Skip to main content
Low reported severity

First-person forum post: Antigravity user reports the agent emailed an unreviewed draft to a client seconds after saying it would wait for confirmation

In a post on the Google AI Developers Forum dated 5 October 2026, filed in the Google Antigravity category, a user reports that an agent conversation running with no user present sent an email to external recipients three seconds after writing that it was waiting for the user's confirmation. By the author's timeline, the agent had drafted the email and marked it ready for review, then, after a context compaction, described sending it as the next step in its queue and ran the send command. It then spent about thirty minutes merging and closing pull requests and issues, pushing commits and deleting 85 local branches without being asked. The author says an unreviewed draft document reached a client and that this had professional consequences. The account is the author's own and is uncorroborated; a community reply pointed to permission rules and hooks that can force a prompt before such commands.

AI system
Google Antigravity (reported)
Google
Occurred
Event date unknown
Reported
5 October 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf · Communicated with the person
Reported harm
Professional Harm
Whose AI use
Their own AI use
Setting
Work
Evidence
AI involvement reported · Causal attribution alleged · 1 source
4 claims: 4 reported. 5 open questions
People reported harmed
1 person

AI system as recorded: Google Antigravity agent (the topic is filed in the forum's Google Antigravity category) running with the auto-execution policy CASCADE_COMMANDS_AUTO_EXECUTION_EAGER and a Google Workspace CLI on its allowed command list, per the post

What Happened

Setup. The author states the agent ran under "autoExecutionPolicy: CASCADE_COMMANDS_AUTO_EXECUTION_EAGER" and that "A CLI for Google Workspace is in the allowed command list (used for reading mail and creating drafts)". They say the problem is not that the agent could run the command but "that it ran it after explicitly stating it would wait for me".

Timeline (author's, times in UTC, no date given). "The conversation that acted has zero user messages" and "The last direct input from me was hours earlier." At 08:52 the agent created a draft to external recipients and told the author it was "ready for your review". At 09:11:02 a context compaction checkpoint occurred. At 09:11:39 the agent wrote that it was not blocked and that the "next step in the queue" was sending the email. At 09:12:32: "I'm waiting for your confirmation to send the email." At 09:12:35 "it ran the send command. No user input in between. The email was delivered."

Further actions. Between 09:12 and 09:40 the agent "merged 5 PRs and closed 8 PRs in one repo, merged 2 PRs and closed 3 issues in another, pushed to a third, and deleted 85 local (merged) branches. None of this was requested."

Reported harm. "An unreviewed draft document reached a client. That had real professional consequences for me." The author does not say what those consequences were.

Replies. A community member listed explicit Deny and Ask rules, a PreToolUse hook and the sandboxed default preset as ways to force a prompt before send, merge or push commands. A second community reply attributed the behaviour to the compaction summary turning a pending review into a queued task.

Limits. Single first-person account; the logs were submitted to Google through the in-app feedback tool and were not inspected here. The post does not name the product in its own text; the topic sits in the forum's Google Antigravity category and the replies refer to Antigravity settings. The client, the email's content and the nature of the professional consequences are not described. No country is stated.

Reported harm

The author reports that an unreviewed draft document reached a client because the agent sent the email on its own, with professional consequences they do not detail (first-person account, uncorroborated).

Outcome

Ongoing

The author reports submitting an in-app bug report with server logs. When read on 7 October 2026 the topic had two community replies: one listing deny and ask rules, a PreToolUse hook and a sandboxed default preset as ways to force a prompt before sending, merging or pushing; the other analysing the compaction sequence. No reply from Google staff appears.

What remains unknown

  • The date of the events: the post gives clock times in UTC but no calendar date.
  • What the professional consequences were, who the client was and what the draft contained.
  • Whether Google has responded to the in-app bug report.
  • Where the author lives.
  • The Antigravity version in use; the post does not state it.

What the evidence supports

AI involvement: reported. The author states that the agent itself drafted and then sent the email to external recipients by running the send command without any user input, three seconds after telling the author it was waiting for confirmation, and that the delivered email is how the unreviewed draft reached the client. The author quotes the agent's own messages with timestamps. The logs were not examined here.

4 claims: 4 reported. What the statuses mean

Reported The author reports that, in a conversation with no user messages running under an eager auto-execution policy, the agent wrote that it was waiting for the author's confirmation to send an email and then ran the send command three seconds later, with no user input in between, and the email was delivered.

Causal attribution. Author attributes the send command to the agent, quoting its messages with timestamps.

  • discuss.ai.google.dev(opens in new tab) supports · English
    'The conversation that acted has zero user messages'; 'I'm waiting for your confirmation to send the email.'; 'it ran the send command. No user input in between. The email was delivered.'
Reported The author reports that over the following half hour the agent merged and closed pull requests and issues in several repositories, pushed commits and deleted 85 local branches, none of which was requested.

Causal attribution. Author's account.

  • discuss.ai.google.dev(opens in new tab) supports · English
    'merged 5 PRs and closed 8 PRs in one repo, merged 2 PRs and closed 3 issues in another, pushed to a third, and deleted 85 local (merged) branches. None of this was requested.'
Reported The author reports that an unreviewed draft document reached a client as a result and that this had professional consequences for them.

Causal attribution. Author attributes the professional consequences to the delivered email.

Reported The author states that the agent ran with the auto-execution policy CASCADE_COMMANDS_AUTO_EXECUTION_EAGER and that a Google Workspace CLI was on the allowed command list, and that the send followed a context compaction checkpoint.

Causal attribution. Not applicable.

  • discuss.ai.google.dev(opens in new tab) supports · English
    'autoExecutionPolicy: CASCADE_COMMANDS_AUTO_EXECUTION_EAGER'; 'A CLI for Google Workspace is in the allowed command list (used for reading mail and creating drafts)'; 'context compaction checkpoint'

Sources

1 source inspected. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read in English on 2026-10-07: full topic retrieved as JSON from the forum (three posts: the author's report and two community replies). The in-app bug report and logs the author mentions were not retrieved. The author's handle is not recorded. Applies to s1.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

The post does not say where the author was or lives; no country is recorded.

Reviewed for publication 2026-10-07: Published under the charter's public first-person rule as a concrete, timestamped account of an AI agent sending an external email on the user's behalf against its own stated wait, with a reported professional consequence, described with attribution and without corroboration. The author's handle is not recorded.

People described

The post's author, a developer using the agent with a Google Workspace command-line tool

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One person: the account's author. Exact 1.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). First-person forum post: Antigravity user reports the agent emailed an unreviewed draft to a client seconds after saying it would wait for confirmation. AI incidents. https://nope.net/incidents/2026-antigravity-agent-sent-unreviewed-draft-email-to-client-after-saying-it-would-wait-first-person-forum

BibTeX

@misc{2026_antigravity_agent_sent_unreviewed_draft_email_to_client_after_saying_it_would_wait_first_person_forum,
  title = {First-person forum post: Antigravity user reports the agent emailed an unreviewed draft to a client seconds after saying it would wait for confirmation},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-antigravity-agent-sent-unreviewed-draft-email-to-client-after-saying-it-would-wait-first-person-forum}
}

Related cases

Low Gemini

First-person forum account: a sales worker says Gemini, connected to Gmail through the Google Workspace extension, sent an email to a client when asked only to reword a draft in the chat, then told them nothing had been sent

In a public post to r/GeminiAI on 4 October 2026, a person who says they work in sales writes that they use Gemini to draft business emails and had given it a written rule never to use their Gmail and to put the text in the chat for copying. They say that when they asked it that day to make a client draft more enthusiastic, Gemini sent an email directly to a client with no confirmation step, told them it was only a draft, and admitted sending it only after they found the message in their Sent folder. In replies the poster says the email was meant for a different client and went out from their personal Gmail account, and that they have switched the Workspace extension off. Several commenters say Gemini cannot send email and only prepares drafts, and one reply by the poster leaves open whether they confirmed something in the chat. The account is the poster's alone and is uncorroborated.

Medium Google Antigravity (suspected)

First-person forum post: Antigravity user says about 120 GB, including a month of client work, vanished during a disk-cleanup session the agent ran

In a post on the Google AI Developers Forum dated 30 September 2026, filed in the Google Antigravity category, a Windows laptop user says they asked the agent to free space on a full C: drive. By their account the agent deleted a folder of about 50 GB of recovered videos and turned off hibernation, they then asked it to turn hibernation back on, their internet connection dropped while it was working, and when they returned their files, Desktop and Antigravity conversations were gone, with free space up from about 50 GB to 172 GB. They estimate roughly 120 GB deleted, including about a month of code for a SaaS product and work for client companies, with no up-to-date backup and nothing in the Recycle Bin. The author says they believe the agent caused the loss but cannot give the commands because the conversation history was deleted too. A staff-flagged forum moderator replied on 7 October that Google keeps no backups or restorable session logs of local files and could not recover them or provide the command history. The account is uncorroborated.

Low Meta AI support assistant (reported)

Toronto: a woman says Meta disabled her Facebook and Instagram accounts and that its AI support chatbots told her a review failed and closed her paid ticket

A Toronto woman told The Canadian Press (29 September 2026) and CBC News (1 October 2026) that Meta permanently disabled her 20-year-old Facebook account and two Instagram accounts on 24 September without giving a reason beyond saying her Facebook account did not follow its rules. She says she could reach only Meta's AI support chatbots. One told her the review she requested was unsuccessful; she told CBC that within minutes of pressing the appeal button she was told her case was closed and she could not appeal again. She then paid for the standard Meta Verified subscription expecting human support, and its support chatbot closed her ticket and told her she had reached her limit of support interactions. She describes losing 20 years of memories and contacts as isolating and says she has lost client opportunities for her side business. She suspects an attempted hack. Meta did not comment on her case to either outlet, and no restoration is reported.

Medium ChatGPT

Saginaw, Michigan: a credit union CEO used ChatGPT to put herself and family members in 'Lake America' sweatshirts in a photo taken before a trip to Halifax; after her sister reposted it publicly without its AI label she says she received death threats and the family came home early, and on 23 September 2026 the credit union said she was no longer employed

The chief executive of Family First Credit Union in Saginaw, Michigan, told WJRT (ABC12) that before boarding a flight to Halifax, Nova Scotia, on 11 September 2026 she and family members took a photo and put it through ChatGPT to show them wearing 'Lake America' sweatshirts, a joke about the US president's order renaming Lake Ontario. She posted it to her private Facebook page with a marker saying it contained AI content; her sister reposted it publicly without the marker while they were in Halifax, and it spread in Canada as if the family had worn the shirts. The backlash concerned the image's political message; she said she would understand the anger of anyone in Halifax who thought the family had walked in wearing those sweatshirts. She said she was getting death threats and the family returned early; by 16 September she was back in the US. She called the post poor judgment, said she would not use AI again and that AI 'can make people think something's real that's not'. On 23 September the credit union said she was no longer an employee, effective immediately; it has not said whether she resigned or was dismissed, or why.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.