21 June 2025

Against AI in Your Inbox

Convenience at the Expense of Privacy, Security, and Integrity

Barrister Fraz Wahlah

AI use in email platforms
Email has always been the soft underbelly of our digital lives: intimate, searchable, legally consequential, and—too often—poorly defended. Integrating artificial intelligence into email platforms promises relief from clutter and writer’s block. But if we ground our judgment in whistleblower revelations and documented incidents—not marketing copy—the prudent conclusion is stark: AI-augmented email supercharges long-standing surveillance and security risks and subtly erodes the integrity of our communications and records.

1) The Lesson of History

A decade of brave citizen leaks and investigative reporting shows that email was—and remains—a prized target for surveillance and compelled access. The Snowden disclosures revealed PRISM, an NSA program collecting data from major tech platforms, with email among the most sensitive flowsGuardianWaPo.

Compelled scanning has also happened at the provider level: in 2016, Reuters reported that Yahoo built custom software to scan all incoming user emails at the request of U.S. intelligence—hundreds of millions of accountsReuters.

And when providers are breached, the blast radius is historic: Yahoo’s 2013 incident ultimately touched all three billion accountsReuters.

2) What “AI in Your Inbox” Actually Does

Today’s email AIs read threads, summarize them, suggest replies, and draft messages—which requires expanded access to message bodies and metadata. Google’s Gemini for Gmail offers thread summaries and reply suggestions; Microsoft’s Copilot in Outlook summarizes long conversations; Apple Intelligence introduces summaries and Smart Reply in MailGoogleMicrosoftApple.

Vendors stress limits—often that user content isn’t used to train foundation models—but the operational reality still involves processing, storage, and logging. Microsoft and Google describe retention and safety processing; Apple touts “Private Cloud Compute” as a hardened path for cloud-side inferenceMS LearnGoogleApple Sec.

3) A Bigger Attack Surface: AI-native Email Threats

Once an AI assistant reads emails to summarize or take action, the content of any message becomes an instruction channel to the model. Security researchers call this indirect prompt injection—malicious cues embedded in ordinary text or HTML that cause the assistant to mislead the user or exfiltrate data. OWASP now lists prompt injection and sensitive-information disclosure among the top risks for LLM applicationsOWASP.

Even vendor guidance acknowledges the issue, and independent write-ups demonstrate viable email-based prompt-injection proofs-of-concept against modern assistantsMS LearnImmersive.

4) Centralization Risk: When the Cloud Becomes the Target

Even before AI, cloud email made high-value prey. In 2023, it was reported a group Storm-0558 accessed cloud email for about 25 organizations, including government accounts; a subsequent federal review criticized preventable failures and transparency lapses. When AI adds more data flows, background services, tokens, and logs, it enlarges the terrain attackers aim forMS SecurityDHS CSRB.

5) Data Integration and Mission Creep

AI doesn’t live in a vacuum; it thrives on integration. That’s good for productivity—and perfect for aggregation. Palantir’s government platforms are designed to ingest vast, disparate datasets and surface people-centric intelligence. However you feel about specific deployments, the capability is clear, and public debates have followed as such tools enter civic systems. The more your communications are machine-read and summarized, the more portable—and attractive—they become for downstream analyticsPalantirBMJ.

6) Privacy Claims vs. Practical Exposure

“Not used to train the model” is not the same as “not processed, logged, or retained.” Microsoft says Copilot prompts and responses aren’t used to train foundation models; Google notes short-term retention for reliability and safety; Apple emphasizes a constrained cloud pathway. The security reality: more systems now hold more derivatives of your mail—summaries, embeddings, telemetry, caches—each a potential subpoena point, breach vector, or insider-threat surfaceMS LearnGoogleApple Sec.

And legal pressure has a long history: Yahoo’s 2016 scanning episode and the Snowden disclosures show how far compelled access and collection ambitions can runReutersGuardian.

7) Integrity and Authorship: Small Nudges, Big Consequences

Email is a record. What you say can bind you legally, ethically, and personally. AI reply-suggestion systems demonstrably shape what people send. Google’s Smart Reply research reported that, at launch, it assisted with a significant fraction of mobile replies—evidence that models already influence communicative style and content; early behavior (like over-suggesting “I love you”) shows how defaults can steer tone and meaningGoogle ResNew Yorker.

8) Whistleblowers Warn of Opacity—and Retaliation

Recent AI whistleblowers have argued for a right to warn about advanced systems and for legal protections when raising safety concerns. If insiders building the technology struggle to speak openly, users should be doubly cautious about embedding it into the most sensitive channel they own: emailRightToWarn.

The case for abstaining from AI-layered email (for now)

  1. Proven surveillance gravity. Email content and metadata draw state interest and covert access. AI increases the volume and value of what exists to be takenGuardianReuters.
  2. New, under-tested threats. Indirect prompt injection flips every message into potential executable “code” for your assistantOWASP.
  3. Centralized risk concentration. The Storm-0558 episode underscores how one cloud’s failure compromises many; AI multiplies services, tokens, and logsMS Security.
  4. Integrity drift. AI replies and summaries affect what gets said—and remembered—in ways that are convenient and corrosive to authorship and accountabilityGoogle Res.

What to do instead (practical steps)

  • Don’t use email that has anything to do with AI
  • Don’t use email from big tech notorious for data hoarding, tracking and exploitation
  • At least turn off AI features, if those can really be turned off, in email clients (e.g., disable Smart Reply/Compose in Gmail)Gmail Help.
  • Segregate tasks: use AI for low-risk drafting outside the inbox, then paste and edit manually; keep sensitive correspondence human-authored.
  • Prefer encryption for confidential mail and keep summaries local (client-side) wherever possible.
  • Reduce data exhaust: prune archives, disable autosaving AI chats, and tighten retention policies; know (and limit) what’s storedGoogle.
  • Assume hostile inputs: treat every inbound message as untrusted content—especially if your tooling auto-summarizes it.

Author

Barrister Fraz Wahlah is a democracy and civil rights icon and the founder of Space Email. He was the leading force behind the Movement of Restoration of Democracy, one of the world’s greatest democratic movements against dictatorship.

References

  1. The Guardian (June 6–7, 2013), initial PRISM reporting. Link ↩︎ ↩︎ ↩︎
  2. The Washington Post (June 7, 2013), PRISM slides/reporting. Link ↩︎
  3. Reuters (Oct 4, 2016), Yahoo built software to scan all users’ incoming emails. Link ↩︎ ↩︎ ↩︎
  4. Reuters (Oct 3, 2017), Yahoo says all 3B accounts were affected in 2013. Link ↩︎
  5. Google support — Gemini in Gmail features (summaries, reply suggestions). Link ↩︎
  6. Microsoft support — Copilot summarize email threads in Outlook. Link ↩︎
  7. Apple support — Use Apple Intelligence in Mail (summaries, Smart Reply). Link ↩︎
  8. Microsoft Learn — Copilot Chat privacy/protections; not used to train foundation models. Link ↩︎ ↩︎
  9. Google — Gemini Apps Privacy Hub (72-hour retention when activity is off). Link ↩︎ ↩︎ ↩︎
  10. Apple Security — Private Cloud Compute (Apple Intelligence). Link ↩︎ ↩︎
  11. OWASP — Top 10 for LLM Applications (includes prompt injection, data leakage). Link ↩︎ ↩︎
  12. Microsoft Learn — Microsoft 365 Copilot: protections include blocking prompt injections. Link ↩︎
  13. Immersive Labs (2025) — Email HTML prompt-injection proof of concept. Link ↩︎
  14. Microsoft Security Blog (Jul 14, 2023) — Storm-0558 analysis. Link ↩︎ ↩︎
  15. DHS — Cyber Safety Review Board report page on the incident. Link ↩︎
  16. Palantir — Gotham platform overview. Link ↩︎
  17. BMJ (2024) — Editorial on Palantir & NHS data platform concerns. Link ↩︎
  18. Google Research — “Smart Reply: Automated Response Suggestion for Email.” Link ↩︎ ↩︎
  19. The New Yorker (2015) — Early Smart Reply quirks (“I love you”). Link ↩︎
  20. “A Right to Warn about Advanced Artificial Intelligence” (2024) — open letter. Link ↩︎
  21. Gmail Help — Turn Smart Compose on/off. Link ↩︎
Space Email Trademark Logo

Space Email. Private by Nature. Out of this world. ™

Humanized tech ™
Made for you by Rocket.

SPACE EMAIL, SPACE POST, i.EMAIL, MARS.EMAIL, HOME.EMAIL, METAVERSE EMAIL, COSMOS EMAIL, COSMIC EMAIL, ASTRONAUT EMAIL, MEDIUM.EMAIL, APOLLO.EMAIL, ARTEMIS.EMAIL, SUN.EMAIL, WEB.EMAIL, HEY.EMAIL, ZEN.EMAIL, PANDA.EMAIL, GOLD.EMAIL, MILKYWAY EMAIL, ANDROMEDA.EMAIL, STARRY EMAIL, YOU.EMAIL, EARTHLING EMAIL, GRAVITY.EMAIL, AND OUR OTHER EMAIL CHOICES, MARKS, AS WELL AS SPACE DOCS, SPACE DRIVE, SPACE SHEETS, SPACE CLOUD, SPACE MEET, SPACE NOTES, SPACE IDs, SPACE CALL, SPACE EMAIL LOGO, SUN & MOON LOGO, MOON  FACE WITH SUN & STAR LOGO, HUMAN FACE LOGO ON YOU EMAIL PAGE, AND ROCKET DOMAINS LOGO ARE TRADEMARKS OF ROCKET DOMAINS LTD.

© Space Email. All rights reserved.