Quick Facts
- Microsoft bug CW1226324 allowed Copilot AI to access confidential emails in Sent Items and Drafts folders despite data protection labels
- Issue was active from January 21 to February 11, 2026, affecting over 37,000 organizations with Microsoft 365 Copilot
- European Parliament blocked AI features on work devices citing security concerns following the disclosure
Microsoft acknowledged a bug that allowed its Copilot AI chatbot to read and summarize paying customers’ confidential emails for several weeks, bypassing established data protection policies.
The company confirmed the issue on February 3, 2026, through service health advisory CW1226324. Microsoft said the root cause was a “code issue” that allowed “items in the Sent Items and Drafts folders to be picked up by Copilot even though confidential labels are set in place.”
Customers first reported the problem on January 21, 2026. Microsoft began deploying a fix on February 11, approximately three weeks after initial reports and eight days after confirming the issue existed.
Technical Scope and Impact
The bug affected messages marked with Microsoft’s sensitivity labels and configured with data loss prevention policies. Microsoft’s advisory stated that “email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat.”
The failure was limited to Sent Items and Drafts folders but created significant security risks. Sent Items routinely contain corporate correspondence sent externally — precisely the type of messages organizations expect to keep from AI systems.
Microsoft 365 Copilot serves over 37,000 organizations with approximately 1 million paying customers. The company has not disclosed how many customers were affected or whether AI-generated summaries were retained for model training.
Regulatory Response
The European Parliament’s IT department told lawmakers it blocked built-in AI features on work devices following the disclosure. The Parliament cited concerns that AI tools could upload confidential correspondence to external cloud services.
The move sets a precedent for government institutions approaching AI adoption. Security experts noted the decision signals that technical compliance may not satisfy institutional security requirements.
Business Implications
The incident highlights risks for enterprises adopting AI tools. Recent surveys show 67% of enterprise security teams express concerns about AI exposing sensitive information.
“This vulnerability demonstrates how attackers can automatically exfiltrate the most sensitive information from Microsoft 365 Copilot’s context without requiring any user interaction,” said Adir Gruss, co-founder and CTO at Aim Security.
Microsoft faces regulatory scrutiny as organizations rely on its enterprise email and productivity tools under contractual and compliance obligations. AI systems reading sensitive mail can trigger violations of data protection rules and confidentiality commitments.
The bug represents one of several documented vulnerabilities in Microsoft’s AI tools. Earlier in 2025, researchers identified “EchoLeak,” a zero-click vulnerability that could have allowed data extraction through specially crafted emails.
Read more: Microsoft says Office bug exposed customers’ confidential emails to Copilot AI
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
