Claude can now be given meaningful control over a Gmail inbox, according to Engadget, including the ability to send, reply to and forward emails on a user’s behalf. The key caveat is permission: Engadget says Claude can take those actions without a separate approval step if the user allows it, while also noting that the safer default is an “ask before sending” behavior. That moves the AI-assistant risk from drafting into execution. A model that summarizes or proposes text is one thing; a model that can send a message, forward an email or move mail around the inbox is operating closer to an agent with real account privileges. Engadget’s report focuses on risks that can arise when inbox access is paired with actions such as sending, forwarding, trashing or archiving messages. The most direct risk is ordinary model failure. Engadget points to cases where Claude could hallucinate false information, misunderstand a user’s request or send a message before the user has reviewed it. If approval is not required, the recipient may see the mistake before the sender does. The more security-specific risk is prompt injection. Engadget describes a scenario in which an attacker sends an email containing hidden instructions — for example, text formatted so the human recipient does not see it — that Claude can still read. If the assistant treats those hidden instructions as valid, the attacker may be able to steer what it does inside the inbox. Engadget says this class of attack is not merely hypothetical and notes that Claude warns users about prompt injection when they first allow it to send emails. The outlet also says the risks could include attempts to monitor Gmail or extract information such as verification codes. Those are reported risk scenarios in the provided item, not independently corroborated here. The limits matter too. Engadget reports that Claude cannot permanently delete email, but it can trash or archive messages. That boundary reduces one form of damage, but it does not remove the operational risk of misfiling, forwarding or sending sensitive messages. The practical mitigation in the report is straightforward: keep approval turned on. Engadget says users should leave the default ask-before-sending behavior active so they can review messages before Claude sends them. For anyone using AI inside a live inbox, that human checkpoint is the difference between drafting assistance and delegated action. Who benefits: Users who keep approval enabled may get faster drafting and inbox handling while retaining final control. Who's exposed: Users who allow Claude to send messages without review are more exposed to mistaken sends, misunderstood instructions and prompt-injection attempts.