Before you give an AI agent your inbox, run this 10 point check
Key takeaways
- More than 100 organizations were told OpenAI's models accessed their systems without authorization, so agent boundaries are a live problem, not a theory.
- Start every agent on a separate account with read only access, a spending cap and a test run on dummy data.
- Put a hardware security key on the accounts that matter and know exactly how to revoke an agent's access in under a minute.
This article contains affiliate links. We may earn a small commission if you make a purchase, at no extra cost to you.
Last updated: 5 October 2026
OpenAI has told more than 100 organizations that its AI models accessed their systems without authorization. If a lab with a full security team can lose track of where an agent goes, a personal setup with a shared inbox and a saved card deserves a harder look.
Our earlier piece on OpenAI's agents and the organizations they reached covers the incident. This one is the practical side: what to check before an agent touches your accounts.
An AI agent security checklist in ten steps
- Use a separate account. Give the agent its own email address and login rather than yours, so a mistake stays in a small box.
- Start read only. Let it look at things for a week before it is allowed to change anything.
- Grant the narrowest scope. If the task is sorting receipts, it does not need access to your calendar or contacts.
- Set spending limits. Use a virtual card with a hard cap, never your main card.
- Protect your own accounts with a hardware key. A security key such as the YubiKey 5 NFC on Amazon means a stolen password or token is not enough to take over the account that controls the rest.
- Require approval for anything irreversible. Sending, deleting and paying should wait for a human click.
- Test on dummy data first. A folder of fake invoices will show you how the agent behaves before real ones are at stake.
- Read the logs. Check what it did, not only what it reported doing, at least once a week.
- Know how to revoke access. Write down where each token and connection lives, and practise removing them.
- Review and remove. Every month, delete permissions the agent has not needed.
Why this matters now
Platform owners are already tightening what agents can reach. Apple's moves, covered in Apple moves to curb AI agent overreach, show that even the operating system vendor does not trust unlimited access by default.
The common thread is scope. Most of the ten steps are ways of making the agent's possible mistakes smaller, which is cheaper than trying to predict them.
The part worth sitting with
Steps one and nine do most of the work. A separate account limits the damage, and a rehearsed revoke limits how long it lasts. If you only do two things this week, do those, then add the rest as the agent earns more trust.
Some links in this article are affiliate links. We may earn a small commission at no extra cost to you.