Office Bug Exposes Emails to Copilot

💡Copilot bug leaked enterprise emails—audit Office privacy settings now.
⚡ 30-Second TL;DR
What Changed
Office bug allowed Copilot AI to access confidential emails
Why It Matters
This security lapse erodes trust in Microsoft 365 for enterprises handling sensitive data. AI practitioners may face heightened scrutiny on Copilot deployments. It underscores the need for robust isolation in AI agents.
What To Do Next
Audit Copilot permissions in Microsoft 365 admin center to restrict email access.
Key Points
- •Office bug allowed Copilot AI to access confidential emails
- •Copilot read and summarized paying customers' emails
- •Bug bypassed Microsoft data protection policies
🧠 Deep Insight
Background and context from public sources — not the original article. 8 sources cited.
🔑 Enhanced Key Takeaways
- •A bug in Microsoft 365's DLP policy for Copilot allowed Copilot Chat to access and expose confidential emails in Sent Items and Drafts folders despite sensitivity labels[1].
- •Customers first reported the issue on January 21, 2026, with Microsoft acknowledging it via service health advisory CW1226324 on February 3, 2026, attributing it to a code issue[1].
- •The glitch bypassed DLP rules designed to exclude emails and documents stamped with Confidential labels from Copilot processing, affecting paying customers[1].
- •Microsoft is actively fixing the problem, highlighting ongoing challenges in ensuring AI tools respect data protection policies in productivity suites[1].
- •This incident underscores privacy risks in AI-integrated tools like Copilot, where software glitches can lead to unintended exposure of sensitive user data[1].
🛠️ Technical Deep Dive
- •The bug stemmed from a code issue in the DLP policy implementation, specifically failing to suppress confidential material in Copilot responses for Sent Items and Drafts folders[1].
- •DLP policy rules are configured to exclude emails, Office documents, or PDFs with Confidential sensitivity labels from Copilot for Microsoft 365 processing[1].
- •Items in other folders beyond Sent Items and Drafts were not affected by this glitch[1].
🔮 Future ImplicationsAI analysis grounded in cited sources
This bug raises concerns about the reliability of AI safety mechanisms in enterprise tools, potentially eroding trust in Microsoft 365 Copilot among businesses handling sensitive data and prompting increased scrutiny on AI testing and policy enforcement.
⏳ Timeline
📎 Sources (8)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- office365itpros.com — Dlp Policy for Copilot Bug
- krebsonsecurity.com — Patch Tuesday February 2026 Edition
- learn.microsoft.com — Office 365 Account Bug
- techradar.com — Microsoft Outlook 365 Outage January 22 2026
- neowin.net — Microsoft Finally Shares Workarounds for Windows 11 Bug That Breaks Outlook in Many Ways
- office-watch.com — Microsoft Copilot Pullback Office
- techcommunity.microsoft.com — 4486346
- securityweek.com — 6 Actively Exploited Zero Days Patched by Microsoft with February 2026 Updates
📰 Event Coverage
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: TechCrunch AI ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.

