Is it safe to give an AI agent access to your Gmail inbox?
It is reasonably safe when four conditions hold. The tool asks only for the Gmail permissions it needs. It has passed Google's verification for those permissions. It cannot send mail without your approval. And its own policy says it does not train models on your email. If any one is missing, the risk goes up sharply.
Judge the permission, not "AI" in the abstract. A model can only touch what the OAuth grant hands it. An app holding full Gmail access can do anything you can do in Gmail, including deleting mail for good. An app holding a narrow scope cannot, however clever the model behind it.
Google's own Gmail API scope list marks gmail.readonly, gmail.modify and https://mail.google.com/ as restricted. That is Google's highest sensitivity tier, and it triggers extra review before a public app can use those scopes.
You can withdraw an app's access later from your Google Account. The vendor still controls what happens to any copies it already made, so check its policy before you connect, not after.
What can an AI email assistant actually see in your Gmail?
An AI email assistant sees exactly what its Gmail API scope allows. That can be your labels alone, or message headers without bodies. It can also be the full text and attachments of every email, plus the power to send, archive or delete. The consent screen tells you which level you are granting.
Gmail access falls into four rough kinds:
Read access is not limited to new mail. It normally covers your whole mailbox, including sent mail and threads from years ago.
Calendar and Contacts are separate Google APIs with their own scopes. A tool that also books meetings will ask for those too, and each appears as its own line on the consent screen.
"It only reads" is still a large grant. To summarise or sort your email, the app fetches the content to its own servers. The vendor then holds a copy, and its retention policy decides how long it stays.
- Metadata: headers, labels and history. Google describes
gmail.metadataas reading metadata "including labels, history records, and email message headers, but not the message body or attachments." - Read: message bodies and attachments. Google describes
gmail.readonlyas able to "read all resources and their metadata," with no write operations. - Write: drafts, labels, archiving and moving to Trash.
- Send: mail going out under your name.
Gmail permissions ranked by risk: the eight scopes an assistant is likely to ask for, from Google's own docs
Gmail's API permissions range from labels-only access to full mailbox control. This table ranks each scope by what an app holding it can do, using Google's own descriptions and sensitivity classes. If an AI tool's consent screen maps to a row near the top, ask the vendor why it needs that much.
To use it, find the wording on the consent screen and match it to a row. Scope strings shortened to gmail.x stand for https://www.googleapis.com/auth/gmail.x.
Classifications as listed on Google's Choose Gmail API scopes page, accessed 11 October 2026. Google can reclassify scopes, so check the live page if a decision rests on one cell.
The delete column is the sharpest signal. Google's reference for users.messages.delete lists only https://mail.google.com/ as the scope that permits it. Google describes gmail.modify as covering all read and write operations "except immediate, permanent deletion of threads and messages, bypassing Trash." Its scope page also tells developers to request full access only if the app must delete mail permanently.
Every scope able to read mail sits in the restricted class. Even metadata is restricted. Who emails you and when is sensitive in its own right.
| Scope | What an app can do (plain words) | Reads message bodies? | Can send? | Can permanently delete? | Google class | What to ask the vendor |
|---|---|---|---|---|---|---|
https://mail.google.com/ | Everything you can do in Gmail, including permanent deletion | Yes | Yes | Yes | Restricted | Why do you need delete-forever rights? Will a narrower scope work? |
gmail.modify | Read, compose, send, label, archive and trash mail. No immediate permanent delete. | Yes | Yes | No (Trash only) | Restricted | Does anything send without my approval? Is there an undo? |
gmail.readonly | Read all messages, attachments and settings | Yes | No | No | Restricted | Where is my mail stored, for how long, and is it used for training? |
gmail.compose | Create, edit and delete drafts, and send messages and drafts | Drafts only, not your inbox | Yes | Drafts only | Restricted | Do you save to Drafts or send directly? |
gmail.insert | Add messages into your mailbox | No | No | No | Restricted | Why do you need to place mail in my inbox? |
gmail.metadata | See headers and labels, not message bodies | No | No | No | Restricted | Is metadata enough for what you do? |
gmail.send | Send email as you. No reading. | No | Yes | No | Sensitive | What triggers a send, and do I approve each one? |
gmail.labels | Create, edit and delete labels only | No | No | No | Non-sensitive | Usually fine on its own. |
What OAuth scopes should an AI email assistant request?
An AI email assistant should request the narrowest OAuth scope that covers its job. A tool that only summarises needs read access. A tool that writes replies for you to send needs drafts access. Full mailbox access (https://mail.google.com/) is rarely justified for an assistant, because the only thing it adds is permanent deletion.
A rough match between job and scope:
Google tells developers the same. Its scope guidance asks them to pick the most narrowly focused scope possible and avoid scopes the app doesn't need. If a tool asks for full access and its feature list never mentions deleting mail, treat that as a red flag.
The OAuth mechanism itself is sound. Under OAuth 2.0, the app never sees your Google password. It receives a token that works only for the scopes you approved, and you can cancel that token without changing your password.
- Summarise or triage:
gmail.readonly - Draft replies for you to send:
gmail.composeplus read access to see the thread - Archive and label:
gmail.modify
How do you read the Google consent screen before clicking Allow?
The Google consent screen lists, in plain sentences, every permission the AI app is asking for, along with the app's name and developer contact. Read each line and match it to a Gmail scope before you click Allow. If a line says the app can permanently delete all your email, that is full access.
Run through this checklist on the screen itself:
Google now shows checkboxes for individual permissions when an app requests several at once. Its granular permissions documentation tells developers to handle the case where you grant only some of them. You can untick a permission you're unsure about. The tool may then stop working for that feature, which shows you what it genuinely needs.
- The app name and developer email match the vendor's own website.
- Each permission line maps to a row in the scope table, and the broadest one makes sense for the job.
- There is no "Google hasn't verified this app" warning in front of the screen.
- Links to a privacy policy and terms of service are present, and they open.
- Any extra Google services requested, such as Calendar, Contacts or Drive, fit what the tool does.
- You have taken a screenshot, so you can compare later if the app asks for more.
What does Google verification prove about an AI email app?
Google verification shows that an app requesting restricted Gmail scopes has had its use of those scopes reviewed by Google. Where the app handles that data on its servers, it has also passed an independent security assessment. Verification does not prove the vendor won't keep your mail for a long time. It does not replace reading the vendor's own privacy policy.
Google's restricted scope verification rules cover apps that request restricted scopes and are available to users outside the developer's organisation. Google checks that each restricted scope is justified by a feature the user can see. It also checks that the app has a public privacy policy and follows the Google API Services User Data Policy. Apps that store or transmit restricted data on their own servers must also pass a security assessment by a Google-approved assessor, repeated every 12 months.
Verification leaves several questions open:
Google's pages also list exemptions. Apps used only inside one Google Workspace organisation, apps for the developer's personal use and apps still in testing don't go through public verification. A tool your company built internally may never show a verification badge, and that alone is not a warning sign.
### What the "Google hasn't verified this app" screen means
This warning appears when an app requests sensitive or restricted scopes without completing verification. Google's unverified apps page explains that you have to click through an extra step to continue. On a tool sold to the public that asks for Gmail read access, treat the warning as a reason to stop. It is reasonable only if you trust the developer personally, for example with a script a colleague wrote.
- How long the vendor keeps copies of your mail
- Which AI model provider processes the text
- Product behaviour, such as whether replies send automatically
Can an AI assistant send emails without your approval?
An AI assistant can send emails without your approval only if you granted a scope that allows sending and the product is built to send on its own. Send-capable scopes are gmail.send, gmail.compose, gmail.modify and full access. The scope tells you whether sending is possible. The product's settings tell you whether it happens without a check.
Use this test on any tool, ChatGPT connectors included:
As one example of approval-gated sending, every email Momo sends for you, and every proposal of meeting times, waits for your tap on an approval card. A disclosure first: this blog is published by Momo, which is in early access, and its Google OAuth verification and CASA security assessment are still pending. If you connect it today, you will see Google's "Google hasn't verified this app" screen, which is exactly the warning this article tells you to weigh carefully, so make that call with the facts in front of you. Its reply drafts go into your Gmail Drafts for you to send yourself, and you get 10 seconds to undo a send after approving it. Other parts of a tool may still act without a card, such as saving a draft or emailing you a summary, so read what each feature does. The same check applies to any tool that offers AI that writes emails in your voice.
Gmail has its own safety net for mail you send yourself. Its Undo Send setting lets you set a cancellation period of 5, 10, 20 or 30 seconds. That covers sends you make in Gmail. It does not govern what a third-party app sends through the API.
- Scope: does the consent screen include a send-capable permission? If it shows only
gmail.readonlyorgmail.metadata, the tool cannot send, whatever the AI says in chat. - Drafts: can the tool save replies to your Gmail Drafts instead of sending them?
- Approval: does every send show an explicit approval step before anything leaves?
- Undo: is there a short window after you approve in which you can cancel?
Will your emails be used to train an AI model?
Your emails should not be used to train general AI models if the app follows Google's rules. Google's Workspace API policy bars apps that access Gmail data from using it to develop or train generalised AI or machine-learning models. Still check each vendor's own policy, because retention and model-provider terms vary.
The Google Workspace API User Data and Developer Policy applies to apps using the Gmail API. It prohibits using data obtained through those APIs to develop, improve or train generalised or non-personalised AI and ML models. An app that breaks this risks losing its access.
Training and processing are different, though. To draft a reply or summarise a thread, the app sends your email text to a model provider and gets an answer back. That happens on every request. So ask a vendor practical questions:
Momo, for instance, states that it doesn't train on your email, purges conversations after 30 days, and lets you delete everything in one tap. Whatever tool you pick, look for that kind of plain statement in its privacy policy or FAQ. If you can't find one, ask before connecting.
- Which model providers process my text, and under what terms?
- How long are conversations and cached mail kept?
- Can I delete everything myself, and how fast does deletion happen?
How do you revoke an AI app's access to your Gmail?
You can revoke any AI app's access to Gmail from your Google Account in under a minute. Removing the connection stops the app reading or sending from that moment. Data the vendor already copied is governed by the vendor's own deletion policy, not by Google, so request deletion separately.
Google Account Help explains how to remove a third-party app's access. The steps:
Google's menu labels change from time to time, so follow the help page if the wording differs. For how long the vendor takes to erase your data, check its privacy policy or help centre. Only the vendor's published policy binds it.
- 1Go to myaccount.google.com/connections, or open myaccount.google.com and choose Security.
- 2Find Your connections to third-party apps & services.
- 3Select the AI app from the list.
- 4Choose the option to delete its connections, then confirm.
- 5Open the app itself and delete your account there, which starts the vendor's own deletion process.
- 6Repeat for every Google account you connected.
Can a Google Workspace admin block AI apps on your work Gmail?
Yes. A Google Workspace admin can block, limit or explicitly trust third-party apps that request access to Gmail and other Workspace data. If you use Gmail through your employer, the admin's settings may stop the connection altogether. Company policy may also forbid it even where the connection works. Ask first.
Google Workspace Admin Help describes these API controls for third-party apps. In the Admin console, under Security, then Access and data control, then API controls, an admin can set each app as trusted, limited or blocked. Admins can also restrict high-risk services such as Gmail, so only apps they've trusted can request those scopes.
This matters most for founders, SDRs and managers. Client threads, deal terms and HR conversations are not only yours to share. A connection that's fine for your personal life can still breach a customer contract.
A personal @gmail.com account has no admin layer. There, the decision and the risk rest with you alone.
When is Gemini in Gmail the safer choice than a third-party AI tool?
Gemini in Gmail can be the lower-risk choice when you only need help on demand, because it runs inside Google's own service. It needs no third-party OAuth grant to your mailbox. You give up the background features that third-party assistants add, such as follow-up tracking or running a scheduling thread.
The privacy case is simple. No additional company receives a copy of your mail, so there's no extra vendor retention policy to read. For work accounts, Google's generative AI privacy hub for Workspace says your content is not used for generative AI model training outside your domain without permission.
The trade-off runs the other way on features. Gemini helps when you ask. It does not watch for unanswered threads or chase promises unprompted. If you only want summaries or a one-off draft, the built-in option may be all you need, and it is worth trying first. You can see what Gemini in Gmail can do before deciding whether a separate tool earns its access.
The bottom line on giving AI access to Gmail
Giving an AI assistant access to Gmail is a trade you can make safely if you treat the consent screen as a contract. Grant the narrowest scope, and prefer verified apps for restricted scopes. Insist on an approval step before anything sends. Read the training and retention policy, and know where the revoke button is.
Reuse this checklist for any tool:
Say no when you see full access with no clear reason, an unverified-app warning on a public tool, no published privacy policy, or a work account your admin hasn't cleared. The anchoring fact is the delete right. https://mail.google.com/ is the only Gmail scope that permits permanent deletion, according to Google's scope documentation, so it is the clearest sign of a tool asking for more than it needs. If you're ready to compare options, see AI chief of staff tools compared.
- The scope matches the job, and full access has a stated reason.
- A public tool asking for restricted scopes shows no unverified-app warning.
- Sends need your approval, ideally with drafts and an undo window.
- The privacy policy rules out training and gives a retention period.
- You know the path to Security, then third-party connections, to revoke.
Sources
Every number and claim above links to one of these.
- Choose Gmail API scopes, Google for Developers: scope descriptions, sensitivity classes, narrowest-scope guidance (accessed 11 October 2026)
- Method: users.messages.delete, Gmail API reference: only full access permits permanent deletion
- Using OAuth 2.0 to Access Google APIs: scoped tokens without sharing your password
- How to handle granular permissions, Google for Developers: per-permission checkboxes on the consent screen
- Restricted scope verification, Google for Developers: verification and security assessment requirements
- Unverified apps, Google Cloud Help: meaning of the unverified-app warning
- Google API Services User Data Policy: policy apps must follow to be verified
- Google Workspace API User Data and Developer Policy: prohibition on training generalised AI/ML models
- Manage connections with third-party apps, Google Account Help: revocation steps
- Unsend sent messages in Gmail, Gmail Help: Gmail's built-in Undo Send periods
- Control which third-party & internal apps access Google Workspace data, Admin Help: admin API controls
- Generative AI in Google Workspace Privacy Hub: Gemini training statement for Workspace
- Momo: approval cards, Gmail Drafts, 10-second undo, training and retention statements
