Microsoft Confirms Copilot Bug Exposed Confidential Emails to AI
Microsoft has confirmed a critical bug that allowed its Copilot AI to access and summarize customers’ confidential emails without authorization. The issue, first reported by Bleeping Computer, enabled Copilot Chat to read and generate summaries of both draft and sent emails since January, even when users had applied confidential labels and data loss prevention (DLP) policies designed to block such data from being ingested into Microsoft’s large language models. Copilot Chat is an AI-powered feature available to paying Microsoft 365 subscribers, integrated into core Office applications like Word, Excel, and PowerPoint. The vulnerability, identified by Microsoft as CW1226324, meant that emails marked as confidential were being incorrectly processed by the Copilot system, potentially exposing sensitive information. Microsoft stated that it began rolling out a fix for the issue earlier in February. However, the company has not disclosed how many customers were affected or provided details on the scope of the exposure. A spokesperson did not respond to requests for comment, including inquiries about the number of impacted users and whether any data was accessed or misused beyond the summarization function. The incident has heightened concerns about AI integration in enterprise environments. Earlier this week, the European Parliament’s IT department informed lawmakers that it had blocked AI features on official work devices due to fears that sensitive communications could be uploaded to the cloud. The move underscores growing scrutiny over how AI tools handle private data, especially in government and highly regulated sectors.
