Microsoft Copilot Ignored Sensitivity Labels Twice in Eight Months, Exposing Enterprise Data Including NHS Records
Microsoft Copilot bypassed DLP policies and sensitivity labels twice in eight months — including a four-week exposure affecting the UK's NHS — revealing a systemic blind spot in enterprise AI security stacks.


