Microsoft has addressed a security flaw where its Copilot AI mistakenly accessed and summarised confidential emails from users’ draft and sent folders. While the company has since released a fix, they maintained that the bug did not grant any users access to information beyond their existing permissions.
Dr. Kolochenko, CEO at ImmuniWeb, and a Fellow at the British Computer Society (BCS), has commented:
“With the rapid proliferation of Agentic AI and AI-powered plugins for traditional software, incidents like this one will likely surge in 2026, possibly becoming the most frequent type of security incident at both large and small companies around the globe.
Most corporations are not ready to properly secure and manage AI at workplace, while both employers and employees are rapidly switching to mushrooming AI solutions in the hope of gaining some productivity. Traditional security controls, such as Data Leak Prevention (DLP) systems, are currently unable to reliably detect unauthorized or excessive use of AI by unwitting employees or malicious insiders. Worse, cybercriminals are already actively creating malicious AI agents and applications to steal sensitive data from users.
Misuse of AI will also be a disaster for privacy in 2026. Every day, tons of sensitive personal data are shared with LLMs around the globe without any precautions. Even governmental agencies of developed countries are exposed to this risk because of inadequate or simply missing governance of AI at workplace. Shadow AI, when employees bring their own devices with AI apps to scan or otherwise ingest confidential data, will be among the key challenges to tackle.
In 2026, and moving forward, we will probably see many class-action and individual lawsuits against both tech giants and AI boutiques for unlawful collection of user data. Some unscrupulous actors, that purposely use Agentic AI to obtain valuable or confidential data, will likely claim that they have been collecting the data without authorization by mistake. Whether such a defence will stand in courts depends on many factors, but AI industry will likely suffer a lot, with some AI vendors going out of business due to litigation and reputational losses.
Lastly, after a few security incidents of a sufficient scale and damage happen, like a crash of a Critical National Infrastructure (CNI) provider or a massive leak of classified documents – governments on both sides of the Atlantic will probably rush to severely regulate use of AI, possibly creating a new AI winter.”