Product Launch2 min read

Anthropic's Claude Can Now Send Emails From Your Gmail

By , Senior AI ConsultantPublished

Anthropic added a free Gmail connector that lets its Claude AI read, draft, send and forward emails on your behalf, a step further than rivals ChatGPT and Gemini have taken and one that opens a real door for scammers to hijack your inbox through hidden instructions in incoming mail.

Anthropic has plugged its Claude AI directly into Gmail. Once connected, you can ask it in plain language to find an email, draft a reply, send something, forward a message, or clean up your labels, and it does the work without any special commands.

What stands out is who gets it. The connector works on every Claude plan, including the free one. Compare that to ChatGPT, whose Gmail connector is restricted to paying subscribers and, even then, cannot send, delete or file emails on its own; it can only draft. Google's Gemini inside Gmail is even more limited: it writes drafts but will not press send for you. Anthropic is the first of the big three to give away full read, write and send access at no cost.

That generosity comes from confidence in its approval system. By default, Claude asks before it sends, replies to, or forwards anything, and reading your inbox happens automatically in the background. You can adjust each action separately: always allow reading, require approval for writing, or block certain actions entirely. Companies running Team or Enterprise plans get a switch to control this for their whole organization, so an employee cannot quietly turn on full autopilot without approval from whoever manages the account.

The real question for any business owner is not whether the tool works, it is what happens when someone tries to break it. An email inbox is close to the worst possible place to hand an AI free rein, because every incoming message is content from someone you do not control. Security researchers have a name for this setup: an AI system that can read private information, take in outside content it cannot verify, and then act on the outside world, like sending an email, checks every box needed for it to be tricked. Attackers can hide invisible instructions inside a message, using white text on a white background, and the AI reads them even though a human never would.

This is not a theoretical worry. A separate AI agent recently deleted more than two hundred emails from the inbox of a Meta safety researcher after ignoring her explicit instruction to wait for approval before acting, a case that has been widely cited as a warning about how fragile these approval systems still are in practice.

There is also a plain financial angle here that has nothing to do with hacking. Business email compromise, where someone tricks a company into wiring money or sharing sensitive data through a fake but convincing email, already cost companies more than two billion dollars in a single year according to the FBI. Handing more of the reading and replying to an AI does not remove that risk, it just moves the point of failure from a tired employee to a system that can be fooled in different, less obvious ways.

None of this means the tool is not useful. For a small business owner drowning in client emails, or a back office team buried in scheduling and follow ups, letting an AI draft replies and sort the inbox saves real time. The sensible approach is to keep the send and delete switches on approval mode, be specific rather than vague when giving instructions, and treat anything unusual coming from an unfamiliar sender with suspicion before letting the AI near it.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable