Microsoft disclosed a bug in Office that enabled Copilot AI to read and summarize paying customers' confidential emails. This incident bypassed the company's data protection policies. The issue highlights privacy risks in AI-integrated productivity tools.
Key Points
- 1.Office bug allowed Copilot AI to access confidential emails
- 2.Copilot read and summarized paying customers' emails
- 3.Bug bypassed Microsoft data protection policies
Impact Analysis
This security lapse erodes trust in Microsoft 365 for enterprises handling sensitive data. AI practitioners may face heightened scrutiny on Copilot deployments. It underscores the need for robust isolation in AI agents.
Technical Details
The bug permitted Copilot chatbot to process email content without authorization checks. It affected Office environments where Copilot is enabled for email summarization.




