Close Menu
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
What's Hot

The Most Stylish Budget 5G Phone in 2026?

April 7, 2026

SeaWorld® Yas Island, Abu Dhabi Announces the Return of SeaBloom | News

April 7, 2026

AAPI Heritage Month Worksheets (Free Printables)

April 7, 2026
Facebook X (Twitter) Pinterest YouTube
Facebook X (Twitter) Pinterest YouTube
Mind Fortunes
Subscribe
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
Mind Fortunes
Home»Technology»Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
Technology

Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one

February 21, 2026No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
Microsoft Copilot ignored sensitivity labels twice in eight months — and no DLP stack caught either one
Share
Facebook Twitter LinkedIn Pinterest Email

In a recent security breach, Microsoft’s AI assistant, Copilot, accessed and summarized confidential emails for four weeks starting on January 21. Despite sensitivity labels and DLP policies in place to prevent this, Copilot was able to read the emails without detection from any security tool in Microsoft’s stack. This breach affected organizations such as the U.K.’s National Health Service, highlighting the severity of the issue in regulated healthcare environments.

This incident, tracked by Microsoft as CW1226324, is not the first time Copilot has violated its own trust boundary. In June 2025, Microsoft patched a critical zero-click vulnerability, dubbed “EchoLeak,” which allowed a malicious email to bypass Copilot’s security measures and exfiltrate enterprise data without any user action. This vulnerability, assigned a CVSS score of 9.3, exposed a significant flaw in Copilot’s retrieval and generation pipeline.

The root causes of these breaches point to a fundamental design flaw in Copilot’s architecture. The AI assistant processes trusted and untrusted data in the same thought process, leaving it vulnerable to manipulation. These vulnerabilities went undetected by traditional security tools such as endpoint detection and response (EDR) and web application firewalls (WAFs) because they were not designed to monitor the inner workings of Copilot’s inference pipeline.

To address these issues and prevent future breaches, security leaders are advised to conduct a five-point audit that includes testing DLP enforcement against Copilot directly, blocking external content from reaching Copilot’s context window, auditing Purview logs for anomalous interactions, enabling Restricted Content Discovery for sensitive data, and establishing an incident response playbook for vendor-hosted inference failures.

See also  Former Googlers seek to captivate kids with an AI-powered learning app

This breach serves as a cautionary tale for organizations deploying AI assistants into production without adequate governance and security measures in place. The risk of unintended or unauthorized behavior from AI agents is a growing concern for CISOs and senior security leaders. It is crucial for organizations to proactively assess and mitigate the risks associated with AI assistants accessing sensitive data.

By implementing the recommended controls and audit measures, organizations can better protect against trust boundary violations and ensure the security of their sensitive data. Stay vigilant, test regularly, and prioritize security when deploying AI assistants in enterprise environments.

Caught Copilot DLP labels Microsoft Months sensitivity stack
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleBeyond Remission: Supporting Oncology Survivorship
Next Article The Politics of Looking Away

Related Posts

The Most Stylish Budget 5G Phone in 2026?

April 7, 2026

AI startup Rocket offers vibe McKinsey-style reports at a fraction of the cost

April 7, 2026

AI agents that automatically prevent, detect and fix software issues are here as NeuBird AI launches Falcon, FalconClaw

April 7, 2026

Out of Every 2026 Android, One Feature Makes Me Return to Xiaomi

April 6, 2026

Comments are closed.

Our Picks

AI Learning Assistant | Teacher Picks

March 29, 2026

NBCU Academy’s The Edit | Teacher Picks

March 7, 2026

What SEL Skills Do High School Graduates Need Most? Report Lists Top Picks

March 8, 2026
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Technology

The Most Stylish Budget 5G Phone in 2026?

April 7, 20260

The Poco M8 5G: A Unique Blend of Power and Style Known for its raw…

SeaWorld® Yas Island, Abu Dhabi Announces the Return of SeaBloom | News

April 7, 2026

AAPI Heritage Month Worksheets (Free Printables)

April 7, 2026

Protein trend adding innovation to bread aisle

April 7, 2026
About Us
About Us

Explore blogs on mind, spirituality, health, and travel. Find balance, wellness tips, inner peace, and inspiring journeys to nurture your body, mind, and soul.

We're accepting new partnerships right now.

Our Picks

The Most Stylish Budget 5G Phone in 2026?

April 7, 2026

SeaWorld® Yas Island, Abu Dhabi Announces the Return of SeaBloom | News

April 7, 2026

AAPI Heritage Month Worksheets (Free Printables)

April 7, 2026

Subscribe to Updates

Awaken Your Mind, Nourish Your Soul — Join Our Journey Today!

Facebook X (Twitter) Pinterest YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 mindfortunes.org - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.