PromptArmor finds 37% of AI connectors changed in 6 weeks, breaking security assumptions
When ChatGPT and Claude can connect out to third-party tools, governance has to keep up with a connector ecosystem that moves fast.

PromptArmor, an AI security company, analyzed how OpenAI's ChatGPT and Anthropic's Claude work with connectors and found rapid change across the connector ecosystem. For decision-makers, that means connector reviews can quickly become outdated, especially when connectors call additional AI services and move data outside your control.
If your security review of AI connectors is based on what the connector “does” today, PromptArmor just handed you a problem: connector behavior changed fast enough that your assumptions may not survive the quarter. In PromptArmor's study, 931 of 2,517 connectors (37 percent) changed over a six-week window from mid-May to the end of June.
And the change was not subtle. PromptArmor found that 1,686 new tools were added to connectors that were already live, while 1,127 tool descriptions were rewritten, potentially altering when and how an AI model decides to invoke a tool. In other words, the integration you approved may have quietly gained new capabilities and new instructions for the model after the approval process.
This matters because connectors are supposed to make agents useful. They integrate third-party services like Gmail or Slack so an AI can take actions and use information outside its own sandbox. But PromptArmor argues connectors expand the risk radius in a way that makes “defensive due diligence” hard to keep rational and complete. The company frames the core issue around what connectors can do, where data is going, and what is being done with the data. Those are the practical questions auditors and CISOs care about. The catch is that connectors evolve, and evolution can invalidate governance.
PromptArmor also ties connector risk back to another known risk pattern. Connectors share some of the risks of MCP servers, upon which connectors are based. MCP servers and connectors are both mechanisms that allow an AI system to discover and invoke tools, which means the blast radius expands when the AI is given broader access. Krishnan, PromptArmor's co-founder, puts it bluntly: “For connectors, the risks are mostly about the type of tools, what they can do, where the data is going, and what is being done with the data.” His underlying point is that the most important security work is not just on the model, but on tool scope, tool behavior, and the data flow that follows.
The study period is especially alarming because it captures a phase where connectors were “introduced about a year ago” and “have been going through a lot of changes recently.” PromptArmor’s numbers show that even if teams start with a catalog of declared capabilities, they may be reviewing a moving target. If you are the person who signs off on connector usage, you are not just approving a static integration. You are approving an ecosystem that adds new tools, rewrites descriptions, and alters permission scopes.
PromptArmor uses the Dropbox connector as a concrete example. At the start of the study, it exposed eight tools. By the end of the study, that number had risen to 24. It went from three write-capable tools to 10, and from zero potentially destructive tools to four. Permission scopes changed and instructions for the model were added. Even without inventing a worst-case scenario, this kind of change is the definition of “review drift.” You could approve a connector while it is relatively tame, then watch it become more powerful later.
There is another second-order effect that often gets missed in procurement and security reviews: connectors can behave like intrusive websites that run tracking scripts. PromptArmor found that connectors commonly send data to additional AI services. In its evaluation of all 7,517 tools used by 487 Claude connectors, 189 connectors, or about 2 in 5, are likely to call additional AI services.
That detail becomes board-level relevant when you remember how procurement and compliance usually work. Most teams approve and assess the connector itself, unaware that the vendor is calling more AI services, adding new subprocessors and terms. Krishnan explains that someone who is concerned about AI risks may have evaluated Claude with a connector and still be unaware of the external AI services that the connector calls. PromptArmor provides an example: if a Claude agent activates Zoom's connector tool to search meetings with natural language and passes in a query containing sensitive data, Zoom AI may send that data to its ten AI subprocessors in order to generate a response from one of eight different model families it uses.
This is where regulatory and cross-border compliance gets sticky. Anthropic’s connector documentation acknowledges that security controls do not necessarily cover third-party data processing. Connected services process data on their own infrastructure, under their own terms, which may be located outside the United States. Settings that control where Claude’s inference runs, like the US-only inference setting on Enterprise plans, do not change where third-party services operate. So even if your AI vendor contract says one thing about inference location, the connector can route data elsewhere when it calls external services.
Finally, PromptArmor argues connectors vastly expand the risk surface for attacks. “Bringing agents new sensitive data, new untrusted data, and new sensitive actions to take, the blast radius of an attack explodes,” Krishnan said. PromptArmor also points to a related risk highlighted in Codex, where even with one connector (email), the combination of sensitive and untrusted data enables exfiltration of legal and financial communications. The unifying theme is that tool connectivity changes the threat model, not just the user experience.
For executives, the strategic stake is simple: if connector ecosystems change faster than governance processes, your organization is effectively operating with stale risk documentation. That is a problem for security teams and also for the business owners who want to ship agent features without turning every audit into a fire drill. The companies that win here will treat connector management like live infrastructure, not one-time due diligence.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Business

Uber buys Delivery Hero for nearly $15B, vaulting to top food delivery outside China
The deal doubles Uber's dual-services footprint and pushes a ride-and-eats bundling play into 50 more markets.

Epic and Google drop settlement bid, forcing rival Android app stores by July 22
Google told the court it is ready to carry third-party app stores starting Wednesday, July 22.

SK Hynix opens at $170, raises $26.5B, and tops foreign IPO records
In Friday's Wall Street debut, SK Hynix turns AI RAM demand into a $26.5B fundraising moment that rewrites comps.

