Vendors Shipped The Send Button And Skipped The Receipt
Gmail sends, live-database access and per-action pricing have all shipped; the audit trail, recall window and permission matrix that clear a security review did not.
The toggle is the whole story
A user approves an agent-drafted email, approves another, then goes looking for the setting that stops the asking. Claude requires approval by default before an email goes out, lets her switch off repeated approval prompts, and on Team and Enterprise plans lets a workspace owner decide whether members may switch them off at all. Per Simplifying AI, that owner-level gate is the smartest thing in the release. As a baseline it is. As a ceiling it fails, because a default users are invited to disable is a default that gets disabled, usually by the heaviest users with the most sensitive threads. Perplexity shipped the same capability with no guardrail described at all: anyone can send, forward or cc [email protected] to launch a job that runs as a normal session.
Separate what was pitched from what it does. An agent that reads an inbox, holds forward authority, and can have confirmations turned off is a data-exfiltration path that needs exactly one crafted inbound email. Anthropic's release describes no recall window, no per-recipient scoping, no injection handling for untrusted inbound content. Email is irreversible. Nobody shipped the recovery layer.
The same pattern one layer down
MongoDB's Atlas Managed MCP Server, deliberately agent-neutral, gives Claude Code, Codex, xAI's Grok Build and Cognition's Devin direct access to live application data through one managed endpoint, per Computerworld. Authority at the data layer, controls left to whoever integrates it. Computerworld and CSO independently reported the same public criticism of OpenAI's president's agentic-AI post: analysts and consultants said it was most notable for omitting what to do when agents go rogue and how to control agent actions. Two outlets on the same omission is a positioning lane, not gossip.
Every vendor here shipped the power to act. None shipped the power to take it back.
Why authority shipped first
The pricing explains the sequencing. Gmail send, reply and forward are gated to all paid Claude plans, and Cowork's full mobile and web rollout is paid-only. Generation is the free-tier bait; agency is the upsell. Techpresso ties Anthropic's quarter to Claude Code and higher earnings per use. Buyers pay for work that completes, which a budget owner can read in a way a token quota never could. One verification note before anyone cites it: the widely repeated $65B annualized run-rate claim does not reconcile cleanly with an $11.6B quarter and is reported at low confidence. Cite the quarter, not the run rate.
The counter-position nobody has claimed
Three questions decide every enterprise security review of an acting agent, and no vendor above answers them:
- What did it do? No audit trail described.
- Can we take it back? No undo, no recall window, no misdirected-send recovery.
- Who authorized it? Approval is a toggle, not a logged decision with an actor attached.
None of that needs a frontier model: an immutable per-action log, a 30-to-120-second hold-and-release queue on irreversible operations, per-role action-class permissions with an owner override, injection-resistant handling of untrusted input. The same audit applies to existing write paths. Claude's Drive save handles text but not images embedded in documents, a silent fidelity loss users find at the worst possible moment. That quiet defect class is what a competitor's demo finds first.
What to do
Spec an Action Ledger into the current agent epic this sprint: immutable per-action log capturing what, when, on whose authority and with what inputs, plus a 30-to-120-second hold-and-release queue on irreversible actions.
Run a prompt-injection red-team this sprint on every surface where untrusted inbound content can reach an agent holding send, forward or write authority, using 'agent forwards a confidential thread to an attacker' as the primary test case.
Write the admin permission matrix before enterprise GA this quarter: which roles may auto-execute which action classes, with an owner-level override on skip-approval.