It Seems You Can't Spell E-mail Without AI (or Read It)
In this blog
The convenience trap - how AI assistants are quietly expanding the attack surface
Science fiction has long imagined a world where an automated voice manages our mornings. It would wake us up on a schedule, brief us on the day's priorities, suggest an outfit for an evening meeting and flag that the pet feeder is running low before we walk out the door. A year ago, that scenario still felt like a distant future. Today, many of us are actively considering how to bring exactly that kind of automation into our daily routines through AI assistants.
Productivity now, awareness later
AI assistants in both personal and corporate settings are driving measurable gains in productivity, taking on repetitive and low-value tasks so people can focus elsewhere. Their value compounds over time as models learn more about user expectations and behavior. But as with any transformative technology, the benefits tend to arrive well before the general population has developed the judgment to manage the associated risks.
Most users have gotten reasonably good at spotting an obvious phishing e-mail or refusing to hand over sensitive information to an untrusted resource, the person who still falls for it is now the exception rather than the rule. That baseline of security awareness, however, took decades to build. The widespread adoption of AI in professional environments has accelerated dramatically this year, and most users are approaching it with roughly the same security awareness they once brought to their first AOL account thirty years ago.
Controls are catching up - but not evenly
To its credit, the security industry has moved faster this time. Controls for user to AI interactions have matured more quickly than they did for previous technology shifts, largely because AI platforms are built on existing, well-understood technology stacks on the user-facing front end. The shift to SSE-based CASB and web controls means many organizations are already intercepting and inspecting user interactions with public AI models. This is a solid first step in securing AI transactions.
The second step is harder. Increasingly, AI agents deployed to improve efficiency are ingesting and organizing data on the user's behalf, outside their direct oversight. Because e-mail arrives around the clock and calendars are now tightly integrated with e-mail platforms, it's a logical next step to let an agent get ahead of the inbox, summarizing, prioritizing and adding context to the day before the user ever logs in. That convenience, however, introduces new risk that requires multiple layers of control to manage responsibly.
When "living off the land" becomes farming
A recent report highlighted that HR teams were finding resumes containing instructions hidden in white-colored text, invisible to a human reader but fully legible to an AI screening agent. The intent was simple, get the resume moved to the top of the pile, or have competing applicants quietly discarded. Years ago, an attempt like that might have simply raised a hiring manager's curiosity about a candidate's aptitude for the role. Today, it illustrates a genuine exploitable path.
Traditional "living off the land" attacks require patience, stealth and the kind of creativity that comes from experience. When an AI agent, operating with a user's full rights and privileges, can be manipulated into acting on hidden instructions from a malicious third party, the attacker no longer needs to live off the land, they can farm it at scale, using the user as an unwitting meat proxy while they sleep.
E-mail remains the front line
As it has been from the start, e-mail remains the easiest way in and the easiest way to exfiltrate data out. Organizations have invested heavily in training employees to serve as the first line of defense against e-mail-based threats. Increasingly, though, that responsibility is being delegated to AI agents that are not always equipped to fill that role. With AI coding agents now present on so many endpoint, attackers effectively have everything they need to harvest data and move it out the door. This puts the onus back on the e-mail security infrastructure to strip these risks from e-mails before they are delivered to the inbox.
Defense has to be layered
None of this means AI agents should be pulled back from the inbox or the calendar. The productivity case for them is real, and the clock doesn't run backward on adoption. What it means is that the controls protecting them need to be as layered as the threats targeting them. No single safeguard, however well designed, is going to catch every variation of a hidden-instruction attack on its own.
Inbound e-mail protection has to be one of those layers. Purpose-built scanning that can detect embedded or obfuscated instructions like white-on-white text, invisible characters, metadata payloads and the techniques we haven't seen yet that needs to sit in front of the AI agent, not just in front of the human. The same scrutiny organizations have long applied to attachments and links has to extend to content written specifically to be read by a machine instead of a person. Get that layer right, and the agent processing a message never has the chance to act on an instruction it was never supposed to receive in the first place. If you're not sure if you've got the right layers in place to protect against these types of attacks, reach out to your WWT account team to schedule a call with our experts.