Microsoft Copilot had access to organizations’ confidential emails – without permission.

Microsoft has acknowledged that a bug in Microsoft 365 Copilot has inadvertently granted the AI assistant access to confidential emails.

A bug has caused Microsoft Copilot to summarize organizations’ confidential emails, without permission.

Microsoft has confirmed that since late January, a bug in Microsoft 365 Copilot has enabled the AI assistant to read and summarize emails even if explicitly marked as confidential. The bug in Copilot bypassed data loss prevention (DLP) policies used by organizations to protect sensitive information. Microsoft has rolled out a fix, but has not yet disclosed how many users or organizations have been affected. One thing is clear: AI assistants like Copilot cannot and must not be trusted to have access to an organization’s mailbox or sensitive data.


According to Bleeping Computer, a service report about the bug (tracked as CW1226324) that was initially detected on January 21 affects the Copilot “work tab” chat feature. This allows it to read and summarize emails in the users’ sent and draft folders. What is concerning is that the AI had access to read and summarize emails marked with confidentiality labels, which are explicitly designed to ensure automated tools to not have access.

Microsoft said when it confirmed the issue to Bleeping Computer:

The Microsoft 365 Copilot ‘work tab’ Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured.”

The Silicon Valley tech giant also said that a “A code issue is allowing items in the sent items and draft folders to be picked up by Copilot even though confidential labels are set in place.” Microsoft has now confirmed it has started rolling out a fix for the bug in early February. On Wednesday, Microsoft stated that it was monitoring the deployment and is reaching out to some users to confirm the fix is working.

Using Copilot to boost productivity is not worth the risk

Microsoft has been pushing the rollout of its AI, Copilot, into all Microsoft 365 apps – not only for personal use, but also for businesses to integrate into the workforce. In September 2025, Copilot Chat, Microsoft’s AI-powered chat which allows users to interact with AI agents was rolled out into Excel, Word, Outlook, PowerPoint, and OneNote for Microsoft 365 business customers. Now, just four months later, a bug has compromised the sensitive data of Microsoft 365 users.

While the use of AI assistants, like Copilot Chat, is globally being pitched by tech giants to boost productivity and speedup workflows, what is clear is that new and developing AI technologies can become extreme security and privacy risk – especially for organizations that need to protect sensitive information.

Turn ON Privacy in one click.

Price hikes, AI, & one bad bug: Goodbye email confidentiality!

Many businesses today use Microsoft Outlook – mostly because it’s bundled with Microsoft’s Office tools like Word and Excel, but recent developments show that switching to alternatives, particularly for email, becomes more and more attractive.

  • In January 2026, a bug enabled Copilot Chat to summarize emails despite having sensitivity labels and DLP policies configured.

  • In 2025, Microsoft announced huge Microsoft 365 price hikes set to begin July 2026.

  • In September 2025, Microsoft rolled out its Copilot Chat into Excel, Word, Outlook, PowerPoint, and OneNote for paying Microsoft 365 business customers.

One thing that becomes clear from all of this: If your business uses Microsoft 365, it is time to quit the vendor lock-in and protect your confidential information. Luckily there are excellent alternatives to Microsoft products available.

Es gibt top Alternativen zu Microsoft-Produkten. Wir empfehlen, Windows durch Linux, Outlook durch Tuta Mail und Outlook Calendar durch Tuta Calendar zu ersetzen. Es gibt top Alternativen zu Microsoft-Produkten. Wir empfehlen, Windows durch Linux, Outlook durch Tuta Mail und Outlook Calendar durch Tuta Calendar zu ersetzen. There are alternatives to Microsoft products readily available. We’d recommend replacing Windows with Linux, Outlook with Tuta Mail, and Outlook Calendar with Tuta Calendar.

Turn ON Privacy in one click.

It’s time to quit the vendor lock-in

This is not the first or the last security issue Microsoft has encountered.

With the integration and rapid development of Copilot in Microsoft 365, individuals’ and organizations’ data will remain at risk.

The announcement of this bug, just months after rollout of Copilot in Microsoft 365 business plans, highlights why AI assistants do not belong in email and the importance of using end-to-end encrypted email, like Tuta Mail.

Illustration of a phone with Tuta logo on its screen, next to the phone is an enlarged shield with a check mark in it symbolizing the high level of security due to Tuta's encryption.