Copilot Chat bug bypasses DLP on 'Confidential' email
Briefly

Copilot Chat bug bypasses DLP on 'Confidential' email
"Redmond, earlier this month, acknowledged the problem in a notice to Office admins that's tracked as CW1226324, as reposted by the UK's National Health Service support portal. Customers are said to have reported the problem on January 21, 2026. "Users' email messages with a confidential label applied are being incorrectly processed by Microsoft 365 Copilot chat," the notice says. "The Microsoft 365 Copilot 'work tab' Chat is summarizing email messages even though these email messages have a sensitivity label applied and a DLP policy is configured.""
"Microsoft explains that sensitivity labels can be applied manually or automatically to files as a way to comply with organizational information security policies. These labels may function differently in different applications, the company says. The software giant's documentation makes clear that these labels do not function in a consistent way. "Although content with the configured sensitivity label will be excluded from Microsoft 365 Copilot in the named Office apps, the content remains available to Microsoft 365 Copilot for other scenarios," the documentation explains. "For example, in Teams, and in Microsoft 365 Copilot Chat.""
Microsoft 365 Copilot Chat summarized emails labeled "confidential" even when sensitivity labels and DLP policies were configured to prevent processing. Customers reported the behavior on January 21, 2026, and Microsoft acknowledged the issue in a notice tracked as CW1226324, reposted by the UK's National Health Service support portal. The notice states that messages with confidential labels are being incorrectly processed and summarized by the Copilot work tab Chat despite applied sensitivity labels and DLP configuration. Microsoft documents that sensitivity labels can be applied manually or automatically, may behave differently across applications, and that some labeled content can remain available to Copilot in other scenarios.
Read at Theregister
Unable to calculate read time
[
|
]