Microsoft has confirmed a
bug in Microsoft 365 Copilot that caused the AI to read and summarize confidential emails from users' Sent Items and Drafts folders, bypassing data loss prevention (DLP) policies and sensitivity labels intended to protect sensitive information. The issue, first detected on January 21, 2026, stemmed from unintended programming behavior and affected the Copilot "work tab" chat feature. Microsoft described it as a code error and began rolling out a staggered fix starting February 10, 2026, though a complete resolution is still pending. Affected enterprise customers are being notified through admin channels.