Putting AI Agents Inside Enterprise Email Creates a New Security Boundary, Not Just a Better Inbox

Written by Silvia Pavelli

Coremail has presented two AI-native enterprise-email products at LEAP 2026: an AI-Native Secure Email System and a CACTER AI-Native Secure Email Gateway. In its September 8 release, the company describes an architecture in which a large language model serves as a cognitive core and multiple AI agents act as the execution layer. The gateway applies semantic and multimodal analysis to identify phishing, impersonation, malicious links and high-risk attachments. The announcement reflects a genuine enterprise trend, but the important story is not that email now has AI. It is that AI is being placed inside one of an organization’s most exposed and consequential communication channels.

Email is unusually difficult terrain for autonomous systems because its inputs are adversarial by default. A message can be authentic, misleading, malicious or merely incomplete. It may contain a link, a document, a request for payment, a calendar invitation or an instruction that tries to alter the behavior of the model reading it. A conventional filter evaluates known signals and policies. An agentic system may summarize, classify, route, draft, retrieve records or trigger a workflow. Every additional action expands the attack surface, especially if external applications and enterprise systems are connected as Coremail says its platform can support.

The central design principle should be least privilege. An agent that categorizes a message does not need authority to change a vendor record. A system that drafts a response should not send it automatically. A model that identifies a potential phishing attachment should not be able to open that attachment in a privileged environment. The key question is not whether an agent is intelligent enough to complete a task; it is whether it has the minimum permission needed, a clearly bounded tool set and an escalation path when uncertainty is high. This is particularly important for inboxes, where outside parties control much of the input.

Coremail says its system combines open interoperability with multi-layer isolation mechanisms. Those are compatible ambitions, but they introduce a trade-off. Interoperability makes AI more useful because it can connect email to customer systems, document repositories and business processes. Isolation reduces the harm when a connection is abused or a model makes an error. Enterprises should require a concrete account of where isolation occurs: at the prompt, the tool, the user identity, the data store, the tenant, the network or all of the above. Generic claims about a secure agent layer are less valuable than testable boundaries and evidence that they work.

The CACTER gateway’s focus on AI-generated phishing and impersonation is timely. Generative systems can make social-engineering messages more fluent, personalized and multilingual. But a vendor’s ability to detect AI-generated content is not the only control that matters. Effective defense also requires sender authentication, domain reputation, URL and attachment detonation, user-reporting channels, payment-verification processes and incident response. Semantic analysis can reduce reliance on simple keyword rules, but it can also generate false positives or false negatives that must be logged, reviewed and measured against operational consequences.

Auditability becomes essential once agents act inside the mail environment. Organizations should be able to reconstruct what the system saw, which policy applied, which model or version produced a decision, what external tools were invoked, what data was accessed and whether a human approved the next step. This is not only a compliance concern. It is how security teams investigate an error and how business owners learn whether automation is saving time or simply moving risk into a less visible layer. Model updates need similar scrutiny: a performance improvement can alter behavior in a workflow that employees already depend on.

Coremail says it serves more than 20,000 enterprise customers and supports over one billion end users; those are company claims rather than independent product-performance evidence. The meaningful validation will come from disclosed detection rates, false-positive burdens, response-time effects, privacy controls, integration safety and independent security testing. The most promising enterprise-email AI will not be the one that automates the most messages. It will be the one that makes high-confidence actions easy, low-confidence actions reviewable and dangerous actions impossible by design.

News
Silvia Pavelli

Silvia Pavelli

Silvia Pavelli is an Italian journalist and AI correspondent based in Rome. She covers how artificial intelligence is reshaping business, policy, and everyday life across Europe. When she's not chasing a story, she's probably arguing about espresso.