{"id":215371,"date":"2026-02-18T14:32:00","date_gmt":"2026-02-18T19:32:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/02\/18\/copilot-chat-bug-bypasses-dlp-on-confidential-email-the-register\/"},"modified":"2026-02-19T14:25:16","modified_gmt":"2026-02-19T19:25:16","slug":"copilot-chat-bug-bypasses-dlp-on-confidential-email-the-register","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/02\/18\/copilot-chat-bug-bypasses-dlp-on-confidential-email-the-register\/","title":{"rendered":"Copilot Chat bug bypasses DLP on &#8216;Confidential&#8217; email \u2022 The Register"},"content":{"rendered":"<p><a href=\"https:\/\/www.theregister.com\/2026\/02\/18\/microsoft_copilot_data_loss_prevention\/\">Copilot Chat bug bypasses DLP on &#8216;Confidential&#8217; email \u2022 The Register<\/a><\/p>\n<p><a href=\"https:\/\/www.theregister.com\/2026\/02\/18\/microsoft_copilot_data_loss_prevention\/\">https:\/\/www.theregister.com\/2026\/02\/18\/microsoft_copilot_data_loss_prevention\/<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-02-18 14:32:00<\/a><\/p>\n<p>Source Domain: <a href=\"www.theregister.com\">www.theregister.com<\/a><\/p>\n<p>The bot couldn&#8217;t keep its prying eyes away. Microsoft 365 Copilot Chat has been summarizing emails labeled \u201cconfidential\u201d even when data loss prevention policies were configured to prevent it.<\/p>\n<p>Though there are data sensitivity labels and data loss prevention policies in place for email, Copilot has been ignoring those and talking about secret stuff in the Copilot Chat tab. It&#8217;s just this sort of scenario that has led 72 percent of S&#038;P 500 companies to cite AI as a material risk in regulatory filings.\u00a0<\/p>\n<p>Redmond, earlier this month, acknowledged the problem in a notice to Office admins that&#8217;s tracked as CW1226324, as reposted by the UK&#8217;s National Health Service support portal. Customers are said to have reported the problem on January 21, 2026.<\/p>\n<p>&#8220;Users&#8217; email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat,&#8221; the notice says. &#8220;The Microsoft 365 Copilot &#8216;work tab&#8217; Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured.&#8221;<\/p>\n<p>Microsoft explains that sensitivity labels can be applied manually or automatically to files as a way to comply with organizational information security policies. These labels may function differently in different applications, the company says.<\/p>\n<p>The software giant&#8217;s documentation makes clear that these labels do not function in a consistent way.<\/p>\n<p>&#8220;Although content with the configured sensitivity label will be excluded from Microsoft 365 Copilot in the named Office apps, the content remains available to Microsoft 365 Copilot for other scenarios,&#8221; the documentation explains. &#8220;For example, in Teams, and in Microsoft 365 Copilot Chat.&#8221;<\/p>\n<p>DLP, implemented through applications like Microsoft Purview, is supposed to provide policy support to prevent data loss.\u00a0<\/p>\n<p>&#8220;DLP monitors&#8230;<\/p>\n<p><a href=\"https:\/\/www.theregister.com\/2026\/02\/18\/microsoft_copilot_data_loss_prevention\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Copilot Chat bug bypasses DLP on &#8216;Confidential&#8217; email \u2022 The Register https:\/\/www.theregister.com\/2026\/02\/18\/microsoft_copilot_data_loss_prevention\/ Publish Date: 2026-02-18&#8230;<\/p>\n","protected":false},"author":1,"featured_media":215372,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/regmedia.co.uk\/2022\/05\/03\/cyberspy_laptop_shutterstock.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26],"class_list":["post-215371","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215371"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=215371"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215371\/revisions"}],"predecessor-version":[{"id":215373,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/215371\/revisions\/215373"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/215372"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=215371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=215371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=215371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}