16 Sources
[1]
Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch
Microsoft has confirmed that a bug allowed its Copilot AI to summarize customers' confidential emails for weeks without permission. The bug, first reported by Bleeping Computer, allowed Copilot Chat to read and outline the contents of emails since January, even if customers had data loss
[2]
Microsoft Bug Let Copilot Access Confidential Emails Without Consent
Microsoft has admitted that a coding bug accidentally allowed Copilot Chat to access and summarize confidential emails. As Bleeping Computer reports, the flaw bypasses data loss prevention (DLP) policies enabled by customers who wish to keep their data shielded from Microsoft's AI. The issue,
[3]
Copilot Chat bug bypasses DLP on 'Confidential' email
The bot couldn't keep its prying eyes away. Microsoft 365 Copilot Chat has been summarizing emails labeled "confidential" even when data loss prevention policies were configured to prevent it. Though there are data sensitivity labels and data loss prevention policies in place for email, Copilot
[4]
Microsoft adds Copilot data controls to all storage locations
Microsoft is expanding data loss prevention (DLP) controls to block the Microsoft 365 Copilot AI assistant from processing confidential Word, Excel, and PowerPoint documents, regardless of their location. Currently, Microsoft Purview DLP policies apply only to files stored in SharePoint or
[5]
Microsoft Copilot Chat error sees confidential emails exposed to AI tool
Microsoft has acknowledged an error causing its AI work assistant to access and summarise some users' confidential emails by mistake. The tech giant has pushed Microsoft 365 Copilot Chat as a secure way for workplaces and their staff to use its generative AI chatbot. But it said a recent issue
[6]
Microsoft says bug causes Copilot to summarize confidential emails
Microsoft says a Microsoft 365 Copilot bug has been causing the AI assistant to summarize confidential emails since late January, bypassing data loss prevention (DLP) policies that organizations rely on to protect sensitive information. According to a service alert seen by BleepingComputer, this
[7]
Copilot bug allows 'AI' to read confidential Outlook emails
Microsoft is rolling out a fix, but the timeline remains unclear, raising significant concerns about AI reliability and data privacy protection. For all its supposed intelligence, "AI" seems to make a lot of stupid mistakes -- for example, scanning and summarizing emails marked "confidential" in
[8]
Microsoft confirms Copilot bug let its AI read sensitive and confidential emails
Microsoft confirmed that a Copilot security bug was allowing the AI assistant to read and summarize emails that were labeled as confidential. According to a report from Bleeping Computer, the bug bypassed Microsoft's data loss prevention policies, which are meant to protect sensitive
[9]
Microsoft admits an Office bug exposed confidential user emails to Copilot
* Copilot Chat was reading Sent and Draft emails, but the Inbox folder appears to have been protected * The bug (CW1226324) was identified in January, a fix followed in February * Though the fix is rolling out, this is still an ongoing issue Microsoft has confirmed that a bug in M365 Copilot
[10]
Microsoft Copilot read confidential emails without permission
A bug in Microsoft 365 and Copilot has been causing the AI assistant to summarize emails that were explicitly labeled as confidential, according to a report from Bleeping Computer. The Copilot security bug reportedly bypassed organizations' data loss prevention (DLP) policies, which are used to
[11]
Microsoft 365 Copilot summarized confidential emails, DLP controls bypassed
Microsoft has confirmed that 365 Copilot allowed the AI assistant to summarize email content that should have been excluded by sensitivity labels and Data Loss Prevention controls. The problem is tracked as CW1226324 and was initially raised through customer complaints starting on January 21, 2026.
[12]
Microsoft bug allowed Copilot to summarize confidential emails
Microsoft confirmed a bug allowed its Copilot AI to summarize customers' confidential emails without permission. The issue, tracked as CW1226324, has been active since January. It bypassed data loss prevention policies designed to protect sensitive information from ingestion into Microsoft's large
[13]
A Microsoft Copilot Bug Has Been Exposing Confidential Emails -- Are You Affected?
A bug has been causing Microsoft Copilot to read and summarize users' confidential emails. The issue has been ongoing since late January, Microsoft said, due to a bug that bypasses data loss prevention (DLP) policies meant to protect sensitive information. "Users' email messages with a
[14]
Microsoft Bug Allowed Copilot to Access Confidential Emails: Report
* Microsoft bug exposed confidential emails to Copilot AI * The bug bypassed Data Loss Prevention (DLP) policies * Microsoft reportedly acknowledged the issue Microsoft added Copilot Chat across its Word, Excel, PowerPoint, and Outlook platforms last year. Now, a recently discovered bug appears
[15]
Copilot AI Reads User's Confidential Emails via MS Office: When EU Fears Came True
Microsoft's Copilot bug comes right at the moment when EU Parliament's tech staff blocked all AI features in their hardware A bug in Microsoft 365 Copilot has resulted in the AI assistant getting to summarise confidential emails on the user's system. This began in late January when the system
[16]
Copilot AI was reading your private emails, confirms Microsoft: Are you safe?
The company started rolling out a fix earlier in February to address the issue. Microsoft has acknowledged an issue in its Copilot AI service that allowed the system to process and summarise users' confidential emails without proper permission. The problem lasted for several weeks and raised
Share
Copy Link
Microsoft confirmed a coding bug allowed Copilot AI to access and summarize confidential emails for nearly a month, despite data loss prevention policies designed to shield sensitive information. The flaw, tracked as CW1226324, affected Microsoft 365 Copilot Chat users since January, raising concerns about AI tool security as organizations struggle to keep pace with rapid feature rollouts.
Microsoft has acknowledged a significant bug that allowed its Copilot AI to access and summarize confidential emails without permission for nearly a month. The flaw, first reported by Bleeping Computer
1
, enabled Microsoft 365 Copilot Chat to read and outline email contents since January, even when customers had implemented data loss prevention policies specifically designed to prevent their sensitive information from being ingested into Microsoft's large language model2
.
Source: CXOToday
The issue, trackable by administrators as CW1226324, was first discovered on January 21, 2026, when customers reported that draft and sent email messages with a confidential label applied were being incorrectly processed by the AI tool
3
. Microsoft 365 Copilot Chat allows paying customers to use the AI-powered chat feature across Office software products, including Word, Excel, and PowerPoint1
.The bug represents a serious breach of trust for organizations relying on DLP controls to safeguard their sensitive communications. Microsoft's own documentation explains that sensitivity labels can be applied manually or automatically to files as a way to comply with organizational information protection policies
3
. However, the code issue allowed items in the sent items and draft folders to be picked up by Copilot even though confidential labels were set in place, effectively bypassing data loss prevention policies that should have blocked access2
.
Source: The Register
The Work tab of Copilot Chat, which began rolling out to Microsoft 365 business users in September, was specifically affected by this vulnerability
2
. The flaw raised immediate data security concerns across multiple sectors, with reports suggesting the UK's National Health Service (NHS) was among the affected organizations2
. The NHS confirmed that while draft or sent emails were processed, patient information was not exposed to AI tool5
.Microsoft began rolling out a fix for the bug earlier in February and stated it is monitoring the effectiveness of the remediation while reaching out to affected customers
1
. A Microsoft spokesperson told BBC News that the company "identified and addressed an issue" and emphasized that "our access controls and data protection policies remained intact," though acknowledged "this behaviour did not meet our intended Copilot experience, which is designed to exclude protected content from Copilot access"5
.The tech giant clarified that the bug provided access to summarized information only to those who were already authorized to see it
4
. However, Microsoft did not disclose how many customers were affected by the data leakage incident1
.Related Stories
The incident highlights growing privacy concerns surrounding Microsoft's integration of AI tools into workplace environments. Earlier this week, the European Parliament's IT department blocked built-in AI features on lawmakers' work-issued devices, citing concerns that AI tools could upload potentially confidential correspondence to the cloud
1
. This sentiment reflects a broader trend, with 72 percent of S&P 500 companies citing AI as a material risk in regulatory filings3
.
Source: Digit
Nader Henein, data protection and AI governance analyst at Gartner, warned that "this sort of fumble is unavoidable" given the frequency of new AI capabilities being released. He noted that organizations using these AI products often lack tools needed to protect themselves and manage each new feature, adding that "the amount of pressure caused by the torrent of unsubstantiated AI hype makes that near-impossible"
5
.In response to customer feedback and the recent security lapse, Microsoft announced it is expanding data controls to block Copilot from processing confidential Word, Excel, and PowerPoint documents regardless of their location
4
. Currently, Microsoft Purview DLP policies apply only to files stored in SharePoint or OneDrive, but not to those stored on local devices. This change will be deployed through the Augmentation Loop (AugLoop) Office component between late March and late April 20264
.Cyber-security expert Professor Alan Woodward of the University of Surrey emphasized the importance of making such tools private-by-default and opt-in only. "There will inevitably be bugs in these tools, not least as they advance at break-neck speed, so even though data leakage may not be intentional it will happen," he told BBC News
5
. Organizations deploying Microsoft 365 should monitor the rollout of enhanced DLP enforcement and consider whether their current sensitivity labels adequately protect critical business communications from unauthorized AI processing.Summarized by
Navi
[1]
[3]
[4]
15 Jun 2026•Technology

12 Jun 2025•Technology

29 Oct 2025•Technology

1
Science and Research

2
Policy and Regulation

3
Technology