first speaks, and never adopts the first person as if it were you dialing in from a bad connection. The goal is a room that knows exactly what it is talking to and relaxes because of that, not despite it.

Restraint is a feature you can ship

It would be easy to read all this as philosophy. It is actually architecture. Defer-by-default has to be enforced in the system, not requested in a prompt: the briefing defines the allowlist, tool calls are the only path to factual claims, writes to any system are staged and require an explicit yes, and the deferral path has to be a first-class feature with its own plumbing back to the owner, or the model will helpfully fill the silence.

The uncomfortable truth about this category is that the market will reward confident delegates before it learns to fear them. A stand-in that smoothly answers everything demos better than one that says "that's for Nick" three times in a meeting. But the second one is the only one you can send to a client. Ask any vendor in this space one question: what does your product refuse to say, and how is that refusal enforced? The answer tells you whether they have thought about whose voice is on the line.

It is your voice. The AI should treat it that way.

KEEP READING
LEARN · THE APPROVAL GATE
AI meeting agents that ask before they act: the case for the approval gate
LEARN · HOW-TO
How to send an AI to a meeting on your behalf: Zoom, Microsoft Teams, and Google Meet
LEARN · CATEGORY MAP
AI note taker, AI worker, or AI delegate: what actually shows up to your meeting
See a delegate handle a real meeting.
Harlyn is in private beta, free while we build with early users. Every claim on this page is shipped behavior.
Request beta access Talk to Harlyn live
© 2026 Harlyn · in the room, even when you're not.
Trust Privacy Terms