Connecting AI agents to outside services explodes the risk radius
A study by AI security firm PromptArmor has found that "connectors" – integrations letting AI agents like ChatGPT and Claude interact with third-party services such as Gmail, Slack or Dropbox – are changing so rapidly and unpredictably that they undermine any security assumptions made when they were first approved. This matters because connectors already carry the risks associated with the "lethal trifecta" of private data access, exposure to untrusted content and external communication channels, but their constant evolution and hidden dependencies on further AI services make it far harder for organisations to assess and manage the risk they pose.
PromptArmor found that 931 of 2,517 connectors examined, or 37 per cent, changed between mid-May and the end of June, with 1,686 new tools added and 1,127 tool descriptions rewritten. Dropbox's connector, for instance, grew from eight tools to 24, with write-capable tools rising from three to ten and destructive-capable tools from zero to four. The firm also found that around two in five of 487 Claude connectors examined are likely to call additional external AI services, meaning sensitive data entered into a query, such as via Zoom's connector, could be passed to numerous third-party AI subprocessors without the approving team's knowledge. Anthropic's own documentation acknowledges that connected services process data under their own terms, potentially outside the US.
- AI connectors to services like Gmail change fast, undermining security assumptions
- 37% of 2,517 connectors studied changed in six weeks
- Many connectors secretly route data to further third-party AI services