Security engineer reviewing systems on a computer in an office setting

When AI Agents Get Standing Access to Your Inbox and Slack

OpenAI’s own lead engineer just told TechCrunch something enterprise security teams should be paying close attention to: when an AI agent has standing access to your inbox, Slack, and connected apps, it might pull from “a private DM” while drafting an unrelated document. That’s not a hypothetical risk analysts are warning about — it’s a tradeoff OpenAI’s own team is already living with while testing its desktop app, built around ChatGPT Work.

From assistant to standing operator

The shift happened incrementally. ChatGPT Work launched July 10, 2026 for Pro, Enterprise, and Edu users, connecting to Gmail, Google Calendar, Slack, and GitHub via MCP-based plugins to autonomously read messages, scan invites, and pull commit histories, according to VentureBeat. OpenAI followed with Workspace Agents and a dedicated ChatGPT Agents app inside Slack, letting deployed agents respond in channels and produce files directly. By the time TechCrunch reported on the desktop app in August, agents weren’t assisting on request anymore — they were operating continuously, across tools, with persistent access.

The numbers say most security teams haven’t caught up

Research from the Cloud Security Alliance and Token Security, cited by Kiteworks, found that 65% of organizations experienced at least one security incident caused by an AI agent in the past year. Among the affected companies, 61% involved sensitive data exposure and 35% resulted in direct financial loss. Perhaps more telling: 63% of organizations can’t enforce purpose limitations on their agents, and 60% can’t even terminate a misbehaving one once it’s running.

Okta’s 2026 survey of nearly 800 executives and knowledge workers across seven countries found only 34% of organizations apply the same security controls to their “agentic workforce” as they do to human employees — even though 58% of executives reported an AI-related security issue or close call in the past year. There’s a confidence gap too: 65% of executives believe agent-use policies are clear, but only 43% of the knowledge workers actually following them agree.

The market is already pricing this risk

Enterprise demand for agent governance isn’t speculative — it’s funded. On September 1, 2026, AIR raised $50M across two seed rounds, led by Sequoia and Greenoaks, to continuously vet the skills and add-ons AI agents use and block the ones that fail security review. The platform already rejects about 27% of the agent add-ons it scans. AIR serves more than 20 customers, roughly a quarter of them large enterprises, with the strongest demand coming from financial services and pharma — exactly the regulated industries where a standing-access mistake is hardest to undo.

What security teams should do now

Treat agents with standing, cross-app access as privileged insiders, not as software features. That means agent-specific identity and audit trails, explicit allow-lists for what each agent can read or act on, and — critically — a tested way to revoke access immediately when something goes wrong.

  • Inventory every agent with standing access to email, chat, or SaaS tools — most security teams don’t have this list today.
  • Apply the same access reviews and offboarding discipline to agents that you apply to employees and contractors.
  • Vet third-party agent skills and add-ons before deployment, rather than trusting a marketplace listing.

OpenAI’s engineer wasn’t being careless when he flagged the private-DM risk — he was being honest about a tradeoff his own company is shipping. The question for every enterprise adopting agentic tools isn’t whether that tradeoff exists. It’s whether anyone on the security team has been asked to sign off on it yet.