Drooid Logo
Back to story perspectives

Full Breakdown

Microsoft 365 Copilot Bug Exposes Confidential Emails

2/20/2026, 2:30:35 AM

Overview of the Incident

Microsoft has confirmed a significant bug in its Microsoft 365 Copilot service, identified as CW1226324, which allowed the AI assistant to access and summarize confidential emails without proper authorization. This flaw, first detected on January 21, 2026, bypassed existing data loss prevention (DLP) policies designed to protect sensitive information. The issue specifically affected emails stored in users' Sent Items and Drafts folders, even when those emails were marked with confidentiality labels intended to restrict access.

Technical Details of the Bug

The bug arose from a coding error that enabled Microsoft 365 Copilot to improperly process emails that should have been off-limits due to their sensitivity labels. Microsoft stated, “Users’ email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.” The company began rolling out a fix in early February 2026 and is actively monitoring the situation while contacting affected users to confirm the effectiveness of the remediation.

Broader Implications for Data Protection

This incident highlights a critical issue within Microsoft’s ecosystem regarding the inconsistent enforcement of sensitivity labels across its services. While applications like Word and Outlook typically honor these restrictions, Copilot Chat and other integrated tools may not apply the same standards, leading to potential data exposure. Microsoft’s documentation acknowledges these inconsistencies, suggesting a need for a comprehensive reevaluation of data protection policies across Microsoft 365.

Official Statements & Responses

Microsoft has categorized the incident as an advisory, indicating limited scope or impact. The company has not disclosed the number of affected users or organizations, nor provided a definitive timeline for complete remediation. The ongoing investigation aims to clarify the full extent of the impact and ensure that similar issues do not arise in the future.

Criticism & Opposition

The incident has raised concerns about data privacy and security, particularly as organizations increasingly rely on AI-driven tools. The European Parliament recently disabled AI features on lawmakers' devices due to fears that confidential data could be transmitted outside secure systems. This move underscores the growing scrutiny surrounding AI technologies and their handling of sensitive information.

What's Next

As Microsoft continues to expand AI capabilities across its products, including Outlook, Word, and Excel, ensuring strict compliance with DLP and sensitivity labeling policies will be essential. The company faces pressure to close systemic gaps in its data protection measures to maintain user trust in its AI-powered ecosystem.

Verbatim Quotes

  • “Users' email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat,” — Microsoft
  • “The Microsoft 365 Copilot ‘work tab’ Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured.” — Microsoft

This incident serves as a cautionary tale for organizations leveraging AI tools, emphasizing the necessity for robust data protection frameworks to safeguard sensitive information.