OpenAI is quietly preparing a new always-on ChatGPT assistant internally codenamed "o" — and references to the unannounced feature briefly appeared on the company's public website before being pulled, as reported by BleepingComputer. The most consequential detail for defenders: this assistant is designed to be persistent and capable of handling email on a user's behalf.
If you have spent any time in a SOC over the past 18 months, you already know where this goes. An always-on agent with delegated access to a user's mailbox collapses three of the hardest problems in enterprise security into one attack surface: indirect prompt injection, over-privileged OAuth delegation, and unsanctioned shadow AI adoption. There is no CVE here — this is not a patch-and-move-on event. This is an architectural risk that will land in your environment the moment a curious employee connects the assistant to their corporate Microsoft 365 or Google Workspace account, whether your CISO approved it or not.
Every enterprise defender should treat this announcement the same way we learned to treat the rollout of any new OAuth-connected SaaS: assume employees will enable it, assume attackers will probe it, and build detection coverage now — before general availability, not after the first incident.
Technical Analysis
What "o" appears to be
Based on the details exposed on OpenAI's website, "o" is positioned as an ambient, always-on assistant rather than a session-based chatbot. Key characteristics with direct security implications:
- Persistent operation: The assistant runs continuously rather than only when invoked, meaning it maintains standing access to connected data sources.
- Email handling: The assistant is designed to read, triage, and potentially act on email — which means it will require delegated mailbox permissions (OAuth scopes such as
Mail.Read,Mail.ReadWrite,Mail.Send, or Gmail equivalents) against the user's identity. - Agentic behavior: Handling email implies the assistant doesn't just summarize — it takes actions (drafting, replying, filing, possibly clicking links or extracting content), which is precisely the behavior class vulnerable to indirect prompt injection.
The attack chain defenders need to model
There is no software vulnerability to scan for. The risk is a technique chain that red teams have been demonstrating against LLM agents with tool access throughout 2025 and into 2026:
- Delivery: An attacker sends a crafted email to a target user whose mailbox is connected to the assistant. The email contains embedded instructions — visible text, hidden HTML, white-on-white content, or payload in attachments/calendar invites.
- Ingestion: The always-on assistant processes the mailbox in the background and ingests the malicious content as part of its context.
- Injection: The embedded instructions hijack the agent's task (indirect prompt injection, MITRE ATLAS AML.T0051). The agent now treats attacker-controlled text as operator intent.
- Action/exfiltration: Using its legitimate, user-granted permissions, the agent forwards sensitive threads, creates inbox rules, sends mail as the user, or summarizes and exfiltrates data to an attacker-controlled endpoint. Critically, every action is performed with valid OAuth tokens and valid user identity — there is no exploit, no malware, and no anomalous logon to alert on.
This maps to MITRE ATT&CK techniques defenders already track: T1550.001 (Use Alternate Authentication Material: Web Session Cookie/token reuse patterns), T1098.002 (Additional Email Delegate Permissions), T1114.003 (Email Forwarding Rule), and T1528 (Steal Application Access Token) — plus ATLAS techniques for prompt injection.
Exploitation status
- Product status: Unannounced/in testing. References appeared briefly on OpenAI's site and were removed. No CVEs are associated with this story.
- Threat status: Indirect prompt injection against email-connected AI agents is a demonstrated, repeatable technique in current research and red team engagements — not theoretical. Illicit consent-grant phishing (OAuth abuse) has been actively exploited in the wild for years and remains the primary delivery mechanism for standing mailbox access.
- Bottom line: You cannot patch this. You can only govern, detect, and constrain it.
Detection & Response
The detections below target the observable behaviors that matter regardless of which AI assistant an employee connects: new OAuth consent grants with mail scopes, anomalous service-principal mailbox access, inbox rule creation, and AI client software on endpoints. These are deliberately scoped to fire on high-signal events, not every chatbot session.
SIGMA Rules
---
title: OAuth Consent Grant With High-Risk Mail Scopes
id: 3f8a2c71-6b4d-4e9a-b1c7-2d5e9f0a8b3c
status: experimental
description: Detects user or admin consent grants to applications requesting delegated mailbox permissions, a prerequisite for AI assistants (e.g., always-on agents) accessing corporate email and a common consent-phishing indicator.
references:
- https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-o-an-always-on-chatgpt-assistant-that-could-handle-email/
- https://attack.mitre.org/techniques/T1550/001/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.credential_access
- attack.t1550.001
- attack.persistence
logsource:
product: azure
service: auditlogs
detection:
selection_operation:
OperationName:
- 'Consent to application'
- 'Add OAuth2PermissionGrant'
- 'Add delegated permission grant'
selection_scope:
TargetResources|contains:
- 'Mail.Read'
- 'Mail.ReadWrite'
- 'Mail.Send'
- 'MailboxSettings'
- 'full_access_as_app'
- 'offline_access'
condition: selection_operation and selection_scope
falsepositives:
- Approved enterprise applications with documented mail integration (maintain an allowlist of sanctioned app IDs)
level: high
---
title: Inbox Rule Creation Forwarding or Deleting Mail
id: 8c1d4e92-7a5f-4b3c-9d2e-6f1a0b8c5d4e
status: experimental
description: Detects creation of inbox rules that forward, redirect, or delete messages. A frequent objective of attackers and a plausible action of a prompt-injected AI email assistant acting on a compromised user's behalf.
references:
- https://attack.mitre.org/techniques/T1114/003/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.collection
- attack.t1114.003
- attack.exfiltration
logsource:
product: m365
service: exchange
detection:
selection:
Operation:
- 'New-InboxRule'
- 'Set-InboxRule'
selection_action:
Parameters|contains:
- 'ForwardTo'
- 'ForwardAsAttachmentTo'
- 'RedirectTo'
- 'DeleteMessage'
condition: selection and selection_action
falsepositives:
- Users creating legitimate forwarding rules to personal addresses (still a policy violation in most orgs)
level: high
---
title: AI Desktop Client Execution on Managed Endpoints
id: 5e2b7d14-9c3a-4f8e-a6b1-0d4c7e2f9a1b
status: experimental
description: Detects execution of AI assistant desktop clients on managed endpoints to support shadow-AI discovery and enforce acceptable-use policy before connectors are authorized.
references:
- https://atlas.mitre.org/techniques/AML.T0051/
author: Security Arsenal
date: 2026/01/15
tags:
- attack.execution
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- '\ChatGPT.exe'
- '\OpenAI.exe'
- '\Claude.exe'
- '\Copilot.exe'
OriginalFileName|contains:
- 'ChatGPT'
- 'OpenAI'
condition: selection
falsepositives:
- Sanctioned AI tooling in approved business units — tune to alert only outside allowlisted OUs/devices
level: low
KQL — Microsoft Sentinel / Defender
// Hunt 1: New OAuth consent grants with mail-capable scopes (Entra ID AuditLogs)
AuditLog
| where TimeGenerated > ago(14d)
| where OperationName in ("Consent to application", "Add OAuth2PermissionGrant", "Add delegated permission grant")
| mv-expand TargetResources
| mv-expand TargetResources.modifiedProperties
| where tostring(TargetResources_modifiedProperties.newValue) has_any ("Mail.Read", "Mail.ReadWrite", "Mail.Send", "MailboxSettings", "full_access_as_app")
| extend AppId = tostring(TargetResources.id)
| extend ConsentUser = tostring(InitiatedBy.user.userPrincipalName)
| project TimeGenerated, OperationName, ConsentUser, AppId, TargetResources.displayName, CorrelationId
| order by TimeGenerated desc
;
// Hunt 2: Inbox rules forwarding externally or deleting mail (Office 365 audit)
OfficeActivity
| where TimeGenerated > ago(14d)
| where Operation in ("New-InboxRule", "Set-InboxRule")
| extend Params = tostring(parse_json(Parameters))
| where Params has_any ("ForwardTo", "ForwardAsAttachmentTo", "RedirectTo", "DeleteMessage")
| project TimeGenerated, UserId, Operation, Params, ClientIP, ClientInfoString
| order by TimeGenerated desc
;
// Hunt 3: Mail access by non-interactive / unfamiliar service principals (anomalous item access)
OfficeActivity
| where TimeGenerated > ago(7d)
| where Operation in ("MailItemsAccessed", "Send")
| where ClientInfoString has_any ("Client=WebServices", "REST", "Graph")
| summarize AccessCount = count(), DistinctIPs = dcount(ClientIP) by UserId, ClientInfoString, ClientIP, bin(TimeGenerated, 1h)
| where AccessCount > 500
| order by AccessCount desc
;
// Hunt 4: AI assistant desktop clients in the fleet (Defender)
DeviceProcessEvents
| where TimeGenerated > ago(30d)
| where FileName has_any ("ChatGPT", "OpenAI", "Claude") or ProcessCommandLine has_any ("chat.openai", "chatgpt")
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), Runs = count() by DeviceName, FileName, FolderPath, AccountName
| order by FirstSeen desc
Velociraptor VQL
-- Hunt: AI assistant clients and persistence artifacts on endpoints
-- Identifies installed AI desktop clients, their persistence mechanisms,
-- and outbound connections to AI provider endpoints for shadow-AI discovery.
SELECT Pid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Exe =~ '(?i)(chatgpt|openai|claude)'
OR CommandLine =~ '(?i)(chat\.openai|chatgpt)'
-- Enumerate Run-key persistence referencing AI clients
SELECT Name, FullPath AS Value, ModTime
FROM glob(globs='HKEY_USERS/*/Software/Microsoft/Windows/CurrentVersion/Run/*',
accessor='raw_registry')
WHERE FullPath =~ '(?i)(chatgpt|openai|claude)'
-- Active connections to common AI provider infrastructure
SELECT Pid, Name, RemoteIP, RemotePort, Status
FROM netstat()
WHERE Status =~ 'ESTAB'
AND Name =~ '(?i)(chatgpt|openai|claude)'
Remediation / Hardening Script
# Audit and constrain AI assistant access to Microsoft 365 mailboxes
# Requires: Microsoft.Graph PowerShell SDK, Global Admin or Cloud App Admin
# Run Connect-MgGraph -Scopes "Application.Read.All","Policy.ReadWrite.PermissionGrant","Mail.Read"
# 1. Inventory all delegated permission grants with mail-capable scopes
$ riskyScopes = 'Mail.Read','Mail.ReadWrite','Mail.Send','MailboxSettings.ReadWrite','full_access_as_app'
Get-MgOauth2PermissionGrant -All | ForEach-Object {
$grant = $_
$granted = $grant.Scope -split ' '
if ($granted | Where-Object { $riskyScopes -contains $_ }) {
$sp = Get-MgServicePrincipal -ServicePrincipalId $grant.ClientId
[PSCustomObject]@{
AppName = $sp.DisplayName
AppId = $sp.AppId
ConsentType = $grant.ConsentType
Principal = $grant.PrincipalId
Scopes = $grant.Scope
}
}
} | Format-Table -AutoSize
# 2. Disable end-user self-service consent (force admin approval workflow)
$params = @{ defaultUserRolePermissions = @{ permissionGrantPoliciesAssigned = @() } }
Update-MgPolicyAuthorizationPolicy -BodyParameter $params
# 3. Enable the Admin Consent Request workflow so requests route to reviewers
# (Configure in Entra portal: Identity > Applications > Enterprise applications >
# Consent and permissions > Admin consent settings > Users can request admin consent = Yes)
# 4. Audit inbox rules across all mailboxes for forwarding/deletion actions
Get-Mailbox -ResultSize Unlimited | ForEach-Object {
Get-InboxRule -Mailbox $_.UserPrincipalName -ErrorAction SilentlyContinue |
Where-Object { $_.ForwardTo -or $_.ForwardAsAttachmentTo -or $_.RedirectTo -or $_.DeleteMessage } |
Select-Object @{n='Mailbox';e={$_.MailboxOwnerId}}, Name, ForwardTo, RedirectTo, DeleteMessage
}
# 5. Block external auto-forwarding at the transport layer (defense-in-depth)
Set-HostedOutboundSpamFilterPolicy -Identity Default -AutoForwardingMode Off
Remediation
There is no patch because there is no vulnerability — the remediation here is governance and control-plane hardening before this assistant reaches general availability:
- Get ahead of shadow adoption now. Employees will connect "o" (and its competitors) to corporate mail the day it ships. Publish an explicit AI-assistant acceptable-use policy and communicate which, if any, agents are sanctioned for corporate data.
- Disable user self-service OAuth consent in Entra ID and Google Workspace. Route all consent requests through an admin approval workflow, and auto-block any application requesting
Mail.*scopes that isn't on your approved inventory. This single control neutralizes both consent phishing and unsanctioned AI connectors. - Inventory existing grants. Run the audit script above (or the Workspace equivalent) today. Revoke grants for applications your organization has never reviewed, prioritizing anything with
Mail.ReadWrite,Mail.Send, oroffline_access. - Constrain the agent's blast radius if you do sanction one: require a dedicated service account rather than per-user mailbox delegation, scope it to a subset of folders, and disable send capability unless there is a documented business need.
- Enforce DLP and egress controls on AI provider domains and API endpoints. Monitor for bulk
MailItemsAccessedvia Graph/REST (Hunt 3 above) — an agent summarizing hundreds of messages per hour from an unfamiliar ASN is your earliest exfiltration signal. - Treat agent output as untrusted input. If the assistant drafts or sends replies, require human-in-the-loop confirmation for any outbound mail containing attachments, links, or messages to external recipients. Prompt-injected agents are at their most dangerous when allowed to act autonomously.
- Update your IR playbooks. Add an "AI agent compromise" scenario: revocation of OAuth grants, audit of
MailItemsAccessedduring the exposure window, inbox rule sweep, and forced token revocation (revoke sign-in sessions for the affected principal). Exercise it in a tabletop before you need it. - Track the vendor disclosure. Monitor OpenAI's security and trust documentation for the permission model, data retention, and admin controls "o" will support — those details will determine whether enterprise-sanctioned deployment is ever defensible.
The assistants are coming whether security is invited or not. The organizations that fare best will be the ones whose consent workflows, mailbox telemetry, and DLP controls were already in place when the first employee clicked "Allow."
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.