Security1 publisher2 min readPublished
Hundreds of contractors review the photos users upload to Microsoft's Copilot
At least hundreds of human contractors grading Microsoft's Copilot see users' prompts and uploaded images, internal documents seen by 404 Media show. For employers, anything staff send the assistant now counts as data handed to an outside party.
The Watch · Security desk

What happened
- The contractors are paid to grade the quality of Copilot's output, and their job does not include flagging or vetting offensive or inappropriate uploads.
- Reviewers described requests to shorten a real woman's skirt or enlarge breasts, pro-anorexia content, and one prompt that appeared aimed at a lewd image of young girls.
- The cache 404 Media obtained includes instruction guides, contractor message-board threads, and real Copilot user prompts and pictures.
- 404 Media reported earlier this month that OpenAI has thousands of contractors who in some cases review real ChatGPT prompts.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Real user pictures left the review queue and reached a reporter inside that document cache, so the contract workforce is a second point where an upload can leak after it leaves the company.
- decision Acceptable-use and data-handling policies that treat Copilot as a private tool have to reclassify an upload as a disclosure to the vendor's contract reviewers.
- precedent With human review of real prompts now documented at both Microsoft and OpenAI, the safe default for any other assistant vendor is the same assumption until it states otherwise in writing.
No attacker is involved. The people seeing these uploads are Copilot's quality reviewers, and the documents describe their job [3]. A reviewer gets the user's prompt and the images it produced, then judges whether the edit did what was asked [4]. Two edited versions sit side by side. The instructions ask for instinct. "Your gut reaction as a human viewer matters," one guide reads [5]. "When in doubt go with your first impression," it continues [6]. According to 404 Media, the point is to make the chatbot's responses better. The reviewers are not there to filter offensive images or to serve another safety purpose [10].
For a data-handling policy, the relevant detail is what the reviewer sees unredacted. 404 Media says a user uploading a picture of themselves or someone else probably expects it to stay between them and the tool [11]. "Faces are always uncensored, and many of the prompts are sexual in nature and dubiously consensual," one person who works on the prompts told 404 Media. The person spoke anonymously because they were not permitted to talk to the press [7]. So a photo of a colleague or a customer sent to Copilot for editing can land in front of a contractor with the face intact.
On frequency, 404 Media's own word is "sometimes" [1]. The report does not say what share of Copilot traffic is sampled, which Copilot products feed the queue, or whether business accounts are excluded. The documents show that real user uploads reach human reviewers. They do not show how often any single upload does.
That gap limits how far the finding goes. An organisation cannot size its exposure from this reporting, and it cannot assume a business tier is carved out. What it can rely on is that human review of real user material is documented at two assistant vendors in the same month [1].
What to watch
- A Microsoft statement on what share of Copilot prompts and uploads are sampled for human review, and whether business-tier Copilot accounts are excluded.
- Any change to Copilot's privacy terms or a user-facing opt-out from human review of uploads.
- Further 404 Media reporting that finds human review of uploaded images at assistant vendors beyond Microsoft and OpenAI.