Before an AI tool can help with your email, calendar, or documents, it may ask you to create an account or connect an existing one. Take a few minutes to check what that connection would allow.
You do not need to understand how machine learning attacks work to make useful security improvements. Start with the accounts you rely on and the access you are about to grant.
Start with your main email account
Your inbox often receives password reset messages for other services, so protecting it deserves priority. The FTC explains why a compromised email account can put other accounts at risk.
Use a strong password that you do not reuse elsewhere. A password manager can generate and store it. Turn on two-factor authentication if available; an authenticator app or security key can provide stronger protection than a code sent by text or email. The FTC’s account security guidance explains these choices.
Open security settings from the service’s known app or website. Do not follow an unexpected “secure your account” message to reach them.
Check how you would regain access
Review your recovery email address and phone number. Make sure they belong to you and are still usable. If the provider supplies recovery codes, follow its instructions for keeping them somewhere secure and accessible if your usual device is unavailable.
Do not paste passwords, verification codes, or recovery codes into an AI chat. An assistant can explain a term such as “two-factor authentication” without seeing any of your secrets.
Install and update through trusted routes
Use the developer’s official website or your device’s app store, and check the developer name before installing. Be cautious about lookalike names and advertisements promising special access to a popular AI tool.
Keep your operating system, browser, apps, and security software updated. Automatic updates are useful where available: updates can include fixes for security weaknesses, as the FTC’s software guidance explains.
If setup instructions unexpectedly ask you to disable security software or paste an unexplained command into your computer, pause and verify the instructions with the actual developer.
Read the permission request
Describe the task you want in one sentence, then compare it with the requested access. For example, drafting a sample reply in a chat does not require permission to send messages from your inbox.
- Which account and data would the tool access?
- Can it only read, or can it also create, change, send, or delete?
- Can you select particular files or a smaller scope?
- Where will you review or remove the connection later?
- Is this a personal account, or does your employer control which tools you may connect?
If the permissions are broader than you are comfortable granting, stop setup and choose a smaller task. A fictional sample may be enough to find out whether the tool is useful.
For Google accounts, the official linked-app management guide explains how to inspect and remove different kinds of connections. Other providers have their own controls. Removing a connection is separate from managing information already held by the other service; check that service’s data controls too.
Give AI a limited helping role
You can ask an assistant to explain permission wording after removing personal details:
Explain this app permission request in plain English. Separate reading information from changing or sending it. List questions I should ask the developer before agreeing. Do not assume the app is safe, and do not ask for my password, codes, or account details.
Compare the explanation with the provider’s documentation. A chatbot cannot certify an app’s security. For a separate check on what information belongs in a prompt, see our AI privacy guide.
If an account may already be compromised
Use the provider’s official recovery process. The FTC’s recovery checklist covers checking device security, changing the password, signing out other sessions, reviewing recovery details and email forwarding, and warning contacts about messages you did not send.
If the concern began with a suspicious message, use our AI scam protection guide to plan an independent check. Do not give a stranger remote access or pay someone who promises to recover the account through unofficial channels.
For today’s first step, check your main email account’s security and recovery settings. You can connect a new AI tool after you understand the permissions it needs.
Reviewed October 2, 2026. Featured photo: Alexander Sinn / Unsplash; illustrative photo.
AI disclosure: This article was drafted and revised using AI. Read our full disclaimer.




Pingback: Plan a Realistic Week With AI