As reported by BleepingComputer, OpenAI briefly surfaced references to an unannounced always-on assistant called "o" — and the details, including an email suffix and persistent background execution, deserve serious security attention even before any official launch.

AI Security Alert: As reported by BleepingComputer, OpenAI briefly surfaced references to an unannounced always-on assistant called "o" — and the details, including an email suffix and persistent background execution, deserve serious security attention even before any official launch.

Why "always-on" changes the threat model

The shift from conversational AI to always-on, agentic AI is not incremental — it's categorical. An interactive chatbot responds to direct prompts and stops when you close the tab. An always-on assistant acts in the background, reads your inbound communications, and executes tasks when you're not watching. That persistence is precisely what makes it useful and precisely what makes it dangerous.

The leaked configuration references — display_name: "o", email_suffix: "-o" — strongly imply that this assistant will have its own email identity and the ability to send, receive, or triage mail on the user's behalf. That means one of two things: either "o" holds delegated access to the user's mailbox (OAuth scopes on Gmail, Microsoft Graph, or similar), or it operates its own mailbox that forwards into the user's workflow. Both models expand the attack surface significantly.

Three risk vectors defenders should track now

Why "always-on" changes the threat model
Prompt injection at scale. Email is the largest untrusted-input channel most humans touch. An always-on assistant that ingests email will parse attacker-controlled content. A well-crafted message could instruct the assistant to exfiltrate data, reply to threads, or trigger downstream actions. This is the OWASP LLM01 problem applied to a live inbox.
Autonomous actions without oversight. "Always-on" implies the model takes initiative. If it can reply to email, it can also misreply, forward sensitive threads, or interact with third-party SaaS integrations. Without fine-grained approval gates, a single bad inference becomes an outbound action.
Identity confusion. Recipients see mail from "user-o" or similar. That blurs the line between human-sent and assistant-sent communication, creating ideal conditions for social engineering — both against the user's contacts and against the user themselves.

Who is exposed

The feature was surfaced under the $100 ChatGPT Pro plan — OpenAI's highest consumer tier, and one that over-indexes toward power users, founders, and professionals who route work email through AI. If "o" ships with mailbox integration, the exposed population is effectively knowledge workers who already trust AI with their most sensitive channel. Enterprise customers should be even more concerned: if "o" inherits any of the Aeon-style custom-agent functionality referenced internally, corporate mailboxes become the new perimeter.

Shield53 Recommendations

  • Scope mailbox delegation tightly. If you adopt this, grant the assistant read-only or triage-only scopes — never full send-as. Use Microsoft Graph or Gmail API application-specific restrictions rather than blanket delegated permissions.
  • Require human approval for outbound actions. Reply, forward, and calendar actions must hit an approval queue. "Always-on" should not mean "always-autonomous."
  • Log every action the assistant takes. Persist a tamper-evident audit trail of messages read, drafted, and sent. Assume you'll need it for incident response and eDiscovery.
  • Treat every inbound email as untrusted input to an LLM. Deploy prompt-injection detection on content before it reaches the assistant. The cost of a single malicious email triggering an autonomous action is far higher than the cost of queueing it.
  • Block "o" at the identity layer until governance is ready. For managed tenants, deny the email suffix or delegated scopes at the IdP until your DLP, mail-gateway, and AI-usage policies are updated.
The industry is racing toward agentic AI that acts on our behalf. Security teams need to be racing equally hard toward agentic governance — because the gap between capability and control is where breaches live.