
On August 18, 2026, Anthropic rolled out the full version of Cowork, its productivity suite for Claude, significantly expanding its access to Google Workspace. The AI can now independently draft, reply to, and forward Gmail messages, and manage files in Google Drive. The most notable part is a single setting: users can turn off the usual confirmation step before sending, letting the AI dispatch emails with zero human review.
Key takeaways
- Claude Cowork has been available on all paid plans (Pro, Team, Max, Enterprise) since August 18, 2026, on web and mobile, with full functionality through the desktop app.
- In Gmail, Claude can draft, reply to, and forward messages, and search and sort the inbox; in Google Drive, it moves, shares, and deletes files.
- By default, Claude asks for approval before every action; individual users, and admins on Team or Enterprise plans, can turn that confirmation step off.
- Without confirmation enabled, the AI sends emails on its own, with no human reading the text beforehand.
- Anthropic says actions run in a sandbox and that usage data is not used to train the underlying models.
What Claude Cowork can now do in Gmail and Drive
The expanded Google Workspace connector turns Claude from an assistant that reads into one that acts. In Gmail, it drafts new messages, replies to incoming mail in an appropriate tone, forwards messages, and searches and sorts the inbox. In Google Drive, Claude manages files independently, sharing them with colleagues, moving them between folders, or deleting them. In Google Calendar, the AI can create, edit, and cancel events and check availability. Technically, this runs inside a sandboxed environment with encrypted data transfer; for critical operations like permanent deletion, Anthropic says explicit approval remains mandatory.
The switch: approval on or off
One single setting is doing most of the work here. By default, Claude asks before every email, every calendar change, and every file action before carrying it out. Individual users can turn off that prompt for their own account in the chat interface; on Team and Enterprise plans, administrators decide centrally whether members may let actions run without repeated confirmation. With confirmation switched off, Claude sends messages without a human reading the finished text before it goes out. For heavy email users, that is a genuine time saver, echoing the approval logic kabel-salat.info already described around AI agents trading on Bitpanda: the button that matters isn’t the feature itself, it’s who gets to switch it off and when. Individual users find the switch right in the chat interface, while companies manage it centrally through the organization’s connector settings, which at least in theory lets admins limit automatic approval to specific teams or inboxes instead of turning it on globally.
Why autonomous email is its own risk category
None of the coverage of the announcement explicitly raises security concerns, but the pattern is well known from AI-agent research: once a system can both read incoming email and, in the same breath, send new messages unchecked, every incoming email becomes a potential instruction to the AI itself, an attack pattern known as prompt injection that kabel-salat.info has already covered in the context of AI agents in cyberattacks. For a purely read-only assistant, the damage stays contained; for an assistant that sends binding messages in someone else’s name without a check, the attack surface grows accordingly. That Anthropic keeps the approval setting controllable per user and per organization is therefore not a minor detail, it is the actual security architecture of the feature. For companies handling customer or employee data, there is a second layer to weigh: relying on a US provider to process that data under GDPR raises its own questions once AI-drafted emails carrying personal data go out without a human check.
Outlook
Claude Cowork shows how quickly a read-only assistant turns into an acting one, once a provider trusts its own control layer enough. Anthropic is following an industry-wide shift, turning AI assistants from answer machines into agents that act inside everyday business software. For teams handling heavy routine correspondence, switching off the confirmation step can genuinely save time. But anyone using the feature should recognize that control then sits entirely in the configuration, not in a final glance before hitting send. For companies handling sensitive customer communication, the sensible approach is to enable automatic approval only for low-stakes inboxes at first, and to review the admin settings regularly, rather than handing the AI full latitude from day one.
