Microsoft error sees confidential emails exposed to AI tool Copilot

Microsoft has addressed a security flaw where its Copilot AI mistakenly accessed and summarised confidential emails from users’…..
Immuniweb - securitybuyer.com

Share this article:

Microsoft has addressed a security flaw where its Copilot AI mistakenly accessed and summarised confidential emails from users’ draft and sent folders. While the company has since released a fix, they maintained that the bug did not grant any users access to information beyond their existing permissions.

Dr. Kolochenko, CEO at ImmuniWeb, and a Fellow at the British Computer Society (BCS), has commented:

“With the rapid proliferation of Agentic AI and AI-powered plugins for traditional software, incidents like this one will likely surge in 2026, possibly becoming the most frequent type of security incident at both large and small companies around the globe.

Most corporations are not ready to properly secure and manage AI at workplace, while both employers and employees are rapidly switching to mushrooming AI solutions in the hope of gaining some productivity. Traditional security controls, such as Data Leak Prevention (DLP) systems, are currently unable to reliably detect unauthorized or excessive use of AI by unwitting employees or malicious insiders. Worse, cybercriminals are already actively creating malicious AI agents and applications to steal sensitive data from users.

Misuse of AI will also be a disaster for privacy in 2026. Every day, tons of sensitive personal data are shared with LLMs around the globe without any precautions. Even governmental agencies of developed countries are exposed to this risk because of inadequate or simply missing governance of AI at workplace. Shadow AI, when employees bring their own devices with AI apps to scan or otherwise ingest confidential data, will be among the key challenges to tackle.

In 2026, and moving forward, we will probably see many class-action and individual lawsuits against both tech giants and AI boutiques for unlawful collection of user data. Some unscrupulous actors, that purposely use Agentic AI to obtain valuable or confidential data, will likely claim that they have been collecting the data without authorization by mistake. Whether such a defence will stand in courts depends on many factors, but AI industry will likely suffer a lot, with some AI vendors going out of business due to litigation and reputational losses.

Lastly, after a few security incidents of a sufficient scale and damage happen, like a crash of a Critical National Infrastructure (CNI) provider or a massive leak of classified documents – governments on both sides of the Atlantic will probably rush to severely regulate use of AI, possibly creating a new AI winter.”

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
OPTEX at Essen - securitybuyer.com

OPTEX to showcase perimeter solutions at Security Essen

OPTEX will present its latest perimeter and asset protection solutions at Security Essen 2026, one of Europe’s leading security trade fairs.
Dallmeier

Building Trust in Modern Video Security

Rebecca Spayne, Managing Editor of Security Buyer, speaks with Josua Braun, Chief Revenue Officer at Dallmeier electronic, about cyber resilience, trusted supply chains, the practical value of artificial intelligence and what security professionals should consider when investing in modern video technology. 
Verkada

Verkada Expands AI Security Platform

Verkada, a provider of AI-powered physical security and operations, has unveiled new capabilities for vehicle fleets, enterprise sound systems, and building operations during its annual customer conference, VerkadaOne.
Assa Abloy

“Mobile-first” access 

David Moser, of ASSA ABLOY Opening Solutions EMEIA explores how mobile digital access unlocks new possibilities for organizations everywhere.
Traka - securitybuyer.com

Integrating Digital and Physical Security

Tom Smith, Vice President and Head of EMEIA for Traka, discusses convergence and the expanding role of integrated key and asset management. 
Traka GSX

GSX Exhibitor Spotlight – Traka

Traka, an ASSA ABLOY company and the global leader in intelligent management solutions for keys and equipment, returns to GSX 2026 at Booth #1233. Traka experts will be available to provide personal demonstrations of how smart asset management systems are streamlining operations in numerous industry verticals. 
Rhombus GSX

GSX Exhibitor Spotlight – Rhombus

When it comes to modernising physical security, Rhombus stands out by making it smarter, simpler, and genuinely easier to manage; no matter the size or complexity of the business. 
Keynetics at Essen - securitybuyer.com

Keynetics to Debut at Security Essen 2026

The UK-based Keynetics will exhibit at Security Essen for the first time, showcasing SentriGuard, its smart key-management
Scroll to Top