How can an AI agent be steered by an email?
An agent reading an inbox is supposed to treat a message as information to analyze, not as a new instruction from the account owner. A malicious sender can place instructions inside a message or web page that the agent will read. If the agent follows those instructions instead of its authorized task, the boundary between untrusted content and trusted commands has failed. This is commonly called prompt injection. The possibility matters most when the agent has permission to take actions or access private material.
Why do connected permissions matter?
An assistant that only suggests a calendar change has a different risk profile from one allowed to change the calendar itself. Inbox access can reveal private messages, and permissions for files, work apps or financial accounts can open more consequential paths. The National’s October 4, 2026 report by Alvin R Cabral highlights the value of asking what access an agent actually needs for a task. Keeping permissions narrow reduces the damage that a mistake or malicious instruction might cause. It does not eliminate the need for safeguards from the companies building and deploying these tools.
Practical questions before connecting an AI assistant
- Which accounts, folders and actions will the agent be allowed to use?
- Can it make a consequential change without a human reviewing it first?
- Can you see a record of what it read and did?
- How do you revoke access when the task is over?
Review connected apps regularly, remove permissions you no longer need, and use multifactor authentication on important accounts. For higher-impact actions, keep a person in the approval loop. These are general precautions, not a claim that any particular user’s accounts have been compromised.
Source: Alvin R Cabral, The National, October 4, 2026, “AI ‘less safe’ for keeping secrets than most people assume.”
