Skip to content
GEERD
← All insights

Admissions

What an AI agent may tell a family, and what it must refuse

A clumsy reply can be recovered. A commitment made in the school’s name is either honoured or paid for. That difference, not the quality of the prose, is what should decide whether you let a machine reply.

7 min readBy the GEERD team

It is 10.40 pm. A parent writes to the school’s WhatsApp: “Good evening, my daughter is in her final year, does she have a chance of getting in?” The question is ordinary. It is also, for a machine, one of the most dangerous there is: it asks for a prediction about a person.

When people assess a conversational agent they usually look at whether it replies fast and writes correctly. Those are the two easiest things to get and the least important. What actually decides is the perimeter: what the agent may assert, what it may promise, and what it does when the answer is not in what it was given.

Four sentences that cost you

None of them is aggressive. All four come naturally out of a model tuned to be helpful, which is exactly why they have to be forbidden explicitly.

“With that record, it’s a formality.”

An admission forecast. It does not only bind the committee: it gives a family a reason to stop looking elsewhere. On the day of the refusal it is no longer a decision, it is a word taken back.

“Your daughter has a very strong profile.”

A judgement about a person, delivered by a machine that has read neither the file nor the committee’s rules. Flattering as it is, it creates an expectation, and puts you in the position of explaining later why the “strong profile” was turned down.

“Let me see what I can do about the fees.”

A negotiation. An agent has no business arranging a rate for one applicant: either the discount is published and it states it with its conditions, or it does not exist and there is nothing to offer.

“Only a few places left, don’t wait.”

Pressure. If the figure is true it comes from your data and it is yours to decide to state. If it is produced by a model that learned urgency converts, you have put a pushy salesman on the school’s number.

The line to hold: information is not a commitment

It is the most useful distinction, and the one a supplier should be able to show you in writing. An over-restricted agent is useless; an agent that cannot make this distinction is a liability.

It may say thisIt may not
Fees“Tuition for the programme is the amount in the current fee schedule, payable in three instalments.”“I’m sure we can come to an arrangement on the amount.”
A discount“A 10% discount applies to enrolments before 15 July.”“I’ll give you the discount even if you enrol later.”
Entry requirements“The programme requires a science baccalaureate; you told me she has one, so the requirement is met.”“With a science baccalaureate, she’ll get in.”
What happens next“The committee meets in May; you will get the answer by email.”“I’ll put your file at the top of the pile.”

What must happen when it does not know

That is the real test, and it has nothing to do with the model’s performance. A family asks something nobody anticipated: “can the deposit be paid in three parts?” The answer is written nowhere.

A decent agent does three things, in this order. It does not answer. It says so plainly, without justifying itself or inventing a plausible procedure. And it hands over to a person, saying what was missing, so the question gets handled once, then added to the facts, so that next time it can answer.

That third point is what separates a tool from a project. Every hand-over is an identified gap in what the school has written about itself. After a few weeks, the list of questions the agent could not handle is the most useful document the whole installation produces, often more useful than the successful replies.

What you should be able to read back, six months later

An AI conversation you cannot read back is one you will not be able to defend: to an unhappy family, to your board, or to an authority that asks.

  • What the family wrote and what the agent replied, word for word, with the time.
  • Which facts the reply rested on, and in which version of your own text.
  • The replies that were blocked before going out, and why.
  • The moments the agent handed over, and how long the team took to pick up.
  • What was written on the applicant’s record as a result of the conversation.

How this is held at GEERD

These prohibitions are not recommendations we make to our clients: they are written into the policy of the agent we deploy, and verified on every draft before it is sent. A reply that promises an admission, judges an applicant or negotiates a price is retracted and replaced by a human message.

Agentic AI in an institution

What to take away

The right question to ask a supplier is not “does your AI reply well?” but “what is it forbidden to say, and what stops it?”. If the answer is a usage recommendation rather than a mechanism, the limit does not exist.

And keep the simplest rule of all: a machine can inform a family, prepare a decision and make it readable. It takes no decision about a person. The day someone in your institution can say “the system decided”, you have lost something you cannot buy back.

Thinking of letting an AI reply?

We start by looking at what your school has written about itself: that is an agent’s raw material, and it is usually where the work turns out to be. The diagnostic is free, and the demonstration shows the checks as much as the replies.