Microsoft 365 Copilot DLP Bypass Bug
Analysis based on 16 articles · First reported Feb 18, 2026 · Last updated Feb 20, 2026
The market is impacted by increased scrutiny on AI integrations in corporate productivity suites, potentially leading to stricter regulations and a demand for more robust security features in AI products. Microsoft's stock could face short-term negative pressure due to concerns about data privacy and trust.
Microsoft confirmed a software bug in its Microsoft===Microsoft 365 Copilot AI assistant that allowed it to summarize confidential emails from users' Sent and Drafts folders, effectively bypassing Data Loss Prevention (DLP) safeguards. The issue, reported in late January and tracked as CW1226324, affected Copilot Chat and the 'work tab' feature. Microsoft acknowledged the problem, attributing it to a code error, and began rolling out a fix in early February. While the scope of affected organizations and data exposure remains unclear, the incident has prompted customers and regulators to scrutinize AI integrations within corporate productivity suites. Microsoft stated that the bug did not provide unauthorized access to information but rather incorrectly processed content that should have been protected by DLP policies.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard