Microsoft Recall AI App Continues to Raise Security Concerns Despite Updates

Reviewed byNidhi Govil

3 Sources

Share

Recent tests reveal that Microsoft's Recall AI app, designed to capture PC activity, still has security flaws allowing it to screenshot sensitive information like passwords and financial data.

Microsoft Recall's Persistent Security Issues

Microsoft's AI-powered screenshot tool, Recall, is once again under scrutiny for its ability to capture sensitive information, despite recent security updates. Introduced in 2024 as an exclusive feature for Copilot+ PCs, Recall was designed to take screenshots of user activity for easy searching later. However, recent tests have revealed that the app's security measures are still falling short of expectations

1

.

Source: Tom's Guide

Source: Tom's Guide

Inconsistent Filtering of Sensitive Data

The Register's investigation found that Recall's "Filter sensitive information" setting, which is enabled by default, fails to consistently protect user data. While the filter successfully blocked some instances of financial information and passwords, it struggled with less obvious presentations of sensitive data

1

.

For example:

  • Bank account pages showing balances and transactions were captured
  • Unlabeled lists of usernames and passwords in text files were screenshot
  • Social Security numbers were sometimes captured when not explicitly labeled

Potential Security Risks

The inconsistent filtering raises significant concerns about the potential misuse of captured data. If a malicious actor gains access to a system with Recall enabled, they could potentially retrieve a wealth of sensitive information

2

.

Source: The Register

Source: The Register

Adding to these concerns, The Register's test revealed that Recall screenshots could be accessed remotely using just a PIN, bypassing the supposed requirement for biometric authentication through Windows Hello Enhanced Sign-On

3

.

Microsoft's Response and User Options

When contacted about these findings, Microsoft declined to comment. However, the company has previously acknowledged that the filter is not perfect and has encouraged users to report issues through the Feedback Hub

1

.

Users do have some control over Recall's behavior:

  • Specific apps or websites can be blacklisted in Windows settings
  • The feature can be disabled entirely
Source: pcgamer

Source: pcgamer

Ongoing Controversy and Future Implications

Despite being labeled as a "preview" app, Recall is being actively promoted during the Windows setup process on new Copilot+ PCs. This aggressive push, combined with the persistent security issues, has led to continued criticism of the feature

3

.

As AI-powered tools become more integrated into operating systems, the balance between functionality and privacy remains a critical concern. The ongoing issues with Recall serve as a reminder of the challenges in developing AI systems that can reliably protect sensitive user data while providing innovative features.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo