A language model answers with the same confidence when it knows and when it does not. That is not a defect of a particular model but a property of how they work: there is no built-in marker saying "I made this up". Every limit below follows from it.
Numbers it was not given
Prices, terms, discounts, delivery times. If the figure is not in the brief, a plausible one appears in its place, and you inherit the promise — the knowledge base.
Guarantees
"You will get results", "this always works". Nobody should say those, and a model says them readily because they sound helpful. Put them in the prohibited list explicitly.
Anything legal or financial
Contract terms, tax questions, liability. Not because the model is necessarily wrong, but because being wrong there is expensive and unfixable by apology.
Complaints
An unhappy existing customer talking to an autoresponder becomes a more unhappy customer. This goes to a person immediately, without exception — when to hand over.
Comparisons with competitors
A model asked which is better will answer, and the answer is invention presented as fact. Ban the category rather than trying to steer it.
The question about being a bot
Answer honestly. Insisting otherwise damages the deal far more than the automation itself ever could — and people ask precisely when they already suspect.
What it does well
The routine and the immediate: a first reply that holds the conversation open, standard questions, collecting the facts a person will need. That is most of the volume and none of the risk — DM automation and why enquiries get lost.
How Neurogram does this
Everything above is manual work that runs into the number of hours in a day. Neurogram does it on your own accounts and without you: it collects channels and audiences, writes comments and replies with a language model, and keeps limits and quiet hours so the accounts survive. See pricing or look at your case.