Connecting AI agents to outside services explodes the risk radius
A study by AI security firm PromptArmor has found that "connectors" – integrations letting AI agents like ChatGPT and Claude interact with third-party services such as Gmail, Slack or Dropbox – are changing so rapidly and unpredictably that they undermine any security assumptions made when they were first approved. This matters because connectors already carry the risks associated with the "lethal trifecta" of private data access, exposure to untrusted content and external communication channels, but their constant evolution and hidden dependencies on further AI services make it far harder for organisations to assess and manage the risk they pose.
PromptArmor found that 931 of 2,517 connectors examined, or 37 per cent, changed between mid-May and the end of June, with 1,686 new tools added and 1,127 tool descriptions rewritten. Dropbox's connector, for instance, grew from eight tools to 24, with write-capable tools rising from three to ten and destructive-capable tools from zero to four. The firm also found that around two in five of 487 Claude connectors examined are likely to call additional external AI services, meaning sensitive data entered into a query, such as via Zoom's connector, could be passed to numerous third-party AI subprocessors without the approving team's knowledge. Anthropic's own documentation acknowledges that connected services process data under their own terms, potentially outside the US.
- AI connectors to services like Gmail change fast, undermining security assumptions
- 37% of 2,517 connectors studied changed in six weeks
- Many connectors secretly route data to further third-party AI services
New here? Start with this
The rise of AI chatbots such as ChatGPT and Claude has been followed by a push to make them more useful by linking them to everyday work tools like Gmail, Slack and Dropbox. These links, known as connectors, let an AI agent read files, send messages or move data on a person's behalf, rather than just answering questions in a chat window. Businesses that adopt them typically review the connector once for safety before rolling it out to staff.
The concern raised here is that these connectors do not stay still. Security researchers have been tracking how often they change, and found that the tools and permissions built into them are frequently added to or rewritten without users being told, sometimes making a connector far more powerful, including gaining the ability to delete data, than when it was first approved. Some connectors also quietly pass information to other AI systems behind the scenes, so data typed into one service could end up handled by companies the original user has never heard of.
This matters because organisations often assume a security check done once remains valid, when in fact the tools a connector can use may look very different weeks later. Given that these AI agents are already handling sensitive company information, the worry is that risks can grow unnoticed, leaving IT and security teams unaware of what their AI tools are actually able to do at any given moment.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Security-focused advocates argue that connectors are being allowed to accumulate dangerous new capabilities, such as write and destructive actions, and hidden links to further AI subprocessors, without the renewed scrutiny such changes warrant. They contend that when a tool set can grow from eight to twenty-four functions, or start silently forwarding data to unknown third parties, the original risk assessment is void, and organisations are being left exposed to data breaches, unauthorised actions and legal liability through no fault of their own. On this view, vendors and platforms bear a duty to flag material changes and seek fresh sign-off before expanding what an approved connector can do.
The case against
Others argue that fast, continuous iteration is precisely what makes these tools useful, and that expecting every minor tool addition or description rewrite to trigger a full re-approval cycle would strangle the pace of innovation that gives organisations a competitive edge. They point out that platforms like Anthropic already disclose, in their documentation, that connected services process data under their own terms, meaning the information needed for informed risk decisions is available to those who read it. On this view, responsibility for governance sits with the enterprises deploying these tools, who can restrict permissions, audit usage and choose which connectors to enable, rather than with vendors being expected to freeze functionality in place.