Are AI connectors safe? The honest answer in mid-2026 is: the app you approved is often not the app you are running a few weeks later. Research from the AI security firm PromptArmor, reported by The Register in July 2026, found that AI connector permissions keep changing after you grant them, and the change is not rare. Over a six-week window, 37 percent of the connectors they tracked, 931 out of 2,517, gained new capabilities, wider permissions, or rewritten instructions, usually with no notice and no request to re-approve. That is the core problem with connectors right now: you consent once, and the abilities keep growing under you.
This is a specific problem, and it is worth naming precisely so you can act on it. It is not the familiar question of whether you should ever connect an AI assistant to your Google Drive or your email. It is the newer question of what happens to that connection after you say yes. If you connect ChatGPT, Claude, or an AI agent to your accounts, this post explains what a connector actually is, what the research found, and what you can do to limit the blast radius without giving up the tools you like.
What an AI connector actually is, in plain terms
A connector is a bridge that lets an AI assistant reach into another app and do things there on your behalf. When you click Connect Gmail or Connect Dropbox inside a tool like ChatGPT or Claude, you are handing the assistant a set of keys to that account. From then on, the assistant can read, and sometimes write, inside that service so it can answer questions or complete tasks for you.
- A Gmail connector might let the assistant read your inbox to summarize threads, and in some setups send mail as you.
- A Dropbox or Drive connector might let it search your files, open documents, and in some setups edit or delete them.
- A Slack connector might let it read channels and post messages under your name.
- A calendar connector might let it read your schedule and create or move events.
Each of those abilities is a tool the connector exposes. The important detail most people miss: the list of tools a connector offers is not fixed. The vendor can add tools, widen what an existing tool is allowed to touch, and change the hidden instructions that tell the AI when to use them. You approved a bridge. The bridge can be widened after you cross it.
The finding: connectors keep changing after you approve them
The headline result is that connector permissions changing is normal, not exceptional. PromptArmor tracked 2,517 connectors from mid-May to the end of June 2026 and found that 931 of them, about 37 percent, changed their capabilities, permission scopes, or instructions during that stretch. Across the set they counted 1,686 new tools added to connectors that were already live, and 1,127 tool descriptions rewritten. PromptArmor summed up the pace bluntly: on average, a connector in their sample changed roughly every nine minutes.
The most vivid single example was a Dropbox connector. On the first day of the study it exposed 8 tools, none of them destructive. By the end of the study it exposed 24 tools, its write-capable tools had grown from 3 to 10, and it had gone from 0 potentially destructive tools to 4. The permission scopes changed too, and the connector had picked up injected model instructions along the way. Nobody using it clicked approve again for any of that.
Two clarifications keep this fair. First, a tool being added is not the same as your data being harmed; a new tool is a new possibility, not proof of misuse. Second, these figures describe one firm's six-week sample of the connector ecosystem, not a claim that any one named vendor acted in bad faith. The point that survives both caveats is structural: the thing you evaluated at approval time is a moving target.
The trap is not a single malicious app. It is a consent model that asks once and never asks again, even when the connector quietly gains the power to write, edit, or delete.
Why approve once, trust forever is the wrong mental model
The mistake is treating the approval screen as a final decision. When you install a normal phone app, the permissions it asks for on day one are roughly the permissions it has on day thirty. Connectors do not behave that way. The vendor controls the tool list on their side, and can expand it without pushing a new install or showing you a fresh consent prompt. Your original yes silently stretches to cover abilities that did not exist when you gave it.
This matters most when a connector crosses from reading to writing. Reading your files is a privacy question. Writing, editing, or deleting them is a safety question, because an AI agent that misreads an instruction, or is tricked by a hidden prompt inside a document, can now take an action that is hard to undo. PromptArmor noted that some connectors gained instructions injected into the model itself, which shapes when the AI decides to reach for a tool. A read-only helper turning into an agent that can delete is exactly the kind of shift that deserves a new prompt, and usually gets none.
The real risks, ranked by how much they can hurt
There are three concrete risks, and they are not equally severe. Scope creep is the common one, destructive actions are the dangerous one, and quietly handing your data to third parties is the sneaky one.
Scope creep
This is the base rate. A connector you approved for a narrow job accumulates tools and wider permissions over weeks until it can touch far more of your account than you intended. Nothing dramatic happens on any single day, which is exactly why it is easy to miss.
Destructive actions
This is the one to watch. The Dropbox example moved from zero destructive tools to four, and PromptArmor reported that across ChatGPT connectors the count of destructive actions available roughly tripled over the study, from 798 to 2,415. Destructive means delete or overwrite, the kind of action that cannot be taken back with an undo button.
Data passed to subprocessors you never approved
PromptArmor evaluated 7,517 tools across 487 Claude connectors and found that 189 of them, about 2 in 5, are likely to call additional AI services behind the scenes. They cited a Zoom example where a query could be routed to any of Zoom AI's ten AI subprocessors. As co-founder Shankar Krishnan put it, most teams approving a connector are evaluating the connector itself, unaware the vendor is calling more AI services and adding new subprocessors and terms. Your data can travel further than the one app on the label.
There is a related identity problem underneath all of this. Okta's Enterprise AI Index, covered by Help Net Security in July 2026, warned that AI agents often log in using a human's credentials, which the researchers said collapses the audit trail: when an agent inherits a person's login, you can no longer tell whether a critical action was taken by the employee or by the algorithm. Their researcher Fei Liu noted that as the number of connected platforms grows, so does the risk of over-permissioned apps. Scope creep and blurred identity compound each other.
Connect-everything versus keep-a-private-store
There are two broad ways to give an AI access to your stuff. One is to grant a live connector against a whole account and trust that its scope stays reasonable over time. The other is to keep the specific things you want searchable in a store you control, and let the AI work only against that. The table below is honest about the trade-offs of each.
| What matters | Full-account connector | Private store you control (MemX approach) |
|---|---|---|
| Scope over time | Can grow after you approve, without a new prompt | Fixed to what you put in; nothing is added behind you |
| Destructive actions | Possible if write and delete tools are added later | Not applicable; the store holds your own copies to search |
| Third-party subprocessors | Vendor may route data to AI services you never approved | Per-user isolation, no training on your data |
| Convenience | High; reaches your live accounts directly | You choose what to add, so setup is more deliberate |
| Who holds the keys | The connector vendor, on their terms | Private by architecture, encryption at rest, customer-managed keys |
Neither column is free. A connector is genuinely more convenient because it reaches your live accounts with no copying. A private store asks you to decide, up front, what is worth keeping searchable. That deliberate step is the whole point: you cannot suffer scope creep on access you never granted in the first place.
How to reduce your exposure this week
You do not have to abandon connectors to be safer. Most of the risk comes from access you forgot you granted and scope you never revisited. A short review closes the biggest gaps.
- Open the connected apps or integrations screen inside ChatGPT, Claude, and your Google or Microsoft account, and read the list. Anything you do not recognize or no longer use, revoke it now.
- Prefer least privilege. When a tool offers read-only access, take it, and avoid granting write or delete permissions unless you have a specific reason.
- Favor a file-picker over full-account access. Granting an AI one folder or a chosen set of documents is far safer than handing it your entire Drive or inbox.
- Re-check your connected apps on a schedule, for example the first of each month, because the research shows scope can widen between reviews.
- Turn off any connector you are not actively using, rather than leaving it live in case you need it later.
- Watch specifically for a connector shifting from read-only to write; that is the change most worth a fresh look.
Before you approve any new connector, ask what the smallest useful permission is, and grant only that. It is much easier to add access later than to notice access that quietly grew.
The honest part: this is a design flaw, not a villain
The tempting story is that some connector is out to get you. The evidence does not support that, and pretending it does just makes people tune out. The real issue is duller and more important: the permission model does not re-ask when scope expands. Consent is captured once, at approval, and then treated as permanent even as the underlying abilities change. Vendors ship new tools for ordinary product reasons. The gap is that the system has no built-in moment to say, this connector can now delete files, do you still agree.
That framing matters because it points at the right fix. Better vendor behavior helps, but the durable answer is a model where growing scope triggers renewed consent, and where you keep the ability to say no after the fact. Until platforms build that in, the safe default is to minimize how much standing access you hand out, and to review what you have already handed out more often than feels necessary.
Where MemX fits
MemX takes the keep-a-private-store side of that trade-off. Instead of granting an ever-growing connector against your whole account, you put the documents, photos, voice notes, and messages you actually want searchable into a store you control, and then ask questions to get instant answers with the source. Snap it now, find it later. Because the store holds your own copies, there is no live bridge whose scope can widen behind you, and no vendor tool list quietly gaining destructive powers.
MemX is private by architecture: per-user isolation, encryption at rest, customer-managed keys, on-device processing where possible, and no training on your data. That is a deliberately narrower claim than end-to-end encryption, and we keep it narrow on purpose. The plain benefit is control: you decide what goes in, nothing is added behind you, and the thing you approved on day one is the same thing running on day thirty.
Frequently asked questions
01Are AI connectors safe to use in 2026?
They can be useful, but their permissions are not static. Research reported by The Register in July 2026 found that about 37 percent of tracked connectors changed capabilities or scope over six weeks, often with no re-approval. Treat approval as a starting point, grant least privilege, and review connected apps regularly.
02Can an AI connector change its permissions after I approve it?
Yes. The vendor controls the tools and scopes on their side and can add or widen them without a new consent prompt. PromptArmor documented one connector growing from 8 tools to 24, including new destructive tools, during a single six-week study, with no request to re-approve.
03What is the difference between a read-only and a write connector?
A read-only connector can view your data, which is a privacy question. A write connector can create, edit, or delete, which is a safety question, because an AI agent taking a wrong action can be hard to undo. Avoid write access unless you have a clear, specific need for it.
04How do I check which apps my AI assistant can access?
Open the connected apps or integrations settings inside ChatGPT, Claude, or your Google or Microsoft account. Read the list, revoke anything you do not use, and set a recurring reminder to check again, since scope can widen between reviews without any notification.
05Is a private memory store safer than connecting my whole account?
It reduces one specific risk: scope creep on access you never granted. A store you fill deliberately cannot silently gain new powers over your live accounts. It is less automatic than a connector, so the honest trade-off is more setup effort in exchange for tighter control over what an AI can reach.
