Harry Stebbings predicts inbox-level AI access will feel normal within five years
Granting an AI model access to your inbox and trusting it to decide what colleagues should see sounds reckless today. Harry Stebbings is betting that discomfort is temporary, and the reasoning behind the call is worth examining closely.
Letting an AI model read your inbox and decide what colleagues should see sounds reckless to most people working in enterprise software today. Harry Stebbings, the venture investor, is betting the discomfort is temporary. His call: within five years, employees will be materially more comfortable granting that kind of access, because the models will have earned it by demonstrating real judgment about what not to share.
Stebbings concedes the starting point directly. “Right now, that seems insane,” he says. The bet is not that the concern is wrong, but that the technology will close the gap between what people worry about and what the models actually do.
That gap is not small. An AI assistant with inbox-level access is also, by definition, an assistant with access to personnel matters, client details, and internal deliberations that belong to different people with different interests. The question Stebbings is really answering is not whether LLMs will be permitted into those spaces, but whether they will develop reliable enough judgment to be trusted there: to hold information appropriately rather than surface it indiscriminately.
And right now, that seems insane. You ask me what I think in 5 years. I think we will be more okay with that because in practice, the LMS will be really good at respecting privacy around things that you don't want to share. Harry Stebbings
The distinction matters because knowing a privacy rule and following it under operational pressure are different problems. A model can correctly identify what is sensitive and still surface it when executing a task. Architectural choices, permissioning schemes, and the way agents hand tasks to other agents all affect whether a model’s stated respect for privacy translates into actual behavior. None of these are solved problems.
Stebbings does not offer a mechanism for how the trust gets built, only a prediction that it will be. The mechanism matters. Trust at the level he describes, where an employee hands an AI agent the keys to an inbox and trusts it to make sharing decisions, probably requires something closer to an auditable track record than a technical guarantee. Users would need to see, repeatedly and verifiably, that the model held information it could have shared and chose not to. That is a different bar than accuracy, and the timeline for clearing it depends on how quickly that kind of track record accumulates at scale.
The optimistic reading of the current trajectory is that the field is working on the right problem. Contextual privacy, techniques for enforcing user-specific constraints, and design principles around permissioned access are active areas of development. The pessimistic reading is that each approach addresses a slice of the problem while enterprise deployments are already scaling in ways that outpace the safeguards.
The window Stebbings sets is specific enough to be checkable. Within five years of his call, either workplace AI assistants will routinely operate with inbox-level access and a demonstrated record of contextual judgment, or the discomfort he describes as temporary will still be shaping procurement decisions. He is not predicting a gradual shift in attitude: he is predicting that the models will earn the trust by performing well enough to make the current concern feel dated. Whether that performance materializes in the time he specifies is the open question.