WorkMay 26, 2026via Simon Willison
Microsoft Copilot Cowork Exfiltrates Files
Why it matters
A major AI product deployment reveals a data exfiltration vulnerability, raising urgent questions about enterprise AI security governance and the readiness of AI agents to handle sensitive workflows at scale.
Key signals
- Microsoft Copilot Cowork affected by file exfiltration vulnerability
- Published May 26, 2026 on simonwillison.net
- Affects enterprise deployment of AI agents in collaborative workflows
- Suggests AI product safety/governance gap in production systems
The hook
Microsoft's Copilot Cowork has a critical security flaw. Files are being exfiltrated. Here's what enterprise leaders need to know.