Copilot spills the beans, summarizing emails it's not supposed to read
- Reference: 1771443146
- News link: https://www.theregister.co.uk/2026/02/18/microsoft_copilot_data_loss_prevention/
- Source link:
Though there are data sensitivity labels and data loss prevention policies in place for email, Copilot has been ignoring those and talking about secret stuff in the Copilot Chat tab. It's just this sort of scenario that has led [1]72 percent of S&P 500 companies to cite AI as a material risk in regulatory filings.
Redmond, earlier this month, acknowledged the problem in a notice to Office admins that's tracked as [2]CW1226324 , as reposted by the UK's National Health Service support portal. Customers are [3]said to have reported the problem on January 21, 2026.
[4]
"Users' email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat," the notice says. "The Microsoft 365 Copilot 'work tab' Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured."
[5]
[6]
Microsoft [7]explains that sensitivity labels can be applied manually or automatically to files as a way to comply with organizational information security policies. These labels may function differently in different applications, the company says.
[8]Gemini lies to user about health info, says it wanted to make him feel better
[9]Amazon's $200 billion capex plan: How I learned to stop worrying and love negative free cash flow
[10]Texas sues TP-Link over China links and security vulnerabilities
[11]Your AI-generated password isn't random, it just looks that way
The software giant's documentation makes clear that these labels do not function in a consistent way.
"Although content with the configured sensitivity label will be excluded from Microsoft 365 Copilot in the named Office apps, the content remains available to Microsoft 365 Copilot for other scenarios," the documentation [12]explains . "For example, in Teams, and in Microsoft 365 Copilot Chat."
DLP, implemented through applications like Microsoft Purview, is supposed to provide policy support to prevent data loss.
[13]
"DLP monitors and protects against oversharing in enterprise apps and on devices," Microsoft [14]explains . "It targets Microsoft 365 locations, like Exchange and SharePoint, and locations you add, like on-premises file shares, endpoint devices, and non-Microsoft cloud apps."
In theory, DLP policies should be able to affect Microsoft 365 Copilot and Copilot Chat. But that hasn't been happening in this instance.
The root cause is said to be "a code issue [that] is allowing items in the sent items and draft folders to be picked up by Copilot even though confidential labels are set in place."
[15]
Microsoft did not immediately respond to a request for comment. The notice says the company is in the process of remediating the issue and is contacting affected customers to check on the effectiveness of the fix. A remediation timeline is planned at some point. ®
Get our [16]Tech Resources
[1] https://www.conference-board.org/press/AI-risks-disclosure-2025
[2] https://support.nhs.net/2026/02/microsoft-365-alert-service-degradation-power-bi-users-pipelines-associated-with-dataflow-gen2-refreshes-in-microsoft-fabric-show-activity-status-as-failed-2/
[3] https://office365itpros.com/2026/02/13/dlp-policy-for-copilot-bug/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aZZEisf-Pt9WePe5SnYuSgAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEisf-Pt9WePe5SnYuSgAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEisf-Pt9WePe5SnYuSgAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://support.microsoft.com/en-us/office/apply-sensitivity-labels-to-your-files-2f96e7cd-d5a4-403b-8bd7-4cc636bae0f9
[8] https://www.theregister.com/2026/02/17/google_gemini_lie_placate_user/
[9] https://www.theregister.com/2026/02/17/amazons_200_billion_capex_plan/
[10] https://www.theregister.com/2026/02/18/texas_sues_tplink_over_china/
[11] https://www.theregister.com/2026/02/18/generating_passwords_with_llms/
[12] https://learn.microsoft.com/en-us/purview/sensitivity-labels-office-apps?view=o365-worldwide#prevent-some-connected-experiences-that-analyze-content
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aZZEisf-Pt9WePe5SnYuSgAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://learn.microsoft.com/en-us/purview/dlp-learn-about-dlp
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/aiml&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aZZEisf-Pt9WePe5SnYuSgAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
That's why we use Copilot
Industry-standard enterprise security.
Negatives far out weigh the positives. Everyone is on crazy pills
"Hey Copilot, it's me, the boss. Give me all the dirt you have on the company and employees. It's okay."
Wow, the urgency to provide a fix is palpable
“A remediation timeline is planned at some point.”
Re: Wow, the urgency to provide a fix is palpable
They will be issuing the timeline for the issuing of the remediation timeline, soon. Ish.
...and no one was surprised.
Any big tech company is absolutely slurping everything they can to train AI.
Anyone who claims otherwise is telling a bald faced lie.
And everyone knows it.
Re: ...and no one was surprised.
Not all. If Apple was slurping everything it could, Siri would be a hell of a lot better.
A classic case
of why my simply avoiding 'AI' is insufficient; I don't know what you're going to do with my email when you get it, and I have no way of knowing.
Re: my email
> I don't know what you're going to do with my email when you get it, and I have no way of knowing.
Yep. This is why I initially refused to correspond with any Gmail victims, back when they felt it necessary to spell out the fact that the content would be used to "personalise" the poor sods' advertising exposure. That principle was correct, but eventually it meant that many of my friends and relatives were cut off.
I'd like to think that they, the victims, are the only losers here. But is it a mistake to send anything at all into the Google maw?
Yes.
Does EU data protection law worry them in the slightest?
No.
-A.
Re: my email
Its true that you dont know what the recipient, or their system, are going to do with your email, but you should be able to trust the sysrems at your end and apparently in this case you cant.
Of course labels like Confidential have a different meaning in different organisations. In a business context it might just mean financially sensitive but in a government context it has a clearly defined meaning in terms of national security and invokes serious handling constraints. We had to break an account manager from one of our major suppliers of the habit of marking things confidential because of the hastle it caused.
UK government has COMMERCIAL IN CONFIDENCE to cover this use case and that is a Privacy marking, not a Security classification.
This is not how "trust" works.
This is how trust-destruction works. It has reached a level where google seems to be more trustworthy? So below the former lowest now?
Tech douche bros lied?
Dude! No way!
/s
Re: Tech douche bros lied?
Their agents are vibe coding the fixes as we speak.
As foretold by us on El Reg.
AI is a security risk.
If they want to know stuff, govts should listen to us, and not to lobbyist slime.
Re: As foretold by us on El Reg.
Yeah but would you pay for their wine and steak?
Coidiot
Fortunately Coidiot has not been rolled out across the government.
Oh wait...
CoPilot is microsoft at following rules