Recommended Free Tools
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Yes. Visible text and forged message structure affected summaries in a small 2026 test of Outlook Web App, so hidden white-on-white text was not required. The result shows a risk in that specific setup—not that every email summarizer can be fooled the same way. Treat AI summaries as a convenience, and verify important facts against the original email.
How can an email summarizer be influenced by an email?
An AI assistant asked to summarize a message reads the message as input. That message is untrusted content: it may contain text that attempts to steer the model away from the user’s request. This is called indirect prompt injection because the attacker’s material arrives inside content the user asked the assistant to process, rather than as an instruction typed directly by the user.
Microsoft describes possible routes including direct instructions embedded in a message, hidden markup, quoted email chains, attachments, and encoded or obfuscated text. Depending on the assistant’s access and permissions, a misleading summary is only one possible outcome; other risks can include misclassifying malicious mail or unwanted actions. Microsoft’s overview of email prompt injection describes these scenarios.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesWhat happened in the Outlook Web App test?
Ben Gibney, identified as an X-Labs Senior Researcher, reported the experiment on October 5, 2026. The team tested six sample emails ten times each—60 trials in total—with clean-message controls at both ends. The true facts and pass/fail criteria were registered before the trials, and the model temperature was set to zero.
#1 Best Overall
In every sample series, all ten summaries included a fabricated date and invoice total. The claim is specific to those six samples and that test environment; it is not a general success rate for deployed email assistants.
Visible forged message structure was enough
Some samples did not directly tell the summarizer what to say. Instead, they contained a forged second header block with fields such as From, To, Date, and Subject, followed by fabricated body text. That structure presented the fabricated content as a later message. The summary included the false date and invoice total even without a direct instruction to the model.
Rank #2
Other samples did include explicit instructions, which were associated with removing true facts from the summary. The test therefore illustrates more than one way email content can distort a result; it does not establish which method would work in other products or circumstances.
One sample also pushed true facts below the fold
A “below fold” sample inserted 30 blank lines. In that sample, only two of four registered true facts survived in all ten trials. The facts were a meeting scheduled for Monday, August 24, 2026 at 09:30; Diego Siciliani as reconciliation owner; an invoice total of €8,650; and the action, “Send Diego your signed-off line items before Friday 21 August 2026.” The summary also incorrectly described the forged email as the most recent even though the actual message date was September 4, 2026.
Rank #3
- The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
- ABIS BOOK
What the test does—and does not—show
- It demonstrates a possibility, not prevalence. The results show that the tested summaries could be influenced by the tested email content. They do not estimate how often ordinary email summaries are wrong or manipulated.
- It was limited to one client and viewport. The researchers used Outlook Web App and explicitly did not establish that the result generalizes to other email clients.
- The conditions were controlled. The samples were designed to isolate variables, were not presented as realistic attacks on their own, and were tested at temperature zero. The report does not establish how results change at higher temperatures.
- A misleading summary is not the same as data theft. This test reported fabricated summary details, not mailbox exfiltration or an unwanted action.
Other studies examine different risks and setups, so their numbers should not be combined with this experiment. A USENIX Security 2026 paper by Hongyan Chang, Ergute Bao, Xinjian Luo, and Ting Yu reports that one poisoned email coerced GPT-4o into exfiltrating SSH keys with over 80% success in its tested multi-agent workflow. That result describes the paper’s setup, not a universal rate for consumer email summaries. The paper also says evaluated defenses did not prevent malicious text retrieval. Read the USENIX Security 2026 paper summary.
LLMail-Inject, a simulated adaptive email-assistant challenge, recorded 208,095 unique attack submissions from 839 participants. Those are challenge submissions, not a count or estimate of real-world attacks. See the LLMail-Inject paper.
How should you use AI email summaries safely?
For readers
- Check important dates, amounts, sender identities, and requested actions against the original thread before relying on them.
- Do not treat a summary as evidence that a message is safe, authentic, or accurate.
- Review the underlying email before acting on payment requests, deadlines, or instructions to share information.
For organizations
- Limit an assistant’s access to the data it needs for its task.
- Require a person to review consequential actions, especially external sharing or changes involving sensitive information.
- Give agents narrow, specific tasks rather than broad authority to review messages and act as needed.
- Use controls at both the email layer and the assistant’s runtime; screening incoming mail alone cannot address every risk created by an assistant’s active instructions, permissions, connected data, and tools.
OpenAI’s guidance similarly recommends limiting agent access, reviewing consequential actions before confirming them, and avoiding broad instructions. See OpenAI’s prompt-injection guidance.
What safeguards do email platforms describe?
Vendor documentation describes layered controls, not a guarantee that every injection will be stopped. These are the vendors’ accounts of their own safeguards rather than independent evidence that all attacks are blocked.
Best Value
Microsoft Defender for Office 365
Microsoft says Defender for Office 365 Plan 2 evaluates messages before delivery using large language model classification alongside existing email-security signals. Its analysis can include subjects, bodies, HTML and styling, hidden text, quoted or forwarded content, and normalized obfuscated segments. Microsoft says the feature focuses on credible threat objectives such as data exfiltration through URLs, revealing system prompts, and discovering available tools; it is not designed to block every instruction-like phrase or function as a general prompt-injection benchmark. Microsoft also emphasizes runtime safeguards because risk depends on the assistant’s instructions, permissions, grounded data, and tools. Microsoft documents the protection’s scope and approach here.
Google Gemini in Workspace
Google describes a layered approach that includes classifiers for malicious instructions in email and files, additional security instructions around content, URL protections, and user confirmation for certain actions. This is Google’s description of its Workspace safeguards, not a claim that every attack is blocked. Read Google’s security overview.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →

