Skip to content

Leadership1 publisher3 min readPublished

Copilot Chat read confidential mail for weeks past the DLP policy set to stop it

A February 2026 Microsoft admin advisory and the EchoLeak flaw before it both began in AI features vendors switched on inside already-approved apps, putting the missing review squarely on the operator's side of the line.

The Board Room · Leadership desk

Illustration accompanying Copilot Chat read confidential mail for weeks past the DLP policy set to stop it

What happened

  • Microsoft admin advisory CW1226324, issued in February 2026, confirmed Copilot Chat had spent weeks reading and summarizing emails marked confidential from Sent Items and Drafts, past the DLP policies set to block that.
  • Eight months earlier, researchers disclosed EchoLeak, CVE-2025-32711, a zero-click Copilot vulnerability rated CVSS 9.3 that exfiltrated enterprise data through one crafted email.
  • Both incidents began inside an AI feature the vendor shipped into an app the enterprise had already approved, not through a stolen credential or a misconfigured permission.
  • CloudEagle.ai chief executive Nidhi Jain writes that SSPM tooling covers configuration drift, over-permissioned users and OAuth grants, and not the AI features arriving in sanctioned apps.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure On Jain's account, a vendor's AI feature may route your data to OpenAI, Anthropic or Google under a contract that never names them, which puts regulated data with a subprocessor your legal team never assessed.
  • decision Write-back is now a live choice rather than a setting: with Agentforce, Now Assist and Rovo shipping write-enabled in many tenants, declining to decide leaves the vendor's default in force inside your CRM and ITSM.
  • constraint The security budget already committed to SaaS posture management does not stretch across this surface, so the work lands on teams whose tooling spend is spoken for and whose headcount was sized for a narrower scope.

What makes CW1226324 a governance item rather than a patch note is the kind of failure it describes. A data loss prevention rule was configured to block exactly the behaviour that occurred, and for weeks it did not block it [1]. The cause sat in the AI feature itself rather than a stolen credential or a misconfigured permission [3]. That combination takes away the evidentiary value of the control itself: an audit that samples policy configuration would have returned a clean result for the entire period Copilot Chat was summarising confidential mail out of Sent Items and Drafts [1].

One reading of both incidents is that the disclosure process worked as intended. EchoLeak carries a CVE identifier and a CVSS 9.3 rating [2], which is what a vulnerability looks like when it has been found, scored and published. The harder item in Jain's account is not a bug anyone will patch on your behalf: Salesforce Agentforce, ServiceNow Now Assist and Atlassian Rovo default to write-enabled in many tenants, on her reading [7], and those are configuration choices sitting in your tenant. The record we have covers the bypass, and remediation is a separate, unpublished matter. The advisory as described confirms the bypass and its duration; what happened afterwards falls outside that confirmation [14].

Nidhi Jain, who wrote the piece, is chief executive of CloudEagle.ai, which sells governance of SaaS, identities and AI agents [5], so the prescription tracks the product, and her broader framing that every SaaS app shipped an AI feature in the past 18 months is characterisation rather than measurement [16]. The two incidents have public identifiers, and the Gartner figure she cites gives the rate: moving from under 5% of enterprise applications carrying task-specific AI agents in 2025 to 40% by the end of 2026 [4] is at least an eightfold increase inside roughly a year [2].

The tradeoff is between write-back convenience and ownership. Turning off features that write to production by default, then enabling them per use case with a named human owner [9], costs exactly the speed the business enabled them for, and it costs somebody's headcount to hold the names. The cheaper half is already paid for: Jain notes that Microsoft Purview, Google DLP and Salesforce Shield offer AI-aware controls most enterprises are licensed for but have not configured [10]. The version of this decision available this quarter is a bounded audit of the top 20 vendors and their admin-console usage reports [13]. Next quarter's consequence is structural, because a shipped feature arrives without a purchase order, and the procurement event that used to trigger a security review no longer fires. Whoever accepts the inventory accepts a standing intake, and the 40% projection is the rate at which that intake fills [4].

What to watch

  • Whether Microsoft publishes remediation detail or tenant scope for CW1226324, which the current account of the advisory does not carry.
  • Whether Gartner revises the 40%-by-end-of-2026 agent projection, and what it restates the sub-5% 2025 baseline as.
  • Whether any large customer forces model-provider disclosure into a renewed DPA, which is the one step in Jain's list that needs a counterparty to agree.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories