AI News

Microsoft Copilot Security Failure: A Timeline of Broken Trust

For the second time in eight months, Microsoft’s flagship AI assistant, Copilot, has been found circumventing the very security protocols designed to make it safe for enterprise adoption. A critical bug active throughout early 2026 allowed the AI to read, summarize, and surface emails explicitly marked "Confidential," bypassing Data Loss Prevention (DLP) policies and exposing sensitive data across major organizations, including the UK’s National Health Service (NHS).

This latest incident, which left sensitive records vulnerable for nearly four weeks, is not an isolated glitch. It follows a severe vulnerability discovered in June 2025, painting a concerning picture of a "systemic blind spot" in the modern AI security stack. As enterprises rush to deploy Generative AI, these repeated failures raise urgent questions: Can legacy security frameworks like DLP and sensitivity labels truly contain Large Language Models (LLMs) at runtime?

The February 2026 Incident: Bypassing the "Confidential" Label

In late January 2026, a code-level defect in Microsoft 365 Copilot effectively disabled the "trust boundary" that organizations rely on to protect their most sensitive communications. The bug, tracked by Microsoft as CW1226324, allowed the AI assistant to access, process, and summarize emails stored in users' "Sent Items" and "Drafts" folders, even when those emails bore restrictive sensitivity labels such as "Highly Confidential" or were covered by active DLP policies.

Under normal operations, sensitivity labels act as digital "do not enter" signs for the AI. If a document is labeled "Confidential," Copilot is contractually and technically obligated to ignore it during its Retrieval-Augmented Generation (RAG) process. However, for approximately 28 days—from January 21 to February 19, 2026—this mechanism failed for specific Outlook folders.

The impact was felt acutely in regulated sectors. The NHS, which manages vast amounts of private patient data, flagged the incident internally as INC46740412. For nearly a month, staff utilizing Copilot for routine administrative tasks could have inadvertently surfaced protected health information (PHI) or internal strategy documents that were supposed to be invisible to the AI model.

While Microsoft has since deployed a fix and stated that the bug "did not provide anyone access to information they weren't already authorized to see," the failure undermines the core promise of AI governance: that the AI will not process data it has been told to ignore. In a legal or compliance context, the mere processing of restricted data by an AI model—summarizing a privileged legal draft or a patient record—can constitute a breach of policy.

A Pattern of Vulnerability: The EchoLeak Precedent

The February 2026 failure is the second major strike against Copilot’s security architecture in less than a year. Eight months prior, in June 2025, researchers unveiled a critical vulnerability dubbed "EchoLeak" (CVE-2025-32711).

Unlike the February bug, which was a functional failure of labels, EchoLeak was a sophisticated "zero-click" exploit. It allowed attackers to embed hidden instructions in benign-looking emails. When Copilot processed these emails, the hidden prompts would "hijack" the AI's context window, forcing it to retrieve and exfiltrate sensitive data to the attacker without the user ever realizing a breach had occurred.

Both incidents reveal a dangerous reality: Microsoft’s security controls are struggling to keep pace with the complex, non-deterministic nature of LLMs.

Comparison of Recent Copilot Security Failures

Incident Name Date Active Root Cause Mechanism of Failure
EchoLeak (CVE-2025-32711) June 2025 LLM Scope Violation Malicious prompt injection allowed attackers to hijack RAG retrieval and exfiltrate data.
DLP Bypass (CW1226324) Jan - Feb 2026 Functional Code Defect Copilot ignored sensitivity labels in specific Outlook folders (Drafts/Sent), summarizing confidential data.

The Systemic Blind Spot: Runtime vs. Static Security

The recurrence of these issues highlights a fundamental disconnect between traditional data security and the way Generative AI operates.

Legacy tools like DLP and sensitivity labels are designed for static or transactional protection. They ask binary questions: Does User A have permission to open File B? Does this email contain a credit card number?

However, AI Copilots operate dynamically at runtime. They use RAG to scan, retrieve, and synthesize fragments of information from thousands of documents in milliseconds.

  • The Context Gap: As seen in the February incident, if the AI's retrieval logic has a bug, it simply ignores the metadata tags (labels) that are supposed to block it.
  • The Interpretation Gap: As seen with EchoLeak, the AI can be tricked into interpreting malicious data as a command, bypassing static firewalls that only look for malware signatures.

Security experts are increasingly warning that "applying permissions" is no longer sufficient. The AI layer itself requires a dedicated firewall—one that validates not just who is accessing data, but what the AI is doing with it in real-time.

Industry Implications: The Trust Deficit

For CIOs and CISOs, the implications of the "twice in eight months" timeline are severe. The NHS exposure serves as a potent case study in the risks of relying on provider-native security controls for high-stakes environments.

Key Takeaways for Enterprise Leaders:

  • Verification over Trust: Organizations can no longer assume that toggling "DLP On" ensures AI compliance. Independent auditing and "Red Teaming" of AI implementations are becoming mandatory.
  • Data Sanitation: The "Drafts" and "Sent" folder loophole suggests that data hygiene is critical. Old drafts often contain unfiltered thoughts or sensitive data that, if resurfaced by AI, can cause reputational damage.
  • Sovereignty Concerns: With the European Parliament and other government bodies previously pausing Copilot rollouts due to data concerns, these technical failures validate the "sovereign AI" approach, where critical data is physically isolated from general-purpose LLMs.

Microsoft has moved to patch these vulnerabilities, but the frequency of these high-profile failures suggests that the architecture of Enterprise AI is still finding its footing. Until the "blind spot" between static permissions and dynamic AI processing is closed, enterprises remain one update away from their next data exposure.

Featured
Video Watermark Remover
AI Video Watermark Remover – Clean Sora 2 & Any Video Watermarks!
ThumbnailCreator.com
AI-powered tool for creating stunning, professional YouTube thumbnails quickly and easily.
AdsCreator.com
Generate polished, on‑brand ad creatives from any website URL instantly for Meta, Google, and Stories.
Refly.ai
Refly.AI empowers non-technical creators to automate workflows using natural language and a visual canvas.
VoxDeck
Next-gen AI presentation maker,Turn your ideas & docs into attention-grabbing slides with AI.
Elser AI
All-in-one AI video creation studio that turns any text and images into full videos up to 30 minutes.
BGRemover
Easily remove image backgrounds online with SharkFoto BGRemover.
FixArt AI
FixArt AI offers free, unrestricted AI tools for image and video generation without sign-up.
Skywork.ai
Skywork AI is an innovative tool to enhance productivity using AI.
Qoder
Qoder is an agentic coding platform for real software, Free to use the best model in preview.
FineVoice
Clone, Design, and Create Expressive AI Voices in Seconds, with Perfect Sound Effects and Music.
Flowith
Flowith is a canvas-based agentic workspace which offers free 🍌Nano Banana Pro and other effective models...
SharkFoto
SharkFoto is an all-in-one AI-powered platform for creating and editing videos, images, and music efficiently.
Funy AI
AI bikini & kiss videos from images or text. Try the AI Clothes Changer & Image Generator!
Pippit
Elevate your content creation with Pippit's powerful AI tools!
Yollo AI
Chat & create with your AI companion. Image to Video, AI Image Generator.
KiloClaw
Hosted OpenClaw agent: one-click deploy, 500+ models, secure infrastructure, and automated agent management for teams and developers.
AI Clothes Changer by SharkFoto
AI Clothes Changer by SharkFoto instantly lets you virtually try on outfits with realistic fit, texture, and lighting.
SuperMaker AI Video Generator
Create stunning videos, music, and images effortlessly with SuperMaker.
AnimeShorts
Create stunning anime shorts effortlessly with cutting-edge AI technology.
insmelo AI Music Generator
AI-driven music generator that turns prompts, lyrics, or uploads into polished, royalty-free songs in about a minute.
WhatsApp AI Sales
WABot is a WhatsApp AI sales copilot that delivers real-time scripts, translations, and intent detection.
Wan 2.7
Professional-grade AI video model with precise motion control and multi-view consistency.
BeatMV
Web-based AI platform that turns songs into cinematic music videos and creates music with AI.
Kirkify
Kirkify AI instantly creates viral face swap memes with signature neon-glitch aesthetics for meme creators.
kinovi - Seedance 2.0 - Real Man AI Video
Free AI video generator with realistic human output, no watermark, and full commercial use rights.
Text to Music
Turn text or lyrics into full, studio-quality songs with AI-generated vocals, instruments, and multi-track exports.
UNI-1 AI
UNI-1 is a unified image generation model combining visual reasoning with high-fidelity image synthesis.
Iara Chat
Iara Chat: An AI-powered productivity and communication assistant.
Video Sora 2
Sora 2 AI turns text or images into short, physics-accurate social and eCommerce videos in minutes.
Lyria3 AI
AI music generator that creates high-fidelity, fully produced songs from text prompts, lyrics, and styles instantly.
Tome AI PPT
AI-powered presentation maker that generates, beautifies, and exports professional slide decks in minutes.
Paper Banana
AI-powered tool to convert academic text into publication-ready methodological diagrams and precise statistical plots instantly.
Atoms
AI-driven platform that builds full‑stack apps and websites in minutes using multi‑agent automation, no coding required.
AI Pet Video Generator
Create viral, shareable pet videos from photos using AI-driven templates and instant HD exports for social platforms.
Ampere.SH
Free managed OpenClaw hosting. Deploy AI agents in 60 seconds with $500 Claude credits.
Free AI Video Maker & Generator
Free AI Video Maker & Generator – Unlimited, No Sign-Up
Palix AI
All-in-one AI platform for creators to generate images, videos, and music with unified credits.
Hitem3D
Hitem3D converts a single image into high-resolution, production-ready 3D models using AI.
HookTide
AI-powered LinkedIn growth platform that learns your voice to create content, engage, and analyze performance.
GenPPT.AI
AI-driven PPT maker that creates, beautifies, and exports professional PowerPoint presentations with speaker notes and charts in minutes.
Seedance 20 Video
Seedance 2 is a multimodal AI video generator delivering consistent characters, multi-shot storytelling, and native audio at 2K.
Create WhatsApp Link
Free WhatsApp link and QR generator with analytics, branded links, routing, and multi-agent chat features.
Gobii
Gobii lets teams create 24/7 autonomous digital workers to automate web research and routine tasks.
Veemo - AI Video Generator
Veemo AI is an all-in-one platform that quickly generates high-quality videos and images from text or images.
ainanobanana2
Nano Banana 2 generates pro-quality 4K images in 4–6 seconds with precise text rendering and subject consistency.
AI FIRST
Conversational AI assistant automating research, browser tasks, web scraping, and file management through natural language.
AirMusic
AirMusic.ai generates high-quality AI music tracks from text prompts with style, mood customization, and stems export.
GLM Image
GLM Image combines hybrid AR and diffusion models to generate high-fidelity AI images with exceptional text rendering.
WhatsApp Warmup Tool
AI-powered WhatsApp warmup tool automates bulk messaging while preventing account bans.
Manga Translator AI
AI Manga Translator instantly translates manga images into multiple languages online.
TextToHuman
Free AI humanizer that instantly rewrites AI text into natural, human-like writing. No signup required.
Remy - Newsletter Summarizer
Remy automates newsletter management by summarizing emails into digestible insights.
FalcoCut
FalcoCut: web-based AI platform for video translation, avatar videos, voice cloning, face-swap and short video generation.
Telegram Group Bot
TGDesk is an all-in-one Telegram Group Bot to capture leads, boost engagement, and grow communities.
SOLM8
AI girlfriend you call, and chat with. Real voice conversations with memory. Every moment feels special with her.
LTX-2 AI
Open-source LTX-2 generates 4K videos with native audio sync from text or image prompts, fast and production-ready.
Vertech Academy
Vertech offers AI prompts designed to help students and teachers learn and teach effectively.

Microsoft Copilot Ignored Sensitivity Labels Twice in Eight Months, Exposing Enterprise Data Including NHS Records

Microsoft Copilot bypassed DLP policies and sensitivity labels twice in eight months — including a four-week exposure affecting the UK's NHS — revealing a systemic blind spot in enterprise AI security stacks.