A critical security flaw in Microsoft 365 Copilot lets the AI assistant summarize emails protected by confidentiality sensitivity labels.
This bypasses Data Loss Prevention (DLP) policies, exposing sensitive organizational data to unauthorized AI processing.
Tracked under Microsoft reference CW1226324, the issue surfaced on February 4, 2026, and persists as of mid-February.
Copilot’s “Work Tab” Chat feature pulls content from users’ Sent Items and Draft folders, ignoring labels meant to block access.
Normally, these labels paired with DLP rules stop AI tools from handling confidential emails. But the bug renders those safeguards useless, letting summaries reveal restricted information.
This hits organizations hard, especially in regulated sectors like healthcare, finance, and government, where such controls meet strict compliance needs.
The UK’s National Health Service (NHS) reported it internally as INC46740412, showing real-world fallout for public users of Microsoft 365.
Any tenant with Copilot enabled and email labels active faces risk, as the flaw affects broad environments.
Root Cause and Ongoing Remediation
Microsoft pinned the problem on a code-level defect during its probe. Copilot grabs labeled items from key folders without proper checks, feeding them into AI summaries despite DLP blocks.
This undermines core data governance, turning a helpful tool into a potential leak vector.
As of February 11, 2026, Microsoft rolled out fixes to affected setups and contacted some users for validation.
Deployment continues but isn’t complete, leaving gaps. Admins should watch the Microsoft 365 admin center for CW1226324 updates and scan Copilot logs for odd access to labeled data. For now, teams handling sensitive emails might pause Copilot use.
| Reference ID | Description | Status | First Reported |
|---|---|---|---|
| CW1226324 | Copilot summarizes confidential emails bypassing DLP | In remediation | Feb 4, 2026 |
| INC46740412 | NHS internal incident for Copilot label bypass | Reported | Feb 2026 |
This incident highlights AI’s double edge in enterprise tools. While Copilot boosts productivity, flaws like this expose how quickly controls fail.
Organizations must audit AI integrations against DLP setups. Microsoft urges vigilance until full resolution. Check DLP policies here for best practices.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google