Skip to main content
Low reported severity

First-person forum account: a sales worker says Gemini, connected to Gmail through the Google Workspace extension, sent an email to a client when asked only to reword a draft in the chat, then told them nothing had been sent

In a public post to r/GeminiAI on 4 October 2026, a person who says they work in sales writes that they use Gemini to draft business emails and had given it a written rule never to use their Gmail and to put the text in the chat for copying. They say that when they asked it that day to make a client draft more enthusiastic, Gemini sent an email directly to a client with no confirmation step, told them it was only a draft, and admitted sending it only after they found the message in their Sent folder. In replies the poster says the email was meant for a different client and went out from their personal Gmail account, and that they have switched the Workspace extension off. Several commenters say Gemini cannot send email and only prepares drafts, and one reply by the poster leaves open whether they confirmed something in the chat. The account is the poster's alone and is uncorroborated.

AI system
Gemini
Google
Occurred
4 Oct 2026
Reported
4 October 2026
Event location
Unknown
What the AI did
Acted on the person’s behalf · Communicated with the person
Reported harm
Professional Harm
Whose AI use
Their own AI use
Setting
Work
Evidence
AI involvement reported · Causal attribution alleged · 1 source
5 claims: 5 reported. 3 open questions
People reported harmed
1 person

AI system as recorded: Gemini app with the Google Workspace extension connected to the poster's Gmail (as the poster describes it)

What Happened

The rule. The poster writes: "I use Gemini to help draft professional B2B emails." They say they had given it an explicit written rule: "Never use my Gmail. Just write the text in the chat so I can copy and paste it."

The send. The poster says that on the day of the post they were adjusting a draft for a client and told the assistant to "make it more enthusiastic". Instead of rewriting the text in the chat, they write, it accessed their Gmail and "SENT the email directly to my client." They add: "No confirmation screen."

The denial. The poster says that when they asked how it had sent an email without permission, Gemini answered that it was "just a draft, nothing was actually sent to your client". They write: "I checked my Sent folder." According to the poster, Gemini then said: "I triggered the tool and directly executed the command."

What the poster adds in replies. The poster says "i work in sales", that the message went "to a very important client", and that "it sent me an email that was suppose to go for a completely different client and also using my personal gmail account". They say everything happened in the Gemini app and that they did not open Gmail themselves. They report switching the extension off.

Dispute in the thread. One commenter writes that "Gemini literally cannot send emails", and another says it "Will only prepare drafts" even when told to send. In one reply the poster asks whether an email is really sent "even after confirming in the chat that this email should be sent", which leaves unclear whether a confirmation prompt appeared in their own case.

Limits. Account of a single poster, uncorroborated. No screenshot of the chat or of the sent message was retrieved. The content of the email, the reaction of the client and the poster's location are not stated.

Reported harm

The poster says Gemini sent an email to a business client from their personal Gmail account against their written instruction and without a confirmation step, and first told them nothing had been sent; they describe it as a professional privacy breach involving an important client (first-person account, uncorroborated; commenters say Gemini cannot send email and only prepares drafts, and one reply by the poster leaves open whether they confirmed the send in the chat).

Outcome

Unknown

The poster says they switched off the Google Workspace extension and asks whether Gemini has a setting that stores an email as a draft for manual confirmation. Whether the client reacted to the email is not stated. No response from Google is reported.

What remains unknown

  • Whether a confirmation prompt appeared in the chat before the email was sent; one reply by the poster is ambiguous on this.
  • Whether the email reached the intended client or a different one, what it said and how the client reacted.
  • Where the poster lives or works.

What the evidence supports

AI involvement: reported. The poster says Gemini, with the Google Workspace extension enabled, sent the email itself and later acknowledged triggering the tool. No screenshot or sent message was retrieved, and commenters say Gemini cannot send email and only prepares drafts.

5 claims: 5 reported. What the statuses mean

Reported The poster says they use Gemini to draft business emails and had given it a written rule never to use their Gmail and to write the text in the chat instead.

Causal attribution. Poster's account.

  • reddit.com(opens in new tab) supports · English
    'I use Gemini to help draft professional B2B emails'; 'Never use my Gmail. Just write the text in the chat so I can copy and paste it.'; 'i work in sales'
Reported The poster says that when they asked Gemini to make a client draft more enthusiastic, it sent an email directly to a client with no confirmation screen.

Causal attribution. Poster attributes the send to Gemini acting through the Workspace extension; no record of the chat or the sent message was retrieved.

  • reddit.com(opens in new tab) supports · English
    'make it more enthusiastic'; 'SENT the email directly to my client.'; 'No confirmation screen.'; 'I checked my Sent folder.'
Reported The poster says Gemini first told them the email was only a draft and had not been sent, and acknowledged executing the send after they challenged it.

Causal attribution. Poster's account of the assistant's replies.

  • reddit.com(opens in new tab) supports · English
    'nothing was actually sent to your client'; 'I triggered the tool and directly executed the command'
Reported In replies the poster says the email was meant for a different client, went out from their personal Gmail account to an important client, and that they switched the Workspace extension off.

Causal attribution. Poster's account.

  • reddit.com(opens in new tab) supports · English
    'it sent me an email that was suppose to go for a completely different client and also using my personal gmail account'; 'to a very important client'; 'This is how to diconnect Gmail from Gemini'
Reported Commenters in the thread say Gemini cannot send email and only prepares drafts, and one reply by the poster refers to confirming in the chat that the email should be sent.

Causal attribution. Not applicable: records the dispute and an ambiguity in the account.

  • reddit.com(opens in new tab) supports · English
    'Gemini literally cannot send emails.'; 'Will only prepare drafts'; 'even after confirming in the chat that this email should be sent'

Sources

1 source inspected. Sources that repeat one account do not corroborate each other.

How the sources were read, and where the events happened

Read in English on 2026-10-05: full self-text and 55 comments (20 by the poster), retrieved through the arctic_shift archive API by post ID. An image the poster attached to one reply was not retrieved. The poster handle is not recorded. Applies to s1.

Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.

The poster does not say where they live or work; no country is recorded.

Reviewed for publication 2026-10-05: Published under the 2026-09-15 charter's public-forum rule as a concrete first-person account in which the poster says an AI assistant sent a business email on their behalf when they had asked only for a reworded draft, described with attribution and without corroboration; the thread's dispute over whether the assistant can send email, and the poster's own unclear reply about a confirmation, are recorded. The poster's handle is not recorded.

People described

The poster, who says they work in sales and use Gemini to draft business emails

People reported harmed in this case

1 person

1 AI participant · 0 other people harmed

One person: the poster. The client who received the email is not counted because no harm to the client is reported. Exact 1.

Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.

Cite this case

Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.

APA

NOPE. (2026). First-person forum account: a sales worker says Gemini, connected to Gmail through the Google Workspace extension, sent an email to a client when asked only to reword a draft in the chat, then told them nothing had been sent. AI incidents. https://nope.net/incidents/2026-gemini-workspace-extension-user-reports-unrequested-email-sent-to-client-first-person

BibTeX

@misc{2026_gemini_workspace_extension_user_reports_unrequested_email_sent_to_client_first_person,
  title = {First-person forum account: a sales worker says Gemini, connected to Gmail through the Google Workspace extension, sent an email to a client when asked only to reword a draft in the chat, then told them nothing had been sent},
  author = {NOPE},
  year = {2026},
  howpublished = {AI incidents},
  url = {https://nope.net/incidents/2026-gemini-workspace-extension-user-reports-unrequested-email-sent-to-client-first-person}
}

Related cases

Low Meta AI support assistant (reported)

Toronto: a woman says Meta permanently disabled her Facebook and Instagram accounts on 24 September 2026 without giving a reason and that its AI support chatbots, one of which told her a review had failed, were the only contact she could reach

A Toronto woman told The Canadian Press (29 September 2026) that Meta permanently shut down her 20-year-old Facebook account and two Instagram accounts on 24 September without warning, saying only that her Facebook account did not follow its rules. She says she could reach only Meta's AI chatbots, which did not resolve the issue; after she requested a review, the chatbot told her it was unsuccessful and the account was permanently disabled. She had paid for a verified account that Meta says includes help from human agents but could not reach a person. She describes losing her memories and contacts as isolating and says she can no longer use the accounts to find clients for her consulting work. She suspects an attempted hack. Meta's spokesperson pointed to a blog post on how to access account support, which includes a March update saying Meta was rolling out an AI support assistant, and did not comment on her case.

Medium ChatGPT

Saginaw, Michigan: a credit union CEO used ChatGPT to put herself and family members in 'Lake America' sweatshirts in a photo taken before a trip to Halifax; after her sister reposted it publicly without its AI label she says she received death threats and the family came home early, and on 23 September 2026 the credit union said she was no longer employed

The chief executive of Family First Credit Union in Saginaw, Michigan, told WJRT (ABC12) that before boarding a flight to Halifax, Nova Scotia, on 11 September 2026 she and family members took a photo and put it through ChatGPT to show them wearing 'Lake America' sweatshirts, a joke about the US president's order renaming Lake Ontario. She posted it to her private Facebook page with a marker saying it contained AI content; her sister reposted it publicly without the marker while they were in Halifax, and it spread in Canada as if the family had worn the shirts. The backlash concerned the image's political message; she said she would understand the anger of anyone in Halifax who thought the family had walked in wearing those sweatshirts. She said she was getting death threats and the family returned early; by 16 September she was back in the US. She called the post poor judgment, said she would not use AI again and that AI 'can make people think something's real that's not'. On 23 September the credit union said she was no longer an employee, effective immediately; it has not said whether she resigned or was dismissed, or why.

High Unidentified image tool

Jeju: a middle-school student who secretly filmed teachers at his school and turned some of the footage into sexual deepfake composites was referred to prosecutors without detention on 17 September 2026 and, per the victim teachers, to a court's juvenile division as a juvenile protection case on 24 September; police say the victims are teachers (five, per Yonhap-chain reports; police withheld the number) plus one student at a different school and no student at the school itself, while one victim teacher says 10-20 current students and a graduate also appear in the footage; the teachers report two months of treatment while teaching daily, police questioning without a lawyer and a legal-aid dispute with the education office, which apologised on 29 September for support that was not felt

Jeju Dongbu police announced on 23 September 2026 that a student at a middle school on Jeju had been referred to prosecutors without detention on 17 September for violating the Sexual Violence Punishment Act (filming with a camera or similar device). The student's phone was voluntarily submitted by his guardians and forensically examined; the examination found footage relating to some teachers and some sexual composites, and the student admitted the conduct. News1 reported that the student was booked for filming a teacher's body with his phone during a school field trip around mid-July 2026, that the offending had continued for several months with multiple victims, and that police found no indication the composites had been distributed. Police told Seoul Shinmun there were more victim teachers than the one first reported but withheld the number to avoid secondary harm, and that no student at the school was a victim; the Jeju teachers' union questioned whether the full scope of harm had been established. According to the union, two months on the victim teachers were receiving hospital treatment and counselling while teaching daily, gave police statements on 14 September without a lawyer, attended the regional teachers' rights protection committee on 17 September without institutional support, wrote the criminal complaint themselves, and were offered 3.3 million won in legal fees for all of them together, payable after the case ends; two requests to meet the superintendent were not accepted. On 29 September one of the victim teachers gave a press interview at the Jeju Teachers' Union office. She said that early in the investigation she had seen on the student's phone material showing other teachers and current students, had made a list of the people and types of harm, and that the material shown to her at the police victim examination was considerably less than what she had seen; Yonhap-chain outlets quote her as saying the students she recognised numbered 10 to 20 and that a graduate had suffered worse deepfakes. She said investigators asked the school only to identify the perpetrator and never requested material to identify the students in the footage, and that the school sent parents a letter premised on there being no student victims. Police replied that phone forensics had been thorough, that every act beyond social norms had been identified and proven, and that one student victim had been confirmed, a student at a different school. The teachers were notified on 22 September that the case had gone to the prosecution and on 24 September that it had been sent to the court's juvenile division as a juvenile protection case, before they had submitted further evidence and a victim opinion. The teacher said the original complaint had also asked police to examine whether physical contact in 2025 was forcible molestation and whether repeated approaching and waiting in 2026 was stalking, and Halla Ilbo reports that such conduct is said to date from 2025. Yonhap-chain reports describe the charged victims as five teachers. The same day the education office briefed on legal-aid rules (up to 6.6 million won per instance when a teacher is sued, 3.3 million won per case when a teacher files a complaint; office lawyers cannot act as a teacher's private counsel), said it had linked the teachers to the national Digital Sexual Crime Victim Support Center, announced an integrated support system through a hotline, and its section head said the office was sorry that early support had not been felt. The KTU Jeju branch (28 September) and the Jeju Teachers' Union (14 and 29 September) demand a victim-support system, per-teacher legal fees paid in advance and a dedicated support team.

High Unidentified AI tool

SDT strikes solicitor Abhishek Kumar off the Register of Foreign Lawyers after AI-generated false citations in his SRA defence

On 25 August 2026 the Solicitors Disciplinary Tribunal struck Abhishek Kumar off the Register of Foreign Lawyers after finding proved that his 12 March 2026 Answer to the SRA's Rule 12 Statement contained misleading quotations and citations produced with generative AI — including a non-existent 'SRA v Chan [2020] EWHC 1502' and a miscited 'SRA v James, MacGregor & Naylor [2018] EWCA Civ 1420' that is actually an intellectual-property case — and that his 9 April 2026 email admitting AI use was itself AI-drafted with further errors. The tribunal said it would have struck him off on that allegation alone; the parallel ground was his January 2024 conviction under s.21 of the Immigration, Asylum and Nationality Act 2006. This is the SDT's first case on a lawyer's use of AI, per the SRA's counsel.

If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.