Email Is Awful. AI Can Fix It, but Only If We Protect the Inbox.
The case for privacy-first AI email classification and filtering.
· Matt Senter

I saw a post from Greg Isenberg about using AI to classify and manage email, which Pieter Levels subsequently reposted. I replied to both because this is exactly the problem I have been thinking about while building Premail.
The more I think about it, the more absurd email seems. Email may be the worst important technology we still use every day, yet we have tied an astonishing amount of our security and identity to it.
Email Is the Wild West
Email is an open pipe connecting essentially every person and automated system on Earth directly to you. Anyone who knows, guesses, buys, scrapes, or steals your address can put something in your inbox. There is effectively no admission control.
We have spent decades layering spam filters, reputation systems, blocklists, authentication standards, phishing detection, unsubscribe mechanisms, security scanners, and increasingly elaborate heuristics on top of a protocol whose fundamental premise remains: someone knows your address, therefore they can send you something. Every new defense tries to tame the same underlying chaos, but the chaos is part of the design.
Somehow, we also decided to make this thing the foundation of our digital identity. Email is insecure, noisy, adversarial, and open to nearly everyone, but it is also where we send the keys to everything else.
We Probably Should Not Be Using Email for This
Think about what is tied to your email address: your bank, employer, healthcare, children's schools, Apple account, Microsoft account, Google account, password resets, two-factor authentication, receipts, taxes, cloud infrastructure, domain registrar, credit cards, and legal documents. Lose control of your email account and the consequences can cascade through your entire digital life.
At the same time, that incredibly important channel is full of absolute garbage. Marketing campaigns, automated notifications, newsletters you do not remember subscribing to, fake invoices, LinkedIn updates, cold pitches, shipping notifications, calendar noise, product announcements, political fundraising, receipts, phishing attempts, promotions, and endless messages that are just circling back all compete for attention.
Buried somewhere inside all of that might be an email from your kid's school saying pickup is changing today, an alert that someone logged into your bank account, or a message from a customer willing to pay you $50,000. We have created a communications system where perhaps 0.1% of the incoming information can be critically important while 99.99% feels like bullshit, and every message competes for exactly the same rectangle on your screen.
Humans Are Bad Email Filters
The traditional solution has been folders, rules, labels, spam filters, VIP lists, and the most powerful email-management technique of all: giving up. Rules work when the world is deterministic, such as moving every message from a known receipt address into a Receipts folder. Human communication is not deterministic.
An email from someone you have never heard of could be spam, or it could be the most important message you receive all month. A newsletter you normally ignore might contain something directly relevant to a project today. A routine notification from your bank might be meaningless 99 times and critically important the hundredth.
Context matters, and that is precisely what large language models are remarkably good at understanding. An AI classifier can potentially look at an email and ask questions that traditional filters cannot:
- Is this actually important to this person, and does it require action?
- Is there a deadline, a question, or a security risk?
- Does this relate to something the recipient is working on now?
- Is this automated marketing disguised as personal correspondence?
- Has this person been waiting for this message?
- Can this safely disappear without interrupting the user?
That is a much more interesting inbox than Primary, Promotions, and Spam. It is also the first plausible way to handle email based on what a message means rather than where it came from or which keywords it contains.
But There Is a Giant Privacy Problem
Your inbox may be one of the most sensitive collections of information you possess. It is a running historical database of your life, and enough email can reveal your relationships, finances, purchases, employers, travel, medical appointments, legal problems, family members, subscriptions, projects, and daily routines.
The naive architecture for an AI email product is horrifyingly simple:
- Connect your Gmail or Microsoft account.
- Upload your email to somebody else's servers.
- Send the contents to somebody else's AI model.
- Trust everybody involved forever.
That may produce an excellent inbox, but it also creates an enormous new privacy surface. There is something particularly backwards about improving email security and productivity by making copies of your email available to even more systems.
The functionality AI makes possible is dramatically better than what came before it. The privacy implications are dramatically larger too, and they cannot be treated as an implementation detail.
AI Email Should Be Privacy-First
This is one of the reasons I built Premail. I believe AI belongs in email, and I think email may eventually become almost unusable without it. I do not think the default architecture should be sending your entire digital life to another SaaS company.
Premail is built around a different assumption: the user should control where the intelligence runs. It is BYOK, or bring your own key, so you can choose the models you want to use. More importantly, you can run local models through Ollama so email classification and analysis can happen on hardware you control rather than shipping every message to a third-party AI provider.
That opens the door to much more aggressive AI filtering because the privacy equation changes. Instead of merely asking whether something is spam, your email client can begin understanding the inbox on your behalf and separating messages that deserve your attention from messages that merely arrived. Those are very different things.
The Inbox Should Become a Decision Engine
I do not really want a better list of email. I want less email, and more precisely, I want software to absorb the parts of email that never required a human in the first place. My ideal inbox eventually looks less like a chronological database and more like a decision engine that says: these three things need you.
Everything else has already been classified, summarized, routed, archived, scheduled, recorded, or discarded according to rules I control. That could mean:
- An order confirmation is extracted and retained without reaching the inbox.
- An obvious marketing message is classified and archived without consuming attention.
- A school email about a dismissal-time change is elevated immediately.
- A suspicious password-reset message receives a security warning.
- Three questions hidden in a 14-paragraph message are presented directly.
- Routine correspondence receives a suggested response or, with permission, is handled automatically.
The important distinction is that I should decide how much authority the system has and where my data goes. An intelligent inbox that requires surrendering control of the inbox is not a good bargain.
The Incentives Are Backwards
Gmail and Outlook are obviously capable of building much more sophisticated AI email classification. They have direct access to the inbox, enormous engineering teams, powerful AI models, and distribution that Premail could never hope to match. So the interesting question is not whether they can build this. It is whether they are incentivized to take it as far as I want to.
Most software businesses are built around engagement: more sessions, more time in the product, more features pulling you back in, and more reasons to remain inside the ecosystem. Premail's goal is the opposite. I do not want you spending more time in Premail. I want you spending less time dealing with email.
That means my incentives are fundamentally different from theirs. It is not necessarily in the best interest of a traditional email provider to give you a perfectly clean inbox that demands almost none of your attention. If the product becomes invisible because it quietly handles everything for you, traditional engagement metrics go down.
For Premail, that is success. If 200 messages arrive and Premail can safely classify, archive, summarize, route, or otherwise handle 197 of them without bothering you, that is better than presenting you with a beautifully organized list of 200 messages.
The useful metric is not how much time you spent in the app. It is how much attention the app gave back to you. You could imagine measuring success in questions like:
- How many emails did you never have to read?
- How many notifications never needed to interrupt you?
- How many routine decisions were made automatically?
- How many times did you have to open your inbox today?
The ultimate metric is even more aggressive: How much email can we eliminate entirely?
That is where Premail diverges from the traditional email client. I am not trying to build the inbox people want to live in. I am trying to build the thing that lets them leave it.
Premail Is Not the End State
I do not believe email is permanent. Premail exists because email is what we have today, and what we have today is a complete ruin. It is insecure, noisy, adversarial, overloaded with responsibilities it was never designed to carry, and deeply embedded in nearly every part of our digital lives.
Premail is a practical response to the current reality, and it is the first step in a much longer plan. The immediate goal is to make email survivable: classify it intelligently, protect privacy, reduce noise, surface what matters, automate what does not, and give the user far more control over how messages are processed.
But the long-term goal is not to perfect the inbox. It is to make the inbox unnecessary. I want software agents to communicate directly, and I want identity, authentication, notifications, receipts, support requests, business workflows, and person-to-person communication to move toward systems that are structured, permissioned, contextual, and designed for machines and humans working together.
I want to eliminate the absurd model where anyone who discovers a string of characters containing an @symbol earns the right to demand your attention. Premail is how I deal with email while email still exists.
My master plan is to destroy email forever.
And I mean that as a product goal.