The same way you trust a new employee with clients: not by assuming they'll never err, but by putting controls around the work. Four controls do most of it.
First, draft-first operation: the AI prepares the email, quote, or invoice, and a person reviews and sends — a mistake caught in a draft costs minutes, not a client. Second, real approval gates: for consequential actions — anything touching clients or money — the run should genuinely stop until a named person decides. A notification after the fact is not an approval; a real gate pauses the work and waits.
Third, hard scope limits: some actions should be off-limits to automation entirely, starting with moving money unattended, and approvals should respect roles, so a junior teammate drafts and a manager signs off. Fourth, an audit record: a timestamped log of what was proposed, who approved it, and when, kept so it can't be quietly edited afterward — the answer to the question an accountant or a dispute will eventually ask.
Beyond the four, match autonomy to consequence: let AI run routine, reversible steps on its own, keep client-facing and financial steps gated, and loosen deliberately as a track record accumulates. When evaluating tools, ask whether the run actually stops for approval, whether reviewers can edit drafts, whether autonomy is settable per action, whether failures fail closed, and what record survives.
Used this way, AI doesn't need your trust — the controls catch its mistakes before a client ever sees them.