Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Microsoft 365 Copilot Chat had a bug that could let it process and return content from some “Confidential”-labeled emails in a user’s Outlook desktop Drafts or Sent Items. Microsoft said the issue did not let anyone access information they were not already authorized to see, and reported that it deployed a worldwide configuration update for enterprise customers by February 19, 2026. That narrows the alarming original headline: the incident was a real failure of a content-protection control, but the available evidence does not show that Microsoft indiscriminately uploaded all confidential email, exposed messages to strangers, or used them to train a public AI model.
What happened
The incident involved Microsoft 365 Copilot Chat in an enterprise Microsoft 365 environment. In a specific Outlook desktop scenario, Copilot could return or summarize content from emails that were labeled Confidential, authored by the user, and stored in that user’s Drafts or Sent Items.
Those messages were supposed to be excluded from Copilot processing under the intended protection behavior. Microsoft characterized the problem as a bug, not a feature. It was tracked as CW1226324. The incident-specific details and Microsoft’s statement were reported by Neowin.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsThe word “uploading” can suggest that Microsoft took every confidential message and sent it somewhere indiscriminately. The evidence supports a narrower description: during Copilot interactions, certain protected messages could enter the summarization path despite the expected exclusion. The report does not establish that every message with that label was processed, that this happened without a Copilot interaction, or that the affected content crossed tenant boundaries.
#1 Best Overall
Was this a data breach?
Microsoft said the bug did not provide access to information users were not already authorized to see. On the available evidence, this was not described as an account compromise or a cross-tenant exposure. There is no reported evidence that strangers or other organizations received the emails.
That access-boundary statement does not make the incident inconsequential. A person can be permitted to read a message while an organization separately intends to prevent an AI assistant from processing it. The failure was that the intended protection for these messages did not work as expected. Whether that triggers an organization’s own legal, regulatory, contractual, or internal notification duties depends on its obligations and the circumstances; Microsoft’s statement alone cannot decide that question.
Nor does the incident establish that customer email was used to train a general-purpose public model. Copilot can use authorized Microsoft 365 content as grounding context to answer a request; that is different from model training. Microsoft says its enterprise data protections apply to Copilot prompts and responses and that customer data is not used except as instructed. That is Microsoft’s stated commitment, not a conclusion proven by this incident. See Microsoft’s enterprise data-protection documentation.
Rank #2
Who may have been affected—and what is unknown
The reported scope is enterprise Microsoft 365 customers using Copilot Chat with the affected Outlook desktop scenarios. The messages were in the user’s own Drafts or Sent Items. The available reporting does not show that consumer Outlook.com accounts or every Copilot surface were affected. Do not assume the same behavior applied to Outlook on the web or mobile, Teams, Word, Excel, PowerPoint, or consumer Copilot.
Microsoft has not provided a public count of affected tenants, users, or messages in the sources reviewed here, nor a complete public incident report. The evidence also does not establish whether any customer’s Copilot response was copied, forwarded, or retained elsewhere. Those limits matter: neither “all confidential email was exposed” nor “no sensitive content appeared in a response” is supported as a universal claim.
Incident timeline
- January 21, 2026: Customers reportedly first discovered the issue. This is the reported discovery date, not necessarily the date the bug began.
- February 10, 2026: Microsoft reportedly began deploying a fix in stages.
- February 18, 2026: The issue received broad media attention.
- February 19, 2026: Microsoft told Neowin that a configuration update had been deployed worldwide for enterprise customers and that the issue had been addressed.
These dates and the fix description come from Neowin’s report of Microsoft’s statement. A worldwide rollout report is useful, but an administrator should still check tenant-specific service information rather than infer local status from a general statement.
Rank #3
Why labels, encryption, and DLP are not interchangeable
A sensitivity label classifies information and may also apply encryption and usage rights. The word “Confidential” on a message is not automatically a universal technical block on every kind of processing: the effect depends on how the organization configured the label, protection, client, workload, and policies.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Microsoft’s normal Copilot architecture is designed to respect users’ permissions and applicable information-protection controls. For encrypted content, interaction can depend on rights such as VIEW and EXTRACT. Microsoft also documents distinct handling for S/MIME-protected messages; its guidance says those messages are not returned by Copilot, and Copilot is unavailable in Outlook when an S/MIME-protected email is open. These are general documented behaviors, not a claim that every configuration behaves identically. See Microsoft’s Copilot architecture and data-protection guidance.
Microsoft Purview DLP can be configured to restrict Copilot from processing content matching specified conditions, including sensitivity-label conditions. A policy aimed at files, however, is not necessarily a policy that covers Copilot and Copilot Chat interactions. Administrators should confirm the relevant policy location, scope, and enforcement mode in their own environment. Microsoft’s Purview guidance for Copilot describes controls for labels, DLP, auditing, and AI-risk monitoring.
Rank #4
What administrators should check
There is no incident-specific customer remediation procedure in the available reporting. These checks can help an organization establish its own exposure and control status; portal labels and available records can vary by tenant and licensing.
- Check tenant service advisories. Search the Microsoft 365 admin center’s service-health information for CW1226324 and review the advisory and its status for your tenant.
- Confirm tenant-level remediation. Use service health or Microsoft support channels to verify the relevant configuration update reached your tenant. Do not treat a general worldwide rollout statement as tenant-specific proof.
- Review available Copilot audit activity. Investigate the incident period for relevant Copilot Chat or Outlook interactions. Microsoft documents auditing and related Purview controls, but the records available to you depend on configuration, licensing, and retention.
- Identify the potentially relevant users and messages. Determine who had Copilot access during the period and review potentially sensitive Confidential-labeled messages in Drafts and Sent Items. The reported scope does not justify assuming every labeled message was affected.
- Look for downstream handling. Where records permit, assess whether a sensitive response was copied, forwarded, or used in another document or workflow.
- Test policy behavior safely. Use non-production sample messages to verify that DLP policies cover the Microsoft 365 Copilot and Copilot Chat policy location, apply to the intended users and content, and are in enforcement rather than simulation mode where blocking is required.
- Check label protection rights. For encrypted labels, confirm that usage rights—including VIEW and EXTRACT where relevant—match the organization’s intended handling of AI processing.
- Review permissions and connected data sources. Copilot’s responses depend on accessible content, so check for oversharing in Exchange, SharePoint, OneDrive, Teams, and connected sources as part of the broader assessment.
- Escalate and document. Ask legal, privacy, and compliance teams whether the facts create a review or notification obligation. Record the scope, evidence, logging limitations, tests, and conclusions.
Microsoft’s documentation covers Purview controls for Copilot, data protection and auditing, and enterprise data protection.
Free tools Windows power users keep installed
One-click scans. No signup required.
How users and organizations can reduce risk
Users should apply the correct organization-provided label to sensitive messages, but should not assume that typing “confidential” in a subject line creates technical protection. Organizations should decide which content Copilot may process, then configure and test labels, encryption, and Copilot-specific DLP controls to match that decision. For high-risk content, a label that applies enforceable protection may offer a different control than a classification-only label.
Best Value
Organizations should also maintain appropriate audit retention and an incident process for AI-generated responses. A response can become a new exposure point if someone copies sensitive content into an unprotected email or document. Microsoft’s Zero Trust guidance for Copilot discusses the need to govern data access and reduce oversharing alongside the AI controls themselves.
The practical lesson is not that all Copilot use is unsafe, nor that a sensitivity label guarantees exclusion from every processing path. It is that access permissions, AI-processing policy, label configuration, and downstream handling are separate controls that should be tested together.
What remains unresolved
The reported update does not answer how many tenants or messages were affected, provide a complete root-cause analysis, or say whether Microsoft will publish a formal post-incident report. The evidence reviewed also does not establish the impact beyond the described enterprise Outlook desktop scenario. Organizations with potentially affected content should base their assessment on tenant advisories, available logs, and their own obligations—not on assumptions that the incident was either universal or harmless.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

