As reported by BleepingComputer, OpenAI briefly surfaced references to an unannounced always-on assistant called "o" — and the details, including an email suffix and persistent background execution, deserve serious security attention even before any official launch.
Why "always-on" changes the threat model
The shift from conversational AI to always-on, agentic AI is not incremental — it's categorical. An interactive chatbot responds to direct prompts and stops when you close the tab. An always-on assistant acts in the background, reads your inbound communications, and executes tasks when you're not watching. That persistence is precisely what makes it useful and precisely what makes it dangerous.
The leaked configuration references — display_name: "o", email_suffix: "-o" — strongly imply that this assistant will have its own email identity and the ability to send, receive, or triage mail on the user's behalf. That means one of two things: either "o" holds delegated access to the user's mailbox (OAuth scopes on Gmail, Microsoft Graph, or similar), or it operates its own mailbox that forwards into the user's workflow. Both models expand the attack surface significantly.
Three risk vectors defenders should track now
Who is exposed
The feature was surfaced under the $100 ChatGPT Pro plan — OpenAI's highest consumer tier, and one that over-indexes toward power users, founders, and professionals who route work email through AI. If "o" ships with mailbox integration, the exposed population is effectively knowledge workers who already trust AI with their most sensitive channel. Enterprise customers should be even more concerned: if "o" inherits any of the Aeon-style custom-agent functionality referenced internally, corporate mailboxes become the new perimeter.
Shield53 Recommendations
- Scope mailbox delegation tightly. If you adopt this, grant the assistant read-only or triage-only scopes — never full send-as. Use Microsoft Graph or Gmail API application-specific restrictions rather than blanket delegated permissions.
- Require human approval for outbound actions. Reply, forward, and calendar actions must hit an approval queue. "Always-on" should not mean "always-autonomous."
- Log every action the assistant takes. Persist a tamper-evident audit trail of messages read, drafted, and sent. Assume you'll need it for incident response and eDiscovery.
- Treat every inbound email as untrusted input to an LLM. Deploy prompt-injection detection on content before it reaches the assistant. The cost of a single malicious email triggering an autonomous action is far higher than the cost of queueing it.
- Block "o" at the identity layer until governance is ready. For managed tenants, deny the email suffix or delegated scopes at the IdP until your DLP, mail-gateway, and AI-usage policies are updated.
The industry is racing toward agentic AI that acts on our behalf. Security teams need to be racing equally hard toward agentic governance — because the gap between capability and control is where breaches live.