Microsoft 365 Copilot bug exposes governance gap
IT Security Guru reports that for several weeks earlier this year Microsoft 365 Copilot read and summarised confidential emails despite sensitivity labels and Data Loss Prevention (DLP) policies being correctly configured to block that behaviour. The incident is tracked as bug CW1226324, per IT Security Guru. According to IT Security Guru, Microsoft said users only accessed information they were already authorised to see. The article argues the core failure was architectural: the same platform hosted the AI, the governance controls, and the telemetry, creating a single point of failure with no independent detection for weeks. IT Security Guru places this issue in a broader pattern affecting enterprise AI tools such as Google Gemini for Workspace and Salesforce Einstein.

















