Microsoft Copilot Exposes Private GitHub Data

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

An Israeli cybersecurity firm discovered that Microsoft's Copilot AI tool can access historical data from private GitHub repositories, exposing sensitive information and intellectual property. Over 16,000 organizations, including Microsoft, AWS, and Google, are affected, raising concerns over data security and privacy.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (Microsoft Copilot) that accesses and exposes sensitive data due to its reliance on cached public GitHub repositories. This has directly led to a data breach risk affecting thousands of organizations, including major companies. The harm includes potential violations of intellectual property rights and privacy, which fits the definition of an AI Incident as the AI system's use has directly led to harm or risk of harm. The issue is not merely potential but ongoing, as Copilot can still access sensitive data despite mitigation efforts, thus constituting an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityAccountabilityTransparency & explainabilityRespect of human rightsSafety

Industries
IT infrastructure and hostingDigital security

Affected stakeholders
Business

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Business function:
Research and developmentICT management and information security

AI system task:
Content generation

In other databases

Articles about this incident or hazard