Monday, August 3, 2026

AI & Models

Microsoft bug exposed confidential emails to Copilot AI

A Microsoft bug allowed Copilot AI to summarize confidential emails for weeks, bypassing data loss prevention policies and prompting the European Parliament to block the tool.

Microsoft bug exposed confidential emails to Copilot AI

Microsoft has confirmed that a software bug allowed its Copilot AI tool to summarize confidential emails without permission. The flaw bypassed established data loss prevention policies—which are security measures designed to prevent sensitive data from being shared or accessed inappropriately. According to technology news publication Bleeping Computer, the Copilot Chat feature had been reading and outlining the contents of these emails since January. This allowed the artificial intelligence tool to ingest sensitive information that should have been restricted under enterprise security protocols.

The technology giant stated that it began rolling out a fix for the bug in early February. According to Microsoft, the issue meant that draft and sent email messages “with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.” The tool, which is available to paying Microsoft 365 customers, allows users to access AI-powered chat features within Microsoft’s suite of productivity software. When asked about the scale of the incident, a Microsoft spokesperson declined to disclose how many customers were affected by the security flaw, leaving the total number of impacted enterprise accounts unclear.

The incident has already prompted regulatory caution within European institutions. Earlier this week, the European Parliament’s IT department blocked built-in AI features on work-issued devices. The legislative body’s IT department asserted that the block was a precautionary measure, citing concerns that the AI tools could upload potentially confidential correspondence to the cloud. This decision highlights the growing friction between rapid enterprise AI adoption and the stringent data protection standards maintained by public institutions.

Why it matters

This incident highlights the tension between enterprise AI adoption and strict data privacy requirements, as even robust data loss prevention policies can fail when integrated with large language models.