Comserv Connect
← Back to Blog
AI

Before You Let AI Read Your Email: The Questions Nobody Asks First

By Comserv Connect TeamReviewed by Chris Ferrera

Almost none of our clients have asked us about AI browsers. Most of them will end up with one anyway.

That is not a criticism of anybody. These assistants are being built directly into the browsers people already have open, so this is arriving as an update rather than as a decision somebody makes. You do not go shopping for it. One day it is there, offering to read your inbox for you.

Which is why it is worth understanding now instead of after, because researchers have spent this year demonstrating that those assistants can be given orders by the content they read.

The Thing Being Sold, and the Thing Being Bought

An AI assistant in the browser is sold as time saved. Catch me up on my inbox. Book that meeting. Pull the numbers out of this document. All of that is genuinely useful, and we are not going to pretend otherwise.

What you are actually granting is different from what is being advertised. You are installing a piece of software that acts using your logins, at your permission level, on content that strangers can send you. Your assistant reads your mail with your access. It reads your calendar with your access. And anyone in the world can put an item into both of those simply by emailing you.

That combination is the whole story.

What the Researchers Showed, in Plain English

Researchers at Zenity Labs documented a class of attacks against AI browsers and browser agents, published through the Cloud Security Alliance's AI Safety Initiative in the spring and expanded with new demonstrations at a security conference this month. The products they looked at are the mainstream ones: Perplexity's Comet, OpenAI's Atlas and Deep Research, Google's Gemini in the browser, and other agentic browsers.

The mechanism is easier to follow than it sounds. Malicious instructions are hidden inside ordinary content. An email. A calendar invite. A document. A fragment of a web address. You then ask your assistant to do something perfectly normal, like summarizing what came in overnight. The assistant reads that content as part of the job, cannot distinguish your instructions from the ones buried in the material, and follows both.

The Cloud Security Alliance note is blunt about what makes this different. It describes attacks requiring "no clicks, no downloads, no exploitable memory corruption, and no user awareness," and says that this approach "removes the human from this loop entirely."

The underlying problem is structural rather than a bug in any one product. In the note's words, agentic browsers "inherit the user's authenticated session and process untrusted web content without a validated boundary." The assistant is already signed in as you. It has no reliable way to tell which of the words in front of it came from you and which came from an attacker.

Why Your Existing Training Does Not Cover This

Every security awareness lesson your team has ever sat through ends the same way. Look at the sender. Hover over the link. Do not open the attachment. So do not click it.

Nobody clicked.

That is worth saying flatly rather than dressing it up. The advice your staff has been trained on assumes a human being makes a decision at some point in the chain. In this scenario there is no such moment. The message arrives, the assistant reads it as part of a task you asked for, and it acts. Your phishing training, which may be perfectly good training, simply does not have anything to say about it.

Five Things to Check Before You Connect an AI Assistant to Anything

These follow the Cloud Security Alliance's own recommendations, translated into questions you can actually ask.

What can it reach? Mail only, or mail and calendar and files and chat? Every additional system is another channel a stranger can use to put words in front of it.

What permissions did it get, and does it need all of them? The CSA's first practical recommendation is auditing and revoking unnecessary permissions. These tools tend to request broad access at install, and in our experience that grant rarely gets reviewed again.

Does it have to ask before sending anything out? Sending mail, sharing a file, posting to a system of record. Anything that moves data outward should require a human to confirm.

Can it do anything destructive without confirmation? Deleting, archiving in bulk, changing settings, moving money. The answer should be no.

Would anyone notice if it did? Treat assistant activity as its own category in your logging and your data-loss policies, so that the record exists before you need it.

Our own position, for whatever it is worth: reading, summarizing, and pulling out what needs doing is fine. Letting a bot answer email on its own is not. Start with read access, see what it can actually do for you, then expand from there. How far you go depends a great deal on what industry you are in and what is sitting in that mailbox.

If Someone Already Turned One On

This happens more often than the tidy version of the story suggests. An office manager installs an extension, connects it to company email and the shared calendar, and mentions it three weeks later.

When we get that call, the extension is not the first thing we look at.

The first question is how a regular user was able to connect an outside application to company email without an administrator approving it. That is the actual finding. One person's enthusiasm should not be enough to grant a third party standing access to your organization's mail. Fix that, and you have fixed the entire category rather than one instance of it.

Then, in order: review what that application already had access to, and check whether it touched or sent anything while it was connected.

A Reasonable Place to Land

This is not a call to ban AI assistants. They are useful, they are improving, and pretending otherwise helps nobody. It is also not a reason to connect one to everything you own because a vendor's demo looked impressive.

Read-only and narrow beats connected and convenient, for now. Give it the smallest amount of access that still does something useful for you, make it ask before it acts on your behalf, and revisit the decision in six months when the guardrails have caught up.

If you are not sure what is already connected to your company email, that is a good place to start, and it is a short conversation. Book a free 30-minute strategy session and we will go through it with you.

Sources

  1. Cloud Security Alliance: research note on PleaseFix agentic browser exploits
  2. Dark Reading: AI browsers and zero-click agent hijacking
  3. SC Media: PleaseFix vulnerabilities expose agentic browsers

Ready to Put AI to Work?

Find the first practical automation opportunity in your business.