Microsoft confirmed a code issue in Microsoft 365 Copilot that allowed the AI to access and summarize confidential emails. The bug bypassed data loss prevention (DLP) policies intended to shield sensitive corporate information.
The glitch specifically affected emails in Sent Items and Drafts folders marked with confidential labels. Customers first reported the security failure on January 21, 2026.
Microsoft acknowledged the vulnerability in a service health advisory. The company began deploying a fix to affected systems in early February 2026.
This incident prompts scrutiny regarding the testing and security oversight of AI tools integrated with sensitive corporate data environments.