HomeMobileAndroidClaude can send emails without asking; Google still won't let Gemini press...

Claude can send emails without asking; Google still won’t let Gemini press send on its own

Google owns Gmail. Google builds Gemini. And Google still won’t let Gemini press send on its own. Well, Anthropic will.

Its August 2026 update to the connector lets Claude read an incoming email, write the reply, and send it to someone else’s inbox.

That’s a thrilling sentence and a frightening one, depending on what the email says.

Where Claude and Gemini differ in Gmail

Reading your mail is standard; show me more

Gemini vs Claude on Android
Credit: Lucas Gouveia / Android Police

Let’s start where Anthropic’s documentation starts. That covers searching your mail, listing saved drafts, summarizing long threads, and reading message metadata.

None of that is new ground, because every assistant reads your mail these days. But keep reading, and you get to the write actions.

Claude can also send, reply to, and forward emails from Gmail. It checks with you first by default. But you can switch that off and let it go YOLO.

At that point, you have an agent writing under your name. Now let’s compare permissions with Gemini.

Claude (Workspace connector)

Gemini in Gmail

Read and search inbox

Yes

Yes

Summarize threads

Yes

Yes

Draft new emails

Yes

Yes

Read attachments

No (Metadata only)

Yes

Auto-send without a human click

Yes, if you turn off approval (asks by default).

No, requires a manual click

Forty emails from one prompt is great until one of them is wrong

Scale works in both directions

Claude icon with key and warning symbol surrounding it
Credit: Lucas Gouveia / Android Police

The upside is scale. Batch email has always meant either a mail merge that reads, well, like a mail merge, or an afternoon of copy-and-paste.

An agent that can read context and write 40 messages is impressive.

Give Claude a list of 40 conference attendees and ask it to thank each one for coming, with a line about the session they attended. That’s one prompt instead of 40 tabs.

But this cuts both ways. Email has no reliable undo function. After a message leaves your outbox, it’s a record that stays in the recipient’s inbox permanently and speaks with your authority.

An agent that hallucinates a bad response to a client is a record you now have to explain. Fixing it means writing the embarrassing follow-up, and that one’s permanent as well.

My reading is that Google probably can’t afford what Anthropic can risk

A smaller blast radius buys room to be aggressive

Gmail inbox with the Gemini turned off.
Credit: Lucas Gouveia / Android Police

Google’s risk profile is different from Anthropic’s. Gmail moves billions of messages a day and handles a constant stream of phishing and malicious payloads.

Give that user base autonomous sending, and one model failure is all it takes for the headline to read “Google’s AI helped run a scam.”

That’s not the only reason. However, it is a fair assumption that nobody at Google fancies defending an unattended agent sending emails at scale.

Anthropic’s blast radius is smaller, and its users chose to be there. Claude’s audience who can use this are paying subscribers who connected Gmail on purpose.

It’s inherently different from a billion people who got an AI button added to an app they already had.

It deploys the feature and hands the liability downstream, which is why a third party can be more aggressive than the platform owner.

What happens when your agent takes orders from a stranger’s email?

Guardrails lower the odds and don’t remove them

A white robot with red spiral eyes surrounded by floating digital prompt boxes.
Credit: Lucas Gouveia / Android Police | tete_escape / Shutterstock

Prompt injection worries me most here. Let’s say someone sends you an email with hidden text that tells the agent to disregard its prior instructions.

The agent reads that message to write a reply, so it swallows the payload as a command.

A working injection could tell Claude to forward sensitive threads to an outside address or pull verification codes to break into other accounts.

Now, like Google, Anthropic also trains its models to flag malicious instructions and treat external content as untrusted input.

Still, security researchers consider prompt injection one of the hardest problems to close off completely. So maybe don’t leave Claude in YOLO mode all the time.

My rule for what Claude gets to send without me

Some sending is low stakes and fine to automate. I put calendar replies, meeting confirmations, even some routine follow-ups in that bucket.

If an agent messes up a meeting status, you probably lose 15 minutes and some goodwill. If it touches money or feelings, I won’t share every detail with the AI, and nothing leaves until I’ve read it.

The time you save by skipping a confirmation click is nothing compared to the time you spend apologizing for a hallucinated message.

RELATED ARTICLES

Most Popular

Dominic
32548 POSTS0 COMMENTS
Milvus
131 POSTS0 COMMENTS
Nango Kala
6924 POSTS0 COMMENTS
Nicole Veronica
12039 POSTS0 COMMENTS
Nokonwaba Nkukhwana
12150 POSTS0 COMMENTS
Shaida Kate Naidoo
7060 POSTS0 COMMENTS
Ted Musemwa
7302 POSTS0 COMMENTS
Thapelo Manthata
7018 POSTS0 COMMENTS
Umr Jansen
7007 POSTS0 COMMENTS