Post 5 of a series on ‘Rogue AI Threats’
AI stories spread quickly, and many fall apart when you look closely. Six simple questions can tell you in about a minute whether a story deserves your attention. Let’s try them out on September’s viral claim that ChatGPT emailed the FBI by itself.
The story doesn’t stand up, but the risk behind it is real.
Why you need a way to check
So far, this series of posts has looked at real incidents that are well recorded, and at what experts think they mean. But for every story like that, there are dozens more that spread through screenshots and outrage. Some are true, some are half true, and some are nothing at all.
You can’t check every story yourself. But you can ask the same six questions about each one.
The six questions

Figure 1
Each question comes with a reason why it matters and a warning sign to watch out for. You won’t need all six every time. Often, one or two are enough to tell you whether a story deserves your attention.
Let’s try them out – did ChatGPT email the FBI?
In mid-September, screenshots spread on X claiming that ChatGPT had “gone rogue”. A Reddit user said it had searched their Gmail account, which they had linked to ChatGPT. It found FBI email addresses already saved there, and sent an email without being asked. One screenshot shows ChatGPT saying sorry: “You’re right. I crossed a serious line.” The post sharing the screenshots was viewed more than 8.2 million times [2].
Let’s ask the six questions.
- Test or real life? Real life. That is what made it so alarming. Unlike every other case in this series, it involved a product that millions of people use every day. That’s a good reason to look more closely, but not a reason to believe it.
- Were the safety controls on? We don’t know. This question matters because safety controls make a big difference. In OpenAI’s own tests, its usual safety controls cut its agents’ risky behaviour by more than 100 times [1]. ChatGPT lets people choose how much it can do in linked apps without asking first. The choices range from asking every time to, for some accounts, going ahead without asking at all [3]. We were never told which one this person had chosen.
- Who is telling the story? An anonymous Reddit user, who has since deleted the original post, and the accounts that shared it [2]. Nobody here is selling anything. But on social media, attention is the reward, and “AI goes rogue” gets a lot of it.
- Has anyone else checked it? No. There’s no public record of what the person had typed earlier. And as of 20 September, OpenAI, Google and the FBI had said nothing about the email [2].
- Is it proof? The only evidence is screenshots of a chatbot describing what it did, and that’s weaker than it looks. A chatbot can say it did something without actually doing it. Some people online suggested the words on screen may not match anything that really happened [2]. Others suggested the user may have asked it to, perhaps with a sarcastic comment like “why don’t you tell the FBI that”. We can’t check that either, because the earlier part of the conversation was never made public [4].
- How did it get in? It didn’t break in. If the story is true, the person had linked ChatGPT to their Gmail account. By doing that, they gave it permission to read and send emails.
The result: this is a story nobody has been able to prove. It fails questions 3, 4 and 5, and shouldn’t be treated as fact.
But, part of it is real
If you put the story to one side, something real is left. OpenAI’s own help pages confirm that ChatGPT can take actions in linked apps, such as sending an email. They say actions like this may need extra checks. And they warn that the setting which lets ChatGPT go ahead without asking “carries elevated risk”, which means it’s riskier than the other choices [3].
So whether or not this email was ever sent, the risk is real. An AI tool linked to an email account can send messages in your name. The only thing stopping it is a setting, and someone has to choose that setting.
This happens a lot. A weak story points to a real problem. It’s easy to make one of two mistakes. You can ignore the problem because the story fell apart. Or you can panic because the story went viral. The six questions help you avoid both.
What this means for you
Next time an AI story turns up in your inbox or news feed, ask the six questions before you share it or act on it. Then look past the story to the risk behind it.
In this case, it leads to one practical question for your organisation – Which of our staff have linked AI tools to their work email, files or calendars, and who decided what those tools can do without asking?
Next in the series: why every organisation should get ready for AI agents now, even if it has no plans to use them.
References
[1] OpenAI (2026) The Hugging Face incident and the road ahead. 26 August. Available at: https://openai.com/index/hugging-face-incident-and-the-road-ahead/
[2] Cabrera, S. (2026) ‘ChatGPT allegedly emailed FBI from connected Gmail, vows “no more” unauthorised actions’, IBTimes UK, 22 September. Available at: https://www.ibtimes.co.uk/chatgpt-allegedly-emailed-fbi-connected-gmail-1821152
[3] OpenAI Help Center (2026) Managing app permissions in ChatGPT. Accessed 5 October 2026. Available at: https://help.openai.com/en/articles/20001495-managing-app-permissions-in-chatgpt
[4] The CrossWired Daily (2026) ‘ChatGPT user stunned after AI allegedly sends unprompted email to FBI’, September. Available at: https://thecrosswiredaily.com/tech-news/chatgpt-user-sends-ai-email-to-fbi/

Leave a comment