Insight · 4 min read
Insight · 3 min read
The AI agent you approved in May is not the one running today
New research found that 37 percent of AI connectors changed their capabilities in six weeks. If your approval process runs once, you are governing a system that no longer exists.

By Jacqueline DeStefano-Tangorra, CPA, CFE, CDMP · Founder & CEO, Omni Business Intelligence Solutions · Contact the author
If you approved an AI connector this spring, you did not approve what is running now. Over roughly six weeks from mid-May to the end of June, researchers at PromptArmor tracked the connectors that link Claude and ChatGPT to outside business systems and found that 931 of 2,517 of them changed. That is 37 percent, in six weeks, with no fresh approval required from the customer. The Register reported the findings on July 19. Most of the operators we talk to have a process that would catch none of it.
A connector approval is a snapshot of something that keeps moving
The specifics matter more than the headline number. PromptArmor found 1,686 new tools added to connectors that were already live in customer environments, and 1,127 tool descriptions rewritten. That second number is the one to sit with. A tool description is the plain-language instruction that tells the model when to reach for a capability, so rewriting it changes the agent's behavior without changing anything you would see in a settings screen. The Dropbox connector is the clearest example in the research: it went from 8 exposed tools to 24, its write-capable tools grew from 3 to 10, and tools that can destroy data went from zero to four. Nobody had to re-sign anything for a read-only-feeling integration to acquire the ability to delete.
You are also approving vendors you never evaluated
The same research found that roughly two in five Claude connectors — 189 of 487 evaluated — are likely to call additional external AI services of their own. So the diligence you did on one model provider may not describe where your data actually goes. PromptArmor co-founder Shankar Krishnan told The Register that teams are evaluating a connector while unaware the vendor is calling more AI services behind it, and that connectors "vastly expand the risk surface for attacks." For a mid-market company that just spent a quarter getting comfortable with one AI vendor's security posture, that is a quiet and consequential gap. This is not an argument against connectors. It is an argument that the unit of governance is the connector's current behavior, not the vendor's name on your contract.
Assuming a reported flaw gets fixed is its own exposure
There is a second assumption worth retiring, which is that a disclosed problem is a solved problem. Manifold Security reported two flaws in Anthropic's Claude for Chrome extension on May 21, 2026, showing that another browser extension could trigger the agent to act — reading Gmail, pulling Google Docs comments, viewing calendar availability, converting Salesforce leads — using an exploit the researchers demonstrated in six lines of JavaScript. On July 27 they published that both were still reproducible in v1.0.80, released July 7, eight releases after the original report. They rate the issue 7.7 on the CVSS severity scale under default settings and 9.6, critical, for users who have turned on the mode that lets the agent act without asking. Note what that means operationally: the setting that makes an agent feel productive is the same setting that raises the severity of a flaw you do not know about.
The fix is a cadence, not a stronger gate
The instinct is to tighten the initial approval. That is the wrong lever, because the problem is not that the first review was too loose — it is that there was only one. Run this through the four lenses we use on every engagement. People: name one person accountable for the agent inventory, or it belongs to nobody. Process: put connector re-review on a recurring cadence, quarterly at minimum, and treat a new tool or a rewritten description as a change that needs a decision. Technology: separate the agent's identity from the human's so its permissions can be scoped and revoked on their own, and keep approval-before-action on for anything that writes or deletes. Data: know which systems each connector can actually reach today, which is a harder question than most teams expect and the one that usually exposes the real gap. None of this requires slowing down adoption. It requires accepting that agent permissions behave like a live system rather than a signed document, and staffing them accordingly. Start with the inventory. You cannot review what you have not written down.
Get in touch
Senior experts on every engagement
Tell us what you're working through. Every inquiry is read and answered personally by our advisory team.

Led by Jacqueline DeStefano-Tangorra, CPA, CFE, CDMP
Founder & CEO, Omni Business Intelligence Solutions
Forbes Technology Council member · Featured by the Wall Street Journal, Business Insider, CNBC, NASDAQ, and Microsoft
Backed by a team of 20+ data, AI, and BI specialists across various teams — the right expert joins at the right moment.
Start the conversation →