logo

Microsoft Copilot Ignored Sensitivity Labels, Processed Confidential Emails

ID: ac1b8c01-5f7d-56f1-b336-ffab27c38b84

STIX ID: report--ac1b8c01-5f7d-56f1-b336-ffab27c38b84

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-02-23

Date Updated: 2026-04-23

Author: Tim Freestone

...
...

Microsoft 365 Copilot contained a bug (CW1226324) that caused Copilot Chat’s “Work” tab to read and summarize confidential emails from users’ Sent Items and Drafts even when sensitivity labels and DLP policies were configured to block AI processing; remediation was slow, the NHS flagged the issue internally, and the scope of affected organizations remains unclear, highlighting a critical governance gap where platform-native controls failed and independent AI governance is needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.