Show summary Hide summary
Allowing an AI assistant to send email on your behalf brings two distinct hazards: covert hijacking through hidden instructions and accidental outbound messages sent without your review. Both expose users to privacy breaches and operational errors when the assistant acts directly on inbox content.
How attackers can hide commands inside messages
Security researchers describe a technique called prompt injection, where an attacker embeds instructions into an email so the assistant reads them but a human recipient does not. In one simple variant the malicious text is effectively invisible — white-on-white or set to zero font size — so it never appears in the message you see but remains machine-readable.
Ultra-thin women smoking cigarettes are making a comeback as a fashion trend
Windows Memory Diagnostic explained: what the test does and how to read results

That covert content can instruct the assistant to forward or extract data. According to reporting about the tool, attackers could use it to monitor Gmail and siphon sensitive items such as verification codes needed to access other accounts. The threat is not hypothetical: the company behind Claude notes the risk and warns users when they first enable outbound email functionality.
The danger of letting the AI send mail automatically
Beyond deliberate attacks, the assistant’s convenience poses an operational risk. When you ask it to send a message, it may draft and transmit the email automatically unless you enable a setting that pauses for review.

That workflow increases the chance that recipients will receive flawed messages. Errors can stem from the assistant hallucinating facts, misunderstanding a user’s intent, or simply making formatting mistakes — and you may not see those errors until after the message has gone.
Practical consequences for users
Granting send-on-your-behalf privileges concentrates trust and data with the AI provider. That raises two interlinked concerns: exposure of private inbox content and the operational risk of unintended or manipulated outgoing messages.
- Account takeover risk: Hidden instructions can be used to harvest verification data.
- Unreviewed mistakes: Automatic sending can put errors in front of contacts before you can correct them.
- Privacy exposure: Allowing the assistant to read and act on email centralizes sensitive information.












