Microsoft has acknowledged an error that caused its AI work assistant to access and summarise some users’ confidential emails by mistake.
The company has promoted Microsoft 365 Copilot Chat as a secure way for workplaces and their staff to use its genAI chatbot. However, a recent issue resulted in the tool surfacing information to some enterprise users from messages stored in their drafts and sent email folders, including those marked as confidential.
Microsoft said it has rolled out an update to fix the issue and maintained that it “did not provide anyone access to information they weren’t already authorised to see”.
Copilot Chat can be used within Microsoft programmes such as Outlook and Teams, which are used for emails and chat functions, to answer questions or summarise messages.
In a statement provided to the BBC, a Microsoft spokesperson said: “We identified and addressed an issue where Microsoft 365 Copilot Chat could return content from emails labelled confidential authored by a user and stored within their Draft and Sent Items in Outlook desktop.
“While our access controls and data protection policies remained intact, this behaviour did not meet our intended Copilot experience, which is designed to exclude protected content from Copilot access.
“A configuration update has been deployed worldwide for enterprise customers.”
The issue was first reported by Bleeping Computer, which said it had seen a service alert confirming the problem. According to the publication, a Microsoft notice stated that “users’ email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat”.
The notice also said that a work tab within Copilot Chat had summarised email messages stored in a user’s drafts and sent folders, even when they had a sensitivity label and a data loss prevention policy configured to prevent unauthorised data sharing.
Further details indicate that inboxes were unaffected. However, Copilot Chat was able to access Sent and Draft folders, and potentially entire threads within those folders, including incoming emails.
Recommended reading
- Microsoft CEO Warns AI Risks Becoming a Speculative Bubble
- Report: 1.5 Million Enterprise AI Agents At Risk of ‘Going Rogue’
- Microsoft Confirms Global Price Hike for 365 Business Bundles
Microsoft has confirmed that the bug in M365 Copilot Chat allowed the AI chatbot to summarise confidential emails without users’ permission, bypassing data loss prevention (DLP) policies and sensitivity or confidentiality labels that were intended to block Copilot from accessing the emails.
Tracked internally as CW1226324, the bug was first identified on 21 January. The company said it has deployed a fix and is continuing to monitor the situation.
Microsoft attributed the issue to a coding problem, explaining: “A code issue is allowing items in the sent items and draft folders to be picked up by Copilot even though confidential labels are set in place.”





