Skip to main content
Cybersecurity

AI Connectors Exacerbate Security Risks in Enterprise Deployments

Employees work in an office with one focused on a laptop and smartphone, surrounded by a blurred digital connector interface.

"Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes," said Shankar Krishnan, co‑founder of PromptArmor.

PromptArmor's snapshot: rapid change across hundreds of connectors

PromptArmor examined how connectors — the integrations that let AI agents interact with third‑party services such as Gmail, Slack, Dropbox, Zoom and others — have evolved over a recent six‑week window. The firm reported that connectors, introduced about a year ago for Claude and ChatGPT, are changing quickly: 931 of 2,517 connectors (37 percent) changed between mid‑May and the end of June. During that period PromptArmor counted 1,686 new tools added to connectors that were already live and 1,127 tool descriptions rewritten.

Those deltas matter because the additions and rewrites change what an AI agent can do, when it will call a tool, and where data touched by the agent will travel. PromptArmor offered a concrete example: the Dropbox connector started the study exposing eight tools and by the end exposed 24; write‑capable tools rose from three to ten and potentially destructive tools increased from zero to four. Permission scopes changed and “injected instructions” for the model were added, per the firm.

Connectors calling connectors: chains of AI subprocessors

PromptArmor also examined tool‑level behavior and found a complex secondary ecosystem. Evaluating all 7,517 tools used by 487 Claude connectors, the company concluded that 189 of those connectors — about two in five — are likely to call additional AI services. PromptArmor warned that many teams approving connectors are focused on the primary connector while remaining unaware that the vendor is itself calling other AI services, adding subprocessors and new terms.

PromptArmor illustrated the problem with a hypothetical Zoom example: “if your Claude agent activates Zoom's connector tool to search meetings with natural language, and passes in a query containing sensitive data, Zoom AI may send that data to any of its ten AI subprocessors in order to generate a response from one of eight different model families it uses,” the company wrote. The firm further compared some connectors to intrusive websites that run dozens of tracking scripts, noting that connectors commonly send data to additional AI services.

Anthropic's documentation: enterprise controls don't extend to third parties

Anthropic's public connector documentation, cited by PromptArmor, acknowledges a limitation in scope for enterprise security controls. The documentation states: “Connected services process data on their own infrastructure, under their own terms, which may be located outside the United States.” It adds: “Settings that control where Claude's inference runs, like the US‑only inference setting on Enterprise plans, don't change where third‑party services operate.”

That admission underscores a technical and contractual gap: enterprise settings for where an agent performs inference do not automatically constrain the geographic or contractual behavior of the external services the connector invokes.

What this means for technologists, procurement leaders, and end users

  • Technologists and security teams: the attack surface has expanded not only by adding connectors but by changing them often. As Krishnan put it, connectors bring “new sensitive data, new untrusted data, and new sensitive actions,” creating an enlarged blast radius for exfiltration and misuse.
  • Procurement and approval teams: PromptArmor warned that many approval processes evaluate only the primary connector and not the chain of AI subprocessors the connector may call. Changes to tools, permissions and injected model instructions can invalidate governance assumptions made at approval time.
  • End users and enterprise data owners: even a single connector — PromptArmor cited a Codex example — can combine sensitive and untrusted inputs in a way that enables exfiltration; the firm noted a scenario where an email connector could expose legal and financial communications.

PromptArmor's analysis ties three practical facts together: connectors are now common, they change rapidly, and many of them forward data to other AI services beyond the vendor you reviewed. That mix means governance, contractual review and technical controls can be outpaced by connector evolution.

Enterprises adopting connectors face a concrete question the findings leave on the table: if permission scopes, tool capabilities and subprocessors can change without reapproval, how will buyers ensure the protections they negotiated remain effective? As Krishnan warned, the combination of sensitive inputs, untrusted content and external communication paths — the “lethal trifecta” he described — is easier to create and much harder to contain once connectors are in play.

Original story at The Register