Microsoft says Office bug exposed customers’ confidential emails to Copilot AI

Microsoft says Office bug exposed customers’ confidential emails to Copilot AI

In Brief

Posted:

In this photo illustration, the Microsoft Copilot logo is seen in the background next to a silhouette of a person using a notebook.
Image Credits:Rafael Henrique/SOPA Images/LightRocket / Getty Images
  • Zack Whittaker

Microsoft has confirmed that a bug allowed its Copilot AI to summarize customers’ confidential emails for weeks without permission.

The bug, first reported by Bleeping Computer, allowed Copilot Chat to read and outline the contents of emails since January, even if customers had data loss prevention policies to prevent ingesting their sensitive information into Microsoft’s large language model.

Copilot Chat allows paying Microsoft 365 customers to use the AI-powered chat feature in its Office software products, including Word, Excel, and PowerPoint.

Microsoft said the bug, trackable by admins as CW1226324, means that draft and sent email messages “with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.” 

The tech giant said it began rolling out a fix for the bug earlier in February. A spokesperson for Microsoft did not respond to a request for comment, including a question about how many customers are affected by the bug.

Earlier this week, the European Parliament’s IT department told lawmakers that it blocked the built-in AI features on their work-issued devices, citing concerns that the AI tools could upload potentially confidential correspondence to the cloud.

Newsletters

Subscribe for the industry’s biggest tech news

Related

Latest in Security

Commandité
Commandité
Mise à niveau vers Pro
Choisissez le forfait qui vous convient
Commandité
Commandité
Annonces
Lire la suite
Download the Telestraw App!
Download on the App Store Get it on Google Play
×