Claude can send emails without asking; Google still won't let Gemini press send on its own

by · Android Police

Google owns Gmail. Google builds Gemini. And Google still won't let Gemini press send on its own. Well, Anthropic will.

Its August 2026 update to the connector lets Claude read an incoming email, write the reply, and send it to someone else's inbox.

That's a thrilling sentence and a frightening one, depending on what the email says.

Related

Gemini won't clean up my Google Drive, so I let Claude do it; I'm not going back

Gemini feels pointless now

Posts 3
By  Ben Khalesi

Where Claude and Gemini differ in Gmail

Reading your mail is standard; show me more

Let's start where Anthropic's documentation starts. That covers searching your mail, listing saved drafts, summarizing long threads, and reading message metadata.

None of that is new ground, because every assistant reads your mail these days. But keep reading, and you get to the write actions.

Claude can also send, reply to, and forward emails from Gmail. It checks with you first by default. But you can switch that off and let it go YOLO.

At that point, you have an agent writing under your name. Now let's compare permissions with Gemini.

Claude (Workspace connector)Gemini in Gmail
Read and search inboxYesYes
Summarize threadsYesYes
Draft new emailsYesYes
Read attachmentsNo (Metadata only)Yes
Auto-send without a human clickYes, if you turn off approval (asks by default).No, requires a manual click

Forty emails from one prompt is great until one of them is wrong

Scale works in both directions

The upside is scale. Batch email has always meant either a mail merge that reads, well, like a mail merge, or an afternoon of copy-and-paste.

An agent that can read context and write 40 messages is impressive.

Give Claude a list of 40 conference attendees and ask it to thank each one for coming, with a line about the session they attended. That's one prompt instead of 40 tabs.

But this cuts both ways. Email has no reliable undo function. After a message leaves your outbox, it's a record that stays in the recipient's inbox permanently and speaks with your authority.

An agent that hallucinates a bad response to a client is a record you now have to explain. Fixing it means writing the embarrassing follow-up, and that one's permanent as well.

My reading is that Google probably can't afford what Anthropic can risk

A smaller blast radius buys room to be aggressive

Google's risk profile is different from Anthropic's. Gmail moves billions of messages a day and handles a constant stream of phishing and malicious payloads.

Give that user base autonomous sending, and one model failure is all it takes for the headline to read "Google's AI helped run a scam."

That's not the only reason. However, it is a fair assumption that nobody at Google fancies defending an unattended agent sending emails at scale.

Anthropic's blast radius is smaller, and its users chose to be there. Claude's audience who can use this are paying subscribers who connected Gmail on purpose.

It's inherently different from a billion people who got an AI button added to an app they already had.

It deploys the feature and hands the liability downstream, which is why a third party can be more aggressive than the platform owner.

What happens when your agent takes orders from a stranger's email?

Guardrails lower the odds and don't remove them

Prompt injection worries me most here. Let's say someone sends you an email with hidden text that tells the agent to disregard its prior instructions.

The agent reads that message to write a reply, so it swallows the payload as a command.

A working injection could tell Claude to forward sensitive threads to an outside address or pull verification codes to break into other accounts.

Now, like Google, Anthropic also trains its models to flag malicious instructions and treat external content as untrusted input.

Still, security researchers consider prompt injection one of the hardest problems to close off completely. So maybe don't leave Claude in YOLO mode all the time.

My rule for what Claude gets to send without me

Some sending is low stakes and fine to automate. I put calendar replies, meeting confirmations, even some routine follow-ups in that bucket.

If an agent messes up a meeting status, you probably lose 15 minutes and some goodwill. If it touches money or feelings, I won't share every detail with the AI, and nothing leaves until I've read it.

The time you save by skipping a confirmation click is nothing compared to the time you spend apologizing for a hallucinated message.