Microsoft Copilot AI Bug Exposes Confidential Emails by Bypassing Security Controls

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A bug in Microsoft 365 Copilot Chat allowed the AI assistant to access and summarize confidential emails, bypassing organizations' Data Loss Prevention (DLP) policies. This unauthorized processing of sensitive information led to privacy breaches. Microsoft acknowledged the issue, deployed a fix, and raised concerns about AI-related data security risks in workplace tools.[AI generated]

Why's our monitor labelling this an incident or hazard?

Microsoft 365 Copilot is an AI system integrated into productivity apps, and the bug caused unauthorized access to private emails, constituting a violation of privacy rights. This is a direct harm caused by the AI system's malfunction, fitting the definition of an AI Incident due to breach of obligations protecting fundamental rights.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
BusinessWorkers

Harm types
Human or fundamental rights

Severity
AI incident

AI system task:
Content generationInteraction support/chatbots


Articles about this incident or hazard

Thumbnail Image

Microsoft Copilot bug lets AI read you private emails

2026-02-19
NewsBytes
Why's our monitor labelling this an incident or hazard?
Microsoft 365 Copilot is an AI system integrated into productivity apps, and the bug caused unauthorized access to private emails, constituting a violation of privacy rights. This is a direct harm caused by the AI system's malfunction, fitting the definition of an AI Incident due to breach of obligations protecting fundamental rights.
Thumbnail Image

Did Microsoft Copilot AI Read Your Private Emails Without Permission? Company Responds

2026-02-19
TimesNow
Why's our monitor labelling this an incident or hazard?
An AI system (Microsoft 365 Copilot) malfunctioned by accessing private and confidential emails without authorization. This unauthorized access directly leads to a violation of users' rights to privacy and confidentiality, which falls under violations of human rights and legal obligations protecting fundamental rights. Therefore, this event qualifies as an AI Incident due to the realized harm caused by the AI system's malfunction.
Thumbnail Image

Microsoft says Office bug exposed customers' confidential emails to Copilot AI | TechCrunch

2026-02-18
TechCrunch
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by incorrectly processing confidential emails, leading to unauthorized exposure of sensitive information. This directly relates to a violation of rights, specifically privacy and data protection obligations, which fits the definition of an AI Incident. The harm has already materialized as confidential emails were accessed and summarized without consent. Therefore, this is classified as an AI Incident.
Thumbnail Image

A Microsoft Copilot Bug Has Been Exposing Confidential Emails -- Are You Affected?

2026-02-18
Inc.
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) malfunctioning by bypassing data loss prevention policies and accessing confidential emails without consent. This misuse directly leads to a breach of obligations intended to protect fundamental rights related to privacy and confidentiality. Therefore, it meets the criteria of an AI Incident due to the realized harm of unauthorized exposure of confidential information caused by the AI system's malfunction.
Thumbnail Image

Copilot bug allows 'AI' to read confidential Outlook emails

2026-02-18
PCWorld
Why's our monitor labelling this an incident or hazard?
An AI system (Microsoft Copilot) is explicitly involved and malfunctioning by accessing confidential emails despite protections. This malfunction directly leads to a violation of data privacy, which constitutes a breach of obligations under applicable law protecting fundamental rights, including privacy. The unauthorized reading and summarizing of confidential emails is a clear harm to individuals and organizations relying on confidentiality, thus meeting the criteria for an AI Incident. The ongoing investigation and fix rollout do not negate the realized harm from the bug.
Thumbnail Image

Copilot AI was reading your private emails, confirms Microsoft: Are you safe?

2026-02-19
Digit
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) that malfunctioned by incorrectly processing confidential emails despite data loss prevention policies. This misuse of the AI system directly led to a violation of privacy and confidentiality, which constitutes a breach of obligations under applicable law protecting fundamental rights. Therefore, this qualifies as an AI Incident due to the realized harm related to unauthorized access and processing of sensitive data by the AI system.
Thumbnail Image

Copilot Chat bug bypasses DLP on 'Confidential' email

2026-02-18
TheRegister.com
Why's our monitor labelling this an incident or hazard?
An AI system (Microsoft 365 Copilot Chat) is explicitly involved and malfunctioning by ignoring configured sensitivity labels and DLP policies, resulting in the unauthorized processing and summarization of confidential emails. This misuse directly leads to a breach of data confidentiality, which is a violation of rights and organizational security obligations. The harm is realized as confidential information is exposed through the AI's outputs, fulfilling the criteria for an AI Incident under violations of rights and harm to property or communities (in this case, data confidentiality).
Thumbnail Image

Microsoft 365 Copilot Bug Summarized Confidential Emails Despite DLP Policies

2026-02-18
Windows Report | Error-free Tech Life
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction directly led to unauthorized access and processing of confidential emails, violating data protection policies and potentially users' privacy rights. This constitutes a breach of obligations under applicable law intended to protect fundamental rights (privacy and confidentiality), fitting the definition of an AI Incident. The harm is realized (unauthorized access and summarization of confidential data), not merely potential, and the AI system's malfunction is the direct cause. Therefore, this event qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft 365 Copilot for Android or iOS auto-sends files to AI & OneDrive before you even realise it, instead of opening normally

2026-02-18
Windows Latest
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (Microsoft 365 Copilot) that automatically uploads and processes files using AI. However, it does not describe any realized harm such as privacy breaches, unauthorized data use, or other violations. The main issue is user frustration and app functionality changes, which do not meet the threshold for harm or plausible future harm. The event is an update on how the AI system operates and its impact on user experience, fitting the definition of Complementary Information rather than an Incident or Hazard.
Thumbnail Image

Microsoft says Copilot was summarizing confidential emails without permission

2026-02-18
Mashable SEA
Why's our monitor labelling this an incident or hazard?
An AI system (Copilot Chat) malfunctioned by incorrectly processing confidential emails, leading to a breach of data protection policies and potentially violating users' rights to privacy and confidentiality. This directly relates to harm under category (c) violations of human rights or breach of obligations under applicable law protecting fundamental rights. Since the bug caused actual unauthorized access and processing of sensitive data, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Patches Security Flaw That Exposed Confidential Emails to AI

2026-02-18
Security Boulevard
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) malfunctioning by ignoring privacy protections and accessing confidential emails without authorization. This malfunction has directly caused harm in the form of privacy violations and breaches of data protection, which fall under violations of human rights and legal obligations. The harm is realized, not just potential, as the AI ingested and summarized confidential information. Hence, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft's Copilot AI Caught Leaking Confidential Emails to Unauthorized Users -- And the Company Calls It a 'Bug'

2026-02-18
WebProNews
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft's Copilot) malfunctioning by bypassing permission controls and leaking confidential information to unauthorized users. This directly led to harm in the form of unauthorized disclosure of sensitive data, which constitutes a violation of privacy rights and potentially breaches legal and regulatory frameworks such as GDPR, HIPAA, and others. The AI system's role is pivotal as the summaries were generated and surfaced by the AI despite existing access controls. Therefore, this qualifies as an AI Incident due to realized harm caused by the AI system's malfunction.
Thumbnail Image

Microsoft 365 Copilot Vulnerability Exposes Sensitive Emails Through AI Summaries - IT Security News

2026-02-19
IT Security News - cybersecurity, infosecurity news
Why's our monitor labelling this an incident or hazard?
Microsoft 365 Copilot is an AI assistant that processes and summarizes emails, clearly an AI system. The vulnerability causes it to incorrectly handle sensitive data, bypassing Data Loss Prevention policies and exposing confidential information. This directly leads to harm in terms of violation of privacy and confidentiality rights, fitting the definition of an AI Incident due to the realized harm from the AI system's malfunction.
Thumbnail Image

Microsoft Bug Allowed Copilot to Access Confidential Emails: Report

2026-02-19
Gadgets 360
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot) malfunctioning by bypassing DLP policies and accessing confidential emails without permission. This unauthorized access constitutes a violation of privacy and data protection rights, which are fundamental rights protected by law. The harm has already occurred as confidential information was processed without consent. Therefore, this qualifies as an AI Incident due to the direct involvement of the AI system's malfunction causing harm related to privacy and legal obligations.
Thumbnail Image

Microsoft Says Bug Led Copilot To Summarise Confidential Emails For Weeks

2026-02-19
NDTV Profit
Why's our monitor labelling this an incident or hazard?
The AI system involved is Microsoft's Copilot Chat, an AI-powered assistant that processes email content. The bug caused the AI to improperly access and summarise confidential emails, bypassing security controls, which directly led to a breach of confidentiality and privacy rights. This fits the definition of an AI Incident because the AI system's malfunction directly caused harm related to violations of rights and confidentiality. The event is not merely a potential risk or a complementary update but a realized harm due to AI malfunction.
Thumbnail Image

Why did Microsoft 365 Copilot summarize confidential emails?

2026-02-19
AllToc
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by accessing and summarizing confidential emails it should not have processed, thereby bypassing data-loss-prevention controls. This constitutes a breach of privacy and potentially a violation of obligations under applicable law protecting fundamental rights. The harm (unauthorized exposure of confidential information) has occurred, and the company has taken remediation steps. Therefore, this qualifies as an AI Incident due to the realized harm caused by the AI system's malfunction.
Thumbnail Image

Why did Microsoft Copilot summarize confidential emails?

2026-02-18
AllToc
Why's our monitor labelling this an incident or hazard?
An AI system (Microsoft 365 Copilot) malfunctioned by accessing and summarizing confidential emails, bypassing security controls, which constitutes a breach of data protection and privacy rights. This directly led to potential harm through unauthorized exposure of sensitive information, fitting the definition of an AI Incident involving violation of rights and harm to property (confidential data).
Thumbnail Image

Why did Copilot summarize confidential emails?

2026-02-18
AllToc
Why's our monitor labelling this an incident or hazard?
An AI system (Copilot) was involved and malfunctioned by bypassing data loss prevention controls, leading to unauthorized summarization of confidential emails. This constitutes a violation of privacy and potentially legal obligations to protect sensitive information, which fits the definition of an AI Incident due to harm related to breach of rights and confidentiality. The harm has already occurred, and the company has taken remediation steps, confirming the incident's materialization.
Thumbnail Image

How did Microsoft's Copilot expose emails?

2026-02-18
AllToc
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft's Copilot) malfunctioning by summarizing internal emails that were meant to remain private, directly leading to unauthorized exposure of private information. This is a clear violation of privacy rights and confidentiality obligations, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law. The incident has already occurred and persisted for several weeks, confirming realized harm rather than a potential risk. Hence, the classification as an AI Incident is appropriate.
Thumbnail Image

Microsoft is uploading your confidential emails to Copilot for summarization

2026-02-18
Neowin
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a programming bug) directly led to unauthorized access and reading of confidential emails, violating privacy and security policies. This constitutes a breach of fundamental rights and obligations under applicable law, fulfilling the criteria for an AI Incident. The harm has already occurred, and the AI system's role is pivotal as it was the component that accessed and processed the confidential data improperly. The ongoing rollout of a fix does not negate the fact that harm has materialized.
Thumbnail Image

Microsoft 365 Copilot Flaw Allows AI Assistant to Summarize Sensitive Emails

2026-02-18
Cyber Security News
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a code-level defect) directly leads to a breach of confidentiality controls, exposing sensitive information in violation of data protection policies. This constitutes a violation of obligations under applicable law protecting fundamental and intellectual property rights, as well as harm to organizational data security. The harm is realized or ongoing, not merely potential, as sensitive data is being processed without authorization. Therefore, this qualifies as an AI Incident due to the direct link between the AI system's malfunction and the harm caused.
Thumbnail Image

Microsoft Says Office Bug Exposed Customers' Confidential Emails To Copilot Ai

2026-02-18
Breaking News, Latest News, US and Canada News, World News, Videos
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by improperly processing confidential emails, which constitutes a breach of privacy and confidentiality. This is a direct harm to users' rights and data security, fitting the definition of an AI Incident. The bug caused unauthorized exposure of sensitive information, which is a clear violation of obligations intended to protect fundamental rights. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft confirmou: falha no pacote Office vazou e-mails de usuários

2026-02-18
Olhar Digital - O futuro passa primeiro aqui
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system that processes email content to generate summaries. The described bug caused the AI to bypass configured data loss prevention policies, leading to exposure of confidential information. This directly resulted in a violation of users' data privacy rights, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law protecting fundamental rights. Since the AI system's malfunction directly led to this harm, this qualifies as an AI Incident.
Thumbnail Image

Microsoft Copilot Chat error sees confidential emails exposed to AI tool

2026-02-19
BBC
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by improperly processing and exposing confidential email content, which is a direct violation of data protection and confidentiality rights. This meets the criteria for an AI Incident because the AI system's malfunction directly led to harm in the form of exposure of confidential information, a violation of fundamental rights and data protection obligations. The presence of the AI system is explicit, the malfunction is clear, and the harm (confidential data exposure) is realized. Therefore, this event is classified as an AI Incident.
Thumbnail Image

Falha no Copilot expõe limites das salvaguardas de confidencialidade

2026-02-19
SAPO
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system designed to process and summarize organizational content, including emails. The malfunction in its code caused it to ignore configured sensitivity labels and data protection policies, leading to unauthorized processing of confidential information. This directly breaches data protection and confidentiality obligations, constituting harm to rights protected by law. The incident is not merely a potential risk but a realized breach, as the AI system processed sensitive data improperly. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft confirms Copilot bug let its AI read sensitive and confidential emails

2026-02-19
Tom's Guide
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by incorrectly processing confidential emails, leading to exposure of sensitive content. This constitutes a violation of obligations under applicable law intended to protect fundamental rights, specifically privacy and confidentiality. Even though Microsoft claims no unauthorized access beyond authorized users occurred, the AI system's malfunction directly led to a breach of data protection policies and potential harm to privacy. Therefore, this qualifies as an AI Incident under the framework.
Thumbnail Image

Microsoft admits an Office bug exposed confidential user emails to Copilot

2026-02-19
TechRadar
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (M365 Copilot Chat) malfunctioning by improperly accessing confidential emails despite protective labels. This unauthorized access constitutes a breach of confidentiality and privacy rights, which are fundamental human rights. The harm has already occurred as confidential emails were exposed without consent. Therefore, this qualifies as an AI Incident due to the direct harm caused by the AI system's malfunction and the violation of users' rights.
Thumbnail Image

Microsoft 365 Copilot Bug: Microsoft confirms Copilot bug summarising confidential emails, says: The issue was with ... | - The Times of India

2026-02-19
The Times of India
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot) malfunctioning by incorrectly accessing and summarising confidential emails, bypassing data loss prevention policies and confidentiality labels. This misuse of the AI system has directly led to a breach of privacy and confidentiality, which is a violation of rights protected under applicable law. The harm is realized, not just potential, as confidential information was processed without authorization. The company's response and ongoing remediation efforts do not negate the fact that harm has occurred. Hence, this is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Copilot liest E-Mails mit: Microsoft räumt brisanten Fehler ein

2026-02-19
GIGA
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) malfunctioning by bypassing security protections and accessing confidential information, which constitutes a violation of privacy and potentially human rights related to data protection. This harm has already occurred as the AI system directly led to unauthorized access and processing of sensitive data. Therefore, this qualifies as an AI Incident due to realized harm stemming from the AI system's malfunction.
Thumbnail Image

Microsoft reconhece bug do Copilot que expôs e-mails confidenciais e busca solução | Exame

2026-02-19
Exame
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system integrated into Microsoft 365 products that uses AI to summarize content. The bug caused the AI to access and summarize confidential emails improperly, which is a direct misuse of the AI system leading to exposure of sensitive data. This exposure constitutes harm to users' rights to confidentiality and privacy, fitting the definition of an AI Incident under violations of rights. The harm has already occurred as emails were exposed, and the company is working on remediation, confirming the incident status rather than a mere hazard or complementary information.
Thumbnail Image

Copilot divulgue vos mails privés mais rien à faire, Microsoft force toujours avec son IA

2026-02-19
Les Numériques
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) whose malfunction directly led to the unauthorized disclosure of confidential information, which is a violation of privacy rights and confidentiality obligations. This harm to users' privacy and potential breach of legal protections qualifies as an AI Incident under the framework. The presence of the AI system is explicit, the harm has occurred, and the malfunction is acknowledged by the company. Therefore, this event is classified as an AI Incident.
Thumbnail Image

Microsoft Copilot : l'IA a fouillé dans les e-mails qu'elle n'avait pas le droit de lire

2026-02-19
Frandroid
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot) malfunctioning by ignoring privacy and confidentiality rules, leading to unauthorized reading of protected emails. This constitutes a violation of fundamental rights related to privacy and confidentiality, fitting the definition of an AI Incident under violations of human rights or breach of obligations under applicable law. The harm is realized, not just potential, as the AI has already accessed sensitive data improperly. Therefore, this event qualifies as an AI Incident.
Thumbnail Image

Copilot has been reading your emails for weeks without your consent - what now?

2026-02-19
Phone Arena
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot Chat) whose malfunction (a code error) caused it to bypass data loss prevention policies and access confidential emails without consent. This directly led to a violation of privacy, a breach of user rights, and thus harm as defined under AI Incident criteria. The harm is realized, not just potential, and the AI system's role is pivotal. Therefore, this qualifies as an AI Incident.
Thumbnail Image

Bug no Microsoft 365 Copilot faz IA resumir e-mails confidenciais

2026-02-19
TecMundo
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system that processes email content to generate summaries. The bug causes the AI to ignore confidentiality labels and DLP policies, leading to unauthorized processing of sensitive data. This constitutes a violation of data protection principles and potentially breaches privacy and confidentiality rights, which falls under harm to rights and possibly harm to communities. Since the AI system's malfunction directly leads to this harm, this event qualifies as an AI Incident.
Thumbnail Image

Email confidencial? O Copilot está lendo mesmo assim, admite Microsoft * Tecnoblog

2026-02-18
Tecnoblog
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system that processes and summarizes email content. The bug allowed the AI to bypass confidentiality labels and DLP policies, leading to unauthorized processing of sensitive information. This is a direct malfunction of the AI system causing a violation of privacy rights and potentially exposing confidential data, which fits the definition of an AI Incident under violations of human rights or breach of obligations to protect fundamental rights. Although the full scope and number of affected users are not disclosed, the harm is realized and ongoing until fully fixed. Therefore, this event qualifies as an AI Incident.
Thumbnail Image

Oups, Copilot a analysé vos emails confidentiels professionnels

2026-02-19
Clubic.com
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot) malfunctioning due to a code error that led to unauthorized access to confidential professional emails. This breach of confidentiality and privacy rights is a direct harm linked to the AI system's malfunction. The incident has already occurred, with Microsoft acknowledging the issue and deploying a fix, indicating realized harm rather than a potential risk. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Quand Copilot fouille là où il ne devrait pas

2026-02-19
01net
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) whose malfunction (a code bug) directly led to unauthorized access and processing of confidential user emails, violating data protection policies and potentially users' rights to privacy and confidentiality. This constitutes a breach of obligations under applicable law protecting fundamental rights, fitting the definition of an AI Incident. The harm is realized (confidential data was accessed and summarized), not merely potential, and the AI system's malfunction is the direct cause.
Thumbnail Image

Bug faz Copilot do Windows exibir e-mails confidenciais em resumos

2026-02-19
Canaltech
Why's our monitor labelling this an incident or hazard?
The Copilot is an AI system integrated into Microsoft 365 that processes and summarizes email content. The bug caused it to inadvertently reveal confidential information, which constitutes a violation of privacy and potentially breaches data protection rights. This exposure of sensitive data is a direct harm to individuals' rights and privacy, fitting the definition of an AI Incident under violations of human rights or breach of obligations to protect fundamental rights. Therefore, this event qualifies as an AI Incident.
Thumbnail Image

Check your Copilot settings after this confidential email bug

2026-02-19
Digital Trends
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by bypassing configured sensitivity labels and DLP policies, leading to the AI generating summaries from confidential emails that should have been blocked. This directly implicates a breach of obligations under applicable law intended to protect fundamental and intellectual property rights, as well as potentially harming confidentiality and privacy. The harm is realized (not just potential), as sensitive information was accessible and summarized by the AI. Therefore, this qualifies as an AI Incident due to the AI system's malfunction directly leading to a breach of protections for sensitive data.
Thumbnail Image

Microsoft 365's buggy Copilot 'Chat' has been summarizing confidential emails for a month -- yet another AI privacy nightmare

2026-02-19
Windows Central
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by accessing and summarizing confidential emails without consent, which is a direct violation of privacy and confidentiality rights. This constitutes harm under the definition of an AI Incident, specifically a violation of human rights and breach of obligations intended to protect fundamental rights. The harm has already occurred as the bug was active for about a month. The company's response and fix rollout are complementary information but do not negate the incident itself.
Thumbnail Image

Copilot est trop curieux : l'IA de Microsoft récupère des données dans d'autres produits, même dans des mails confidentiels

2026-02-19
CommentCaMarche
Why's our monitor labelling this an incident or hazard?
The article explicitly involves an AI system (Microsoft's Copilot) that malfunctioned by accessing confidential emails and aggregating data from multiple Microsoft services without proper user consent or adequate safeguards. This malfunction directly led to a breach of privacy, which constitutes a violation of fundamental rights and harms users. The incident is not hypothetical or potential; it has already occurred and been acknowledged by Microsoft. Therefore, it meets the criteria for an AI Incident due to the realized harm to users' privacy and rights caused by the AI system's malfunction.
Thumbnail Image

Un problème de programmation permet à l'IA Copilot de lire des emails protégés

2026-02-19
PhonAndroid
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Copilot) malfunctioning by accessing protected emails it should not have processed, which constitutes unauthorized access to sensitive data. This is a direct harm to privacy and confidentiality, falling under violations of rights and harm to property or communities. The AI system's malfunction directly led to this harm, making it an AI Incident rather than a hazard or complementary information. The presence of the bug and its exploitation of protected data clearly meets the criteria for an AI Incident.
Thumbnail Image

Microsoft admite falha no Copilot que acedia a e-mails confidenciais

2026-02-19
4gnews
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot) malfunctioning by accessing confidential emails, which constitutes a breach of privacy and a violation of rights. The harm has already occurred as the AI system read sensitive data without proper authorization. The incident is directly linked to the AI system's malfunction and its use in an enterprise context, fulfilling the criteria for an AI Incident under violations of human rights or breach of obligations to protect fundamental rights (privacy). The company's ongoing investigation and patching do not negate the realized harm.
Thumbnail Image

Copilot AI Glitch Raises Alarms: Is Microsoft's Tool Reading Confidential Emails?

2026-02-19
Analytics Insight
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI system (Microsoft 365 Copilot Chat) malfunctioning by improperly processing confidential emails, leading to unauthorized access and analysis of private information. This constitutes a violation of rights and a breach of obligations intended to protect fundamental rights, specifically privacy and confidentiality. Since the harm has already occurred due to the bug's operation over several weeks, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Un bug déclenche la lecture et le résumé d'e-mails confidentiels par Copilot

2026-02-19
Génération-NT
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by ignoring configured sensitivity labels and DLP policies, leading to unauthorized reading and summarization of confidential emails. This is a direct violation of data protection and privacy rights, which falls under harm category (c) - violations of human rights or breach of legal obligations protecting fundamental rights. The harm is realized, not just potential, as confidential information was accessed without authorization. Therefore, this qualifies as an AI Incident.
Thumbnail Image

Microsoft Blames Bug For Copilot Exposing Confidential Emails In Summaries

2026-02-19
HotHardware
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) malfunctioning by accessing and summarizing confidential emails despite data loss prevention labels intended to block such access. This malfunction directly caused a breach of confidentiality, which is a violation of legal and privacy rights. Although the impact appears limited and a fix is underway, the incident meets the criteria of an AI Incident because the AI system's malfunction has directly led to harm in the form of unauthorized disclosure of confidential information. Therefore, this event should be classified as an AI Incident.
Thumbnail Image

Microsoft Bug Let Copilot Access Confidential Emails Without Consent

2026-02-19
PCMag UK
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Copilot Chat) malfunctioning due to a coding bug, which directly led to unauthorized access to confidential emails, violating users' privacy and data protection rights. This fits the definition of an AI Incident because the AI system's malfunction caused a breach of obligations under applicable law protecting fundamental rights (privacy and confidentiality). The involvement of the AI system is explicit, and the harm (unauthorized data access) has materialized. Therefore, this is classified as an AI Incident.
Thumbnail Image

Microsoft's Copilot was secretly reading confidential emails for weeks, and what it did with them is every company's worst nightmare | Attack of the Fanboy

2026-02-19
Attack of the Fanboy
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft's Copilot Chat) malfunctioning by bypassing security policies and accessing confidential emails without permission. This misuse of AI directly leads to a violation of data privacy and security, which falls under violations of human rights or breach of applicable law protecting fundamental rights (specifically privacy and confidentiality). The harm is realized as confidential information was improperly processed, posing significant risks to affected companies. Therefore, this qualifies as an AI Incident due to the direct harm caused by the AI system's malfunction.
Thumbnail Image

Copilot: Microsoft confirma uma falha na sua IA que expõe e-mails confidenciais

2026-02-19
Pplware
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) whose malfunction or misuse has directly led to harm in the form of exposure of confidential information, which constitutes harm to property and potentially breaches data protection rights. The AI system's failure to respect security controls and data classification policies caused unauthorized disclosure of sensitive data, fulfilling the criteria for an AI Incident under the definitions provided. The harm is realized, not just potential, and involves violation of confidentiality and security obligations.
Thumbnail Image

Microsoft Copilot bug led to confidential emails being summarised

2026-02-19
Computing
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) that processes organizational content including emails. The bug caused the AI to access and summarize confidential emails despite safeguards, leading to unauthorized exposure of sensitive information. This constitutes a breach of obligations intended to protect fundamental rights to privacy and confidentiality, fitting the definition of an AI Incident. The harm is realized (not just potential), as confidential data was processed incorrectly. Therefore, this is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Michael Tsai - Blog - Outlook Copilot Bug Exposes Confidential E-mails

2026-02-19
Michael Tsai
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system used to assist with email summarization. The bug described causes the AI to access and summarize confidential emails that should have been protected by data loss prevention policies. This results in a breach of confidentiality and potentially violates privacy and data protection rights. Since the AI system's malfunction directly leads to exposure of sensitive information, this qualifies as an AI Incident under the definitions provided, specifically under violations of rights and harm to property or communities.
Thumbnail Image

Microsoft Bug Let Copilot AI Read Confidential Emails for Weeks

2026-02-19
WinBuzzer
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot AI) malfunctioning by bypassing data loss prevention controls and accessing confidential emails without authorization. This led to a direct breach of privacy and confidentiality, which constitutes harm to individuals and organizations. The exposure lasted for weeks before detection and remediation began, indicating a significant realized harm. The incident fits the definition of an AI Incident because the AI system's malfunction directly caused a violation of rights and harm to property (confidential information).
Thumbnail Image

Why did Microsoft Copilot expose confidential emails?

2026-02-19
AllToc
Why's our monitor labelling this an incident or hazard?
Microsoft 365 Copilot is an AI assistant integrated into Microsoft 365, performing tasks such as summarizing emails. The bug allowed it to access and summarize emails that should have been protected by DLP policies, leading to unauthorized exposure of sensitive information. This is a direct harm caused by the AI system's malfunction, impacting privacy and compliance, which falls under violations of rights and harm to communities or organizations. Therefore, this event qualifies as an AI Incident.
Thumbnail Image

2026-02-19
next.ink
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a bug) directly led to unauthorized access to confidential user emails, violating data confidentiality and privacy rights. This constitutes a breach of obligations under applicable law protecting fundamental rights, specifically privacy and data protection. The harm is realized, not just potential, as confidential information was accessible and summarized by the AI. Therefore, this qualifies as an AI Incident.
Thumbnail Image

Did Copilot expose confidential emails?

2026-02-20
AllToc
Why's our monitor labelling this an incident or hazard?
Microsoft 365 Copilot is an AI system that processes email content to generate summaries. The bug allowed it to access and process emails in Sent and Draft folders without proper authorization, bypassing controls designed to prevent such exposure. This unauthorized processing of sensitive data is a direct harm linked to the AI system's malfunction. Although the full scope of data exposure is not publicly known, the incident involves realized harm to confidentiality and privacy, fitting the definition of an AI Incident.
Thumbnail Image

What happened with the Microsoft 365 Copilot bug?

2026-02-20
AllToc
Why's our monitor labelling this an incident or hazard?
The Copilot feature is an AI system that generates email summaries by processing mailbox content. The bug caused it to access data it should not have, bypassing DLP protections, which directly led to unauthorized exposure of user data, a violation of privacy rights and data protection obligations. This harm is realized, not just potential, and stems from the AI system's malfunction. Therefore, this qualifies as an AI Incident under the framework, specifically a breach of obligations under applicable law protecting fundamental rights.
Thumbnail Image

How did Copilot summarize confidential emails?

2026-02-20
AllToc
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Copilot) malfunctioning by improperly accessing and summarizing confidential emails, which constitutes a breach of data protection and potentially a violation of privacy rights. This malfunction directly led to harm in terms of exposure of sensitive information. Therefore, it qualifies as an AI Incident due to the realized harm caused by the AI system's defect.
Thumbnail Image

Microsoft admits Copilot Chat wrongly pulled confidential emails for some users

2026-02-20
storyboard18.com
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Copilot Chat) malfunctioning by accessing and summarizing confidential emails despite sensitivity labels and data loss prevention policies. This malfunction directly led to unauthorized exposure of confidential information, which is a violation of privacy and confidentiality rights, fitting the definition of harm under (c) violations of human rights or breach of obligations under applicable law. The incident is not merely a potential risk but a realized harm, as Microsoft acknowledged the error and its impact. Hence, it is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Bug no Microsoft 365 Copilot ignora políticas de DLP | SempreUpdate

2026-02-18
SempreUpdate
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system integrated into corporate applications that processes user data to generate summaries and suggestions. The bug CW1226324 causes the AI to improperly process data protected by DLP policies and sensitivity labels, which are legal and organizational safeguards for data privacy and confidentiality. This malfunction directly leads to a violation of these protections, constituting harm under the framework's category of violations of human rights or breach of obligations under applicable law (privacy and data protection). The event describes realized harm due to the AI system's malfunction, not just a potential risk, so it qualifies as an AI Incident rather than an AI Hazard or Complementary Information.
Thumbnail Image

O Copilot está vasculhando os e-mails confidenciais dos usuários, burlando as medidas de segurança. A Microsoft chama isso de bug.

2026-02-18
avalanchenoticias.com.br
Why's our monitor labelling this an incident or hazard?
An AI system (Microsoft 365 Copilot) malfunctioned by ignoring confidentiality labels and DLP policies, directly leading to unauthorized access and processing of confidential emails. This constitutes a violation of user privacy and data protection rights, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law protecting fundamental rights. Since the harm has already occurred and is linked to the AI system's malfunction, this qualifies as an AI Incident.
Thumbnail Image

Microsoft affirme qu'un bug pousse Copilot à résumer des e-mails confidentiels : un incident qui démontre que l'IA d'entreprise et le principe de moindre privilège sont encore loin d'être réconciliés

2026-02-19
Developpez.com
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a bug in the retrieval phase) directly led to the exposure of confidential information that was supposed to be protected by security policies. This constitutes a violation of data protection and confidentiality rights, which falls under harm to human rights and legal obligations. The harm is realized and ongoing, not merely potential, and the AI system's role is pivotal as it was the component that accessed and summarized the confidential emails improperly. Hence, the classification as an AI Incident is appropriate.
Thumbnail Image

0

2026-02-19
developpez.net
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a bug in data retrieval logic) directly caused the AI to access and summarize confidential emails despite DLP protections. This led to unauthorized exposure of sensitive information, constituting harm to privacy and potentially violating legal obligations related to data protection and confidentiality. The harm is realized and documented, affecting multiple organizations including public health entities. Therefore, the event meets the criteria for an AI Incident because the AI system's malfunction directly led to a breach of confidentiality and data protection rights.
Thumbnail Image

Microsoft confirms Copilot bug exposed confidential Outlook emails: Here's what went wrong

2026-02-19
Techlusive
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by bypassing DLP policies and processing confidential emails, which directly led to a breach of privacy and security. This fits the definition of an AI Incident because the AI system's malfunction caused harm related to violations of privacy and potentially legal obligations to protect confidential information. The harm is realized, not just potential, and the company has responded with a fix, but the incident itself is a clear case of AI-related harm.
Thumbnail Image

Un bug dans Microsoft 365 Copilot lui permettait de résumer des emails confidentiels

2026-02-19
next.ink
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by bypassing security measures designed to protect confidential information. This malfunction directly led to unauthorized access and processing of confidential emails, which constitutes a violation of data protection and privacy rights, falling under harm category (c) - violations of human rights or breach of obligations under applicable law protecting fundamental rights. The harm is realized, not just potential, as confidential data was processed incorrectly. Therefore, this qualifies as an AI Incident.
Thumbnail Image

What caused Microsoft Copilot to summarize confidential emails?

2026-02-19
AllToc
Why's our monitor labelling this an incident or hazard?
The AI system (Microsoft 365 Copilot) malfunctioned by accessing and summarizing confidential emails it should not have processed, directly leading to unauthorized exposure of sensitive data. This constitutes a breach of obligations under applicable law protecting privacy and confidentiality, thus qualifying as an AI Incident. The company has fixed the issue, but the harm occurred due to the AI system's malfunction and improper data handling.
Thumbnail Image

Microsoft Copilot confidential emails shock: alarming privacy flaw exposed

2026-02-19
Pune Mirror
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot Chat) that malfunctioned by improperly processing confidential emails, leading to unauthorized access and summarization of sensitive data. This constitutes a breach of privacy and data protection obligations, which are legal protections of fundamental rights. The harm has already occurred as confidential information was exposed without proper permission. The incident stems from a coding error (malfunction) in the AI system's development or deployment. Given the direct link between the AI system's malfunction and the privacy harm, this is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Copilot bug saw AI snoop on confidential emails -- after it was told not to

2026-02-19
IT Pro
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot) malfunctioning by ignoring sensitivity labels and data loss prevention (DLP) policies, leading to unauthorized access to confidential emails. This misuse of AI directly results in a breach of privacy and confidentiality, which falls under violations of human rights and legal obligations protecting fundamental rights. The harm has already occurred as the AI processed sensitive data it was not supposed to access. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Confirms Copilot Bug Let AI Summarize Confidential Emails

2026-02-20
ExtremeTech
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by ignoring data loss prevention policies, which led to a breach of confidentiality protections on sensitive emails. This constitutes a violation of obligations under applicable law intended to protect fundamental rights related to privacy and data protection, thus meeting the criteria for an AI Incident. The harm is indirect but real, as confidential information was processed in violation of policies, even if not exposed to unauthorized users. Therefore, this is classified as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Copilot Chat exposes confidential emails of users: Report

2026-02-20
Business Standard
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system, Microsoft 365 Copilot Chat, which is a generative AI tool integrated into workplace applications. The malfunction caused the AI to access and summarize confidential emails improperly, breaching data protection policies and exposing sensitive information. This directly led to harm in terms of violation of confidentiality and privacy rights, fitting the definition of an AI Incident. The company's response and fix are noted but do not negate the fact that harm occurred due to the AI system's malfunction.
Thumbnail Image

Microsoft corrige un bug embarrassant qui résumait des e-mails confidentiels

2026-02-21
Journal du Geek
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) malfunctioning by ignoring confidentiality labels and summarizing sensitive emails, which directly breaches data protection and confidentiality rights. This is a clear violation of obligations under applicable law protecting fundamental rights, specifically privacy and confidentiality. The harm has already occurred as the AI system processed confidential data without authorization. Therefore, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Copilot sammelte vertrauliche Mails ein, obwohl er das nicht sollte

2026-02-20
PC-WELT
Why's our monitor labelling this an incident or hazard?
The Microsoft 365 Copilot is an AI system integrated into multiple Office applications that processes user emails to provide summaries and assistance. The malfunction caused it to bypass configured confidentiality labels and DLP policies, directly leading to unauthorized access and processing of sensitive information. This constitutes a violation of user privacy and data protection rights, which falls under harm category (c) - violations of human rights or breach of obligations under applicable law protecting fundamental rights. Since the harm has already occurred due to the AI system's malfunction, this event qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft Copilot ignored sensitivity labels twice in eight months -- and no DLP stack caught either one

2026-02-20
VentureBeat
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot) whose malfunction and exploitation led to unauthorized access and exfiltration of sensitive and confidential data, including in regulated healthcare environments. This constitutes a violation of legal obligations protecting data privacy and intellectual property rights, fulfilling the criteria for harm under AI Incident definition (c). The involvement of the AI system is direct, as the failures occurred within its retrieval and inference pipelines, and the harm is realized, not merely potential. The advisory also details the failure of security tools to detect these breaches, emphasizing the AI system's pivotal role in the incident. Hence, the classification as an AI Incident is appropriate.
Thumbnail Image

Copilot : quand l'IA de Microsoft résume sans autorisation des e-mails confidentiels

2026-02-20
Economie Matin
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by ignoring DLP policies and processing confidential emails without authorization. This directly leads to a breach of confidentiality and regulatory compliance, which is a violation of rights and a harm to the affected organizations and individuals. The AI system's malfunction is the pivotal cause of this harm, meeting the criteria for an AI Incident under the OECD framework.
Thumbnail Image

Microsoft Error Sees Confidential Emails Exposed to AI Tool Copilot

2026-02-20
Digit
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by accessing and summarizing confidential emails despite protections intended to prevent this. This malfunction directly led to exposure of confidential information, which is a violation of data protection and confidentiality rights, thus constituting harm under the category of violations of human rights or breach of obligations under applicable law. Therefore, this qualifies as an AI Incident because the AI system's malfunction directly caused harm related to confidentiality breaches. The company's fix and monitoring are complementary information but do not negate the incident classification.
Thumbnail Image

Microsoft's Copilot AI Read Your Confidential Emails -- And Lawyers Should Be Paying Attention Microsoft's Copilot AI Read Your Confidential Emails -- And Lawyers Should Be Paying Attention -

2026-02-21
LawFuel
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) whose malfunction (a bug) caused it to bypass data loss prevention policies and access confidential emails without proper authorization. This directly led to a breach of privacy and confidentiality, which are protected rights under legal and regulatory frameworks. The harm is realized, not just potential, as confidential information was processed without consent or safeguards. The incident affects legal professionals and organizations with high confidentiality requirements, indicating significant harm. Microsoft's fix and statements do not negate the fact that the AI system's malfunction caused the breach. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Google boss says research needed on AI threats, Microsoft confirms private emails read by Copilot AI - Tech Digest

2026-02-20
Tech Digest
Why's our monitor labelling this an incident or hazard?
The Microsoft Copilot AI bug involved the AI system reading and summarizing confidential emails without permission, directly violating data privacy and security, which is a breach of fundamental rights and obligations under applicable law. This harm is realized and directly linked to the AI system's malfunction. The phishing campaign, while harmful, does not explicitly involve AI systems. Other parts of the article discuss calls for research, regulation, and new AI model releases, which are either complementary information or unrelated. Hence, the overall classification is AI Incident based on the Copilot AI bug.
Thumbnail Image

Microsoft Copilot Chat Pulled Confidential Emails - What Went Wrong & How To Protect Your Data

2026-02-20
Qrius
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot Chat) whose malfunction (a configuration error) directly led to the unauthorized access and summarization of confidential emails. This is a clear breach of data protection expectations and potentially legal obligations concerning privacy and confidentiality. The harm is realized, not just potential, as confidential information was accessed improperly. Hence, it meets the criteria for an AI Incident rather than a hazard or complementary information.
Thumbnail Image

What caused Microsoft Copilot to leak emails?

2026-02-20
AllToc
Why's our monitor labelling this an incident or hazard?
Microsoft 365 Copilot is an AI system integrated into Microsoft 365 productivity tools. The bug allowed the AI to access and summarize protected email content, effectively bypassing security policies designed to prevent data leakage. This malfunction directly led to potential harm by exposing confidential information, which is a violation of privacy and data protection rights. Therefore, this event qualifies as an AI Incident because the AI system's malfunction directly caused a breach of obligations intended to protect fundamental rights (privacy and data protection).
Thumbnail Image

Microsoft admits Copilot error exposed some confidential emails

2026-02-20
The Daily Ittefaq
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot Chat) that malfunctioned by accessing and summarizing confidential emails, which is a direct consequence of the AI system's operation. The harm is realized as confidential information was exposed internally, violating data protection and confidentiality obligations. Although Microsoft states that unauthorized access by other users did not occur, the AI system's behavior breached expected privacy safeguards, constituting harm to rights protected under applicable law. Hence, this is an AI Incident rather than a hazard or complementary information.
Thumbnail Image

What caused Microsoft 365 Copilot to expose emails?

2026-02-20
AllToc
Why's our monitor labelling this an incident or hazard?
The event involves a malfunction of an AI system (Microsoft 365 Copilot) that directly led to a breach of data protection policies, exposing sensitive email content. This constitutes a violation of privacy and potentially legal obligations related to data protection, fitting the definition of an AI Incident due to harm to rights and privacy. The bug caused the AI system to access and summarize content it should not have, directly leading to harm through exposure of sensitive information.
Thumbnail Image

Microsoft 365 : Un bug a permis à Copilot de " lire " des e-mails confidentiels

2026-02-20
Actualités technologiques et startups au Sénégal et en Afrique
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot) malfunctioning by processing confidential emails it should have excluded, thus breaching data protection policies. This malfunction directly led to the synthesis of confidential content, constituting a violation of privacy and confidentiality rights. The harm is realized, not just potential, as the AI system did process and summarize sensitive emails incorrectly. Therefore, this qualifies as an AI Incident due to the direct link between the AI system's malfunction and the breach of confidentiality obligations.
Thumbnail Image

Copilot bajo la lupa: vulnerabilidad en Microsoft Office compromete la privacidad de correos

2026-02-20
infobae
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft 365 Copilot) whose malfunction (a coding error) caused it to process and summarize confidential emails that should have been protected, directly leading to a violation of privacy and data protection policies. This constitutes a breach of obligations intended to protect fundamental rights (privacy) and harm to property or communities (confidential information). The harm has already occurred, making this an AI Incident rather than a hazard or complementary information. The article also mentions mitigation efforts but the primary focus is on the realized harm due to the AI system's malfunction.
Thumbnail Image

Cuidado si usas Copilot: un error de Microsoft Office ha expuesto correos electrónicos confidenciales

2026-02-19
20 minutos
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot) malfunctioning by processing confidential emails that should have been protected, leading to exposure of sensitive information. This directly results in a violation of privacy rights and confidentiality obligations, fitting the definition of an AI Incident due to harm caused by the AI system's malfunction. The harm is realized, not just potential, as confidential data was accessed and summarized improperly.
Thumbnail Image

Microsoft reconoce un error que permite a Copilot resumir correos...

2026-02-18
europa press
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft Copilot) malfunctioning by accessing confidential email content it should not have accessed. This unauthorized access and summarization of confidential emails is a direct harm to privacy and confidentiality, which falls under violations of human rights or breach of legal obligations protecting fundamental rights. Since the harm has already occurred and is directly linked to the AI system's malfunction, this qualifies as an AI Incident rather than a hazard or complementary information.
Thumbnail Image

Microsoft confirma un fallo en su IA que expone correos confidenciales

2026-02-18
Hipertextual
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Microsoft Copilot) malfunctioning by ignoring security labels and accessing confidential emails, leading to unauthorized exposure of sensitive information. This constitutes a violation of data protection and privacy rights, which falls under harm to human rights and breach of legal obligations. The harm has already occurred as confidential data was exposed internally without consent. Therefore, this qualifies as an AI Incident due to the direct harm caused by the AI system's malfunction.
Thumbnail Image

El fallo de Microsoft 365 Copilot Chat que dejó asomar correos "confidenciales" y lo que enseña sobre la IA en la oficina

2026-02-21
WWWhat's new
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Microsoft 365 Copilot Chat) malfunctioning by improperly accessing and summarizing confidential email content despite sensitivity labels and data loss prevention policies. This behavior constitutes a breach of expected confidentiality and data protection, which can be considered a violation of obligations under applicable law protecting fundamental and labor rights (privacy and data protection). The harm is realized in terms of reputational and operational impact on organizations and potential exposure of sensitive information, even if no unauthorized external access occurred. Therefore, this qualifies as an AI Incident due to the direct link between the AI system's malfunction and harm related to confidentiality and data protection.