found a new agent safety risk today. asked chatgpt to email three lawyers for quotes (in my head it was clear separately). it put them all in one email thread. now they all know i'm shopping around... this is the same as trying to send a meme to 3 friends and accidentally made a group chat instead.
Xiao Ma says ChatGPT grouped separate lawyer emails into one thread
Andreas Kirsch argues AI should only draft emails.
Autonomous sending creates unintended leaks
The merged thread revealed shopping behavior the user had explicitly wanted kept private, showing how agent coordination can expose intent even when instructions aim for separation.
Draft-only mode limits exposure
One researcher argues agents should never send messages on their own and flags extra prompt-injection risks once email access is granted, leaving open whether future versions will restrict themselves to drafting.
Users express interest in the ChatGPT Agent putting three lawyers in one email thread because it reveals a flaw they hope to investigate and fix in the next GPT version.
No Digg Deeper questions have been answered for this story yet.
Most Activity
@infoxiao I would never allow it to send anything by itself. Drafting yes but not sending. Also worried about giving access to my email account bc of possible prompt injection attacks tbh
found a new agent safety risk today. asked chatgpt to email three lawyers for quotes (in my head it was clear separately). it put them all in one email thread. now they all know i'm shopping around... this is the same as trying to send a meme to 3 friends and accidentally made a group chat instead.
@infoxiao this sounds interesting. will look into it with our teammates and hopefully we can fix it in our next version of gpt.