Microsoft Copilot Data Exposure Risk: Enterprise Prompts Can Leak Through Shared Context Windows

Researchers demonstrate that AI copilot tools can inadvertently expose sensitive enterprise data through shared context windows. Microsoft issues guidance for tenant isolation.

Security researchers have demonstrated that enterprise AI copilot tools — including Microsoft Copilot and GitHub Copilot — can inadvertently expose sensitive organizational data through shared context windows. The vulnerability arises when the AI model incorporates data from one conversation into responses for another user in the same tenant.

Microsoft has issued guidance for tenant isolation, recommending that organizations configure strict data boundaries, disable cross-user context sharing for sensitive workloads, and implement data loss prevention (DLP) policies for AI interactions.

The finding has accelerated enterprise adoption of AI security posture management (AI-SPM) tools, with the market projected to reach $3.5 billion by 2027. Organizations are advised to treat AI copilots as new data endpoints requiring the same security controls as any other enterprise application.

Source: Microsoft Security Response Center