Why in the world would you ever give ChatGPT access to your email? It’s a reasonable question, given everything we’re hearing about rogue AI agents, not to mention the privacy implications of unleashing AI in your inbox.
Then again, one of the best ways to appreciate the power of a personal AI assistant is to let it triage your unruly inbox, culling the spam and the marketing blasts while highlighting the messages that truly matter.
An agent with access to your messages can also give you a heads-up about impending meetings, warn you that your building’s elevator is out of service (that happened to me earlier this week), keep you current on that Jira ticket you filed, and perform other powerful workflows (like the one in this week’s prompt of the week, below).
To get access to your email, AI services like ChatGPT, Claude, Gemini, and Meta’s Muse agent need tools, and among the most common AI tools for email are those for Gmail. These tools allow AI models and agents to perform certain Gmail tasks, like “read message,” “add label,” “draft message,” or even — gulp — “send message.”
Welcome to another edition of Prompt Mode, your weekly AI newsletter.
I’m your host, Ben Patterson. Each week on Prompt Mode, I’ll be serving up analysis of the AI trends that matter to everyday users like you and me. Stay tuned for practical AI tips, hands-on experiences with the latest AI tools, and–you guessed it–prompts to help you get the most out of your AI assistants.
Thanks for reading, and if you like what you see, just sign up right here.
They also come with sets of rules and permissions that (generally speaking) you can customize, allowing some actions to happen autonomously while others require a user’s approval, or are blocked altogether. Tweak these rules the right way, and you can minimize the chance of your agent, say, sending an email on its own when it shouldn’t.
The key word, of course, is “minimize.” AI agents like ChatGPT Dots, Claude Cowork, Gemini Spark, and Meta Muse can act in unpredictable ways, and while you can prevent the agents from scooping up your Gmail messages for AI training data, sensitive details from your Gmail conversations could wind up in your AI chat threads, where they could be stored as memories.
So if you’re uncomfortable taking those risks — and hey, I get it — my advice is to leave the Gmail tools alone.
If you do choose to move ahead, know that enabling an AI’s Gmail integrations is just the first step. (ChatGPT has a Gmail “plugin,” while Claude and Muse call them “connectors,” and Gemini folds its Gmail integration under its “Personal Intelligence” umbrella.) Dig deeper, and you’ll find more granular controls for those Gmail tools, where you’ll be able to do things like set guardrails for when an agent can or can’t send email on its own.
For Claude, click Settings > Connectors, then click on Gmail. From there, you’ll find a wide range of Gmail rules, from allowing Claude to peruse received and drafted messages to whether it can add labels to messages or even send them on its own. You can set entire groups of read-only and write/delete rules to “Always Allow,” “Needs Approval,” or “Blocked,” or you can set specific rules for each action.
ChatGPT’s Gmail plugin rules (check Settings > Plugins) aren’t nearly as granular as Claude’s, giving you just four total options: “Always ask,” “Allow read actions,” “Allow low-risk actions,” or “Allow all actions.” The second setting — “Allow low-risk actions” — is the default, but personally I’d stick with “Allow read actions,” just to be sure ChatGPT asks before sending email on its own.
Gemini is even more vague about the rules for its Gmail tool, essentially limiting you to turning its Gmail integration either on or off. According to a Google support page, Spark is “designed to ask for your review” before “sending communications,” which means it should stop and ask before sending a Gmail message on its own. But if Gemini’s lack of specific permission controls for Spark gives you pause (and that’s perfectly understandable), you might want to switch its Gmail connector off.
Finally, Meta Muse keeps its tool settings under Settings > Permissions > Connectors. Select the Gmail option, then start tweaking. As with Claude, Muse’s permission settings for Gmail allow you to fine-tune whether it can do things like access and search your email, draft messages, and send emails on its own, with your approval, or never.
Aside from general Gmail permissions, you’ll want to block the use of your Gmail for AI model training. The best way is to ensure you have the overall “help improve our models” setting for ChatGPT, Claude, and Meta Muse turned off (check under Settings > Data Controls or Privacy). Google, for its part, says it won’t train its models “directly” on your Gmail messages, but may train on “limited info,” such as “specific prompts in Gemini or AI Mode and the model’s responses.”
Now that you’ve hardened permissions and checked your AI model-training settings, what can you do with your new Gmail AI superpowers? Check the prompt below for one example, and I’ll have more in the weeks ahead.
More in AI this week
- Google will now let anyone try its SynthID detector, a tool that lets you check images, videos, and audio files for AI watermarks. Just keep in mind that the detector can’t prove whether a suspicious-looking viral video is real. [PCWorld]
- ChatGPT is about to get its own digital wallet, which could allow ChatGPT Dot agents to make web purchases on its own. [PCWorld]
- Common Sense Media is sounding the alarm over ChatGPT for Teens, which “could give parents false confidence in guardrails and safety alerts that frequently don’t work.” [The Verge]
- Anthropic’s just filled out its 5.5 family of Claude models with the fast and cheap Haiku 5.5, which joins the mid-range Sonnet 5.5 and the top-end Opus 5.5. I plan on giving the new Haiku a test drive in the next few days, so I’ll report back on what it can and can’t do. [VentureBeat]
- AI is crushing it when it comes to solving math’s toughest riddles. But while their solutions check out, their reasoning is often indecipherable to human mathematicians, with some grimly predicting the “end of math as we know it.” [Quanta Magazine]
Prompt of the week: The “find my forgotten accounts” prompt
So, you took a deep breath and connected your Gmail to AI. Here’s an agentic “outcome”-oriented prompt to put that new ability to the test.
With this prompt, you’ll be directing an AI agent to scour your Gmail for messages about long-lost accounts you previously signed up for, with the AI doing a read-only search for “verify your email” and “confirm your account” messages.
When it’s done, you’ll get a spreadsheet detailing all the accounts the agent found, with the most dormant at the top, along with links (when available) for deleting the forgotten accounts you don’t want anymore.
That’s all for now!
Thanks for reading the latest issue of Prompt Mode.
Want more next week? Don’t forget to sign up to start receiving this newsletter in your inbox.


