Technology
Why the Microsoft 365 Copilot bug matters for data security
NEWYou can now listen to Fox News articles!
You trust your email security settings for a reason. So when an AI assistant quietly reads and summarizes messages marked confidential, that trust takes a hit.
Microsoft says a bug in Microsoft 365 Copilot allowed its AI chat feature to process sensitive emails since late January.
The issue bypassed Data Loss Prevention policies that organizations rely on to protect private information. Put simply, emails that were supposed to stay locked down were being summarized anyway.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter
Microsoft 365 Copilot’s work chat interface sits at the center of the issue after a bug allowed it to summarize confidential emails. (Microsoft)
Microsoft 365 Copilot bug summarized confidential emails
Microsoft says a coding error impacted Microsoft 365 Copilot Chat, specifically the “work tab” feature. The AI assistant helps business users summarize content, draft responses and analyze information across Word, Excel, PowerPoint, Outlook and OneNote.
Beginning Jan. 21, an internal bug labeled CW1226324 caused Copilot to read and summarize emails stored in Sent Items and Drafts folders.
The real concern runs deeper. Several of those messages carried confidentiality or sensitivity labels.
Companies apply those labels along with DLP policies to block automated systems from accessing restricted content. Despite those safeguards, Copilot still generated summaries.
We reached out to Microsoft, and a spokesperson provided CyberGuy with the following statement:
“We identified and addressed an issue where Microsoft 365 Copilot Chat could return content from emails labeled confidential authored by a user and stored within their Draft and Sent Items in Outlook desktop. This did not provide anyone access to information they weren’t already authorized to see. While our access controls and data protection policies remained intact, this behavior did not meet our intended Copilot experience, which is designed to exclude protected content from Copilot access. A configuration update has been deployed worldwide for enterprise customers.”
Why the Microsoft 365 Copilot bug matters for data security
AI tools feel helpful. They save time and reduce busy work. But they also rely on deep access to your data. When safeguards fail, even temporarily, sensitive content can move in ways you did not expect.
YOUR PHONE SHARES DATA AT NIGHT: HERE’S HOW TO STOP IT
For businesses, that could mean:
Legal discussions summarized outside intended controls
Financial projections processed despite restrictions
HR communications are exposed to automated analysis
Even if no data leaves the organization, the bypass itself raises concerns about how AI integrates with enterprise security systems.
Business users rely on Copilot to streamline work, but a recent bug raised concerns about how it handles sensitive email content. (Microsoft)
How Microsoft is fixing the Microsoft 365 Copilot bug
Microsoft says it began rolling out a fix in early February. The company continues to monitor deployment and is contacting some affected users to verify the fix works.
However, Microsoft has not provided a final timeline for full remediation. It has also not disclosed how many organizations were affected.
The issue is tagged as an advisory, which usually signals limited scope or impact. Still, many security professionals will want deeper clarity before feeling comfortable.
What this Microsoft 365 Copilot issue reveals about AI security
This incident highlights something many companies are wrestling with right now. AI assistants sit inside productivity platforms. They need access to email, documents and collaboration tools to work well.
TIKTOK AFTER THE US SALE: WHAT CHANGED AND HOW TO USE IT SAFELY
At the same time, those platforms contain your most sensitive information. When AI features expand quickly, security policies must evolve just as fast. Otherwise, even a small code mistake can create unexpected exposure.
The Copilot chat feature was designed to boost productivity, yet a code error let it process emails labeled confidential. (Microsoft)
Ways to stay safe after the Microsoft 365 Copilot bug
If your organization uses Microsoft 365 Copilot, here are practical steps to reduce risk:
1) Review Copilot access settings
Work with your IT team to confirm which folders and data sources Copilot can access.
2) Revalidate DLP policies
Test sensitivity labels and DLP (Data Loss Prevention) rules to ensure they block AI processing as intended.
3) Monitor advisory updates
Stay current on Microsoft service alerts and verify that the fix is fully deployed in your tenant.
4) Limit AI scope during investigations
If you have concerns, consider temporarily restricting Copilot features until verification is complete.
5) Train employees on AI boundaries
Remind staff that AI assistants can process drafts and send messages. Encourage careful handling of sensitive content.
6) Audit Copilot activity logs
Review audit logs to see whether Copilot accessed or summarized labeled emails. This helps determine actual exposure rather than assumed risk.
7) Review sensitivity label configuration
Confirm that confidential labels are configured to block AI processing where required. Misconfigured labels can create gaps even after a bug is fixed.
8) Reassess retention and draft policies
Because the issue involved Sent Items and Drafts, evaluate whether sensitive drafts should be stored long-term or deleted after sending.
9) Limit Copilot to specific user groups
Instead of enabling Copilot organization-wide, consider a phased deployment to departments with lower sensitivity exposure.
10) Conduct a post-incident security review
Use this moment to reassess how AI tools integrate with compliance controls. Treat it as a learning opportunity rather than a one-time glitch.
Pro Tip: This Copilot bug centers on enterprise controls. Even so, AI tools operate on your devices and accounts, so keeping software up to date and using strong antivirus software adds an important layer of defense. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
Considering a more private email provider
Enterprise AI bugs raise a bigger question: how much access should email platforms have to your data in the first place? If you want an added layer of privacy beyond mainstream providers, privacy-focused email services are worth exploring.
Some offer end-to-end encryption, support for PGP encryption and a strict no-ads business model that avoids scanning messages for marketing purposes.
AI WEARABLE HELPS STROKE SURVIVORS SPEAK AGAIN
Many also allow you to create disposable email aliases, which can reduce spam and limit exposure if one address is compromised.
While no provider is immune to software bugs, choosing an email service built around privacy rather than data monetization can limit how much of your information is accessible to automated systems in the first place.
For individuals, journalists and small businesses especially, that added control can make a meaningful difference.
For recommendations on private and secure email providers that offer alias addresses, visit Cyberguy.com
Kurt’s key takeaways
AI assistants are becoming part of daily work life. They promise speed, efficiency and smarter workflows. But convenience should never outrun security.
This Copilot bug may have a limited impact. Still, it serves as a reminder that AI tools are only as strong as the guardrails behind them.
When those guardrails slip, even briefly, sensitive information can move in unexpected ways. As AI becomes more embedded in business software, trust will depend on transparency, fast fixes and clear communication.
Here is the real question: If your AI assistant can see everything you write, are you fully confident it respects every boundary you set? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report Get my best tech tips, urgent security alerts, and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide – free when you join my CYBERGUY.COM newsletter
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Valve is so behind on Steam Controller orders that some won’t ship until 2027
Valve has some good news and bad news about Steam Controllers. The good news: if you make a reservation for a Steam Controller, the company will now show you one of three estimates of when you’ll be able to actually order your gamepad: by September 2026, by December 2026, or sometime in 2027. The bad news: any reservations made today “indicate a 2027 date for shipping,” Valve says.
“We have no plans to stop making Steam Controller,” according to Valve. “But as we look at the current demand compared to how many we know we can make by the end of the year, we want to manage expectations as much as we can with regards to when folks can expect to receive their order.”
Valve’s very good new Steam Controller went on sale in early May, and the initial rush led some people to run into frustrating problems with trying to check out ahead of the controllers eventually going out of stock. A few days later, the company announced that it would be implementing a reservations queue for interested buyers so they could get on a waitlist. If you’re on the waitlist, when you get notified that a Steam Controller is ready for you to buy, you have 72 hours to actually make the order.
“When we launched Steam Controller last month, we quickly saw that initial demand exceeded our expectations,” Valve says. “Switching to a reservation queue has (hopefully) cut down on the headaches on the customer side, and for us it’s also been helpful as we plan ahead and try to get as many out as quickly as we are able.”
All three of Valve’s big hardware products were delayed from a planned early 2026 launch because of the component crisis, Valve still hasn’t announced when the Steam Machine PC or Steam Frame VR headset might go on sale. However, just yesterday, Valve officially launched its big SteamOS 3.8 update with support for the Steam Machine. It’s also been importing a lot of hardware into the US as of late.
Technology
McDonald’s AI drive-thru may take your next order
NEWYou can now listen to Fox News articles!
The next time you pull up to a McDonald’s drive-thru, the voice taking your order may not be human. McDonald’s is testing a new AI-powered system called ArchIQ at five U.S. locations. The company has not said where those restaurants are located. The voice assistant, nicknamed Archy, can take drive-thru orders and has shown it can handle both English and Spanish.
For anyone who has repeated “no pickles” into a speaker box more than once, this could sound helpful. However, if you remember McDonald’s last AI drive-thru experiment, you may also wonder whether your burger order could somehow turn into a bag full of surprise McNuggets.
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
WOULD YOU EAT AT A RESTAURANT RUN BY AI?
McDonald’s is testing an AI drive-thru system called ArchIQ at five U.S. restaurants. (Kurt “CyberGuy” Knutsson)
What is McDonald’s AI drive-thru?
ArchIQ is McDonald’s new AI system for restaurants. It can take drive-thru orders and also help with operations behind the scenes.
In a post on X, McFranchisee, an anonymous McDonald’s franchisee account, said the system is currently in five test stores and has processed more than one million transactions. The account also said about 90% of orders were completed without a human stepping in. That number sounds promising. Still, McDonald’s has not confirmed a nationwide launch date. For now, this remains a limited test.
The system also appears to connect with a bigger McDonald’s plan called “McDonald’s > NEXT.” CEO Chris Kempczinski described the strategy as a way to bring in more customers and improve restaurant productivity. The plan also includes menu changes, restaurant redesigns, technology upgrades and more focus on hospitality.
Why McDonald’s is testing AI ordering
Drive-thrus can get chaotic fast. Someone changes an order after the total appears. A child calls out from the back seat. Road noise makes the speaker hard to hear. Then the driver remembers the extra sauce after everything has already gone through. That is the type of pressure McDonald’s wants AI to handle.
If ArchIQ works well, it could help restaurants move cars through the line faster. It may also reduce mistakes during busy hours. Workers could then focus more on preparing food, handling payments and helping customers who need a real person.
ArchIQ also appears to have a management role. In the same X post, McFranchisee described Archy as a tool that could alert managers to bottlenecks or other issues before they slow down operations.
STARBUCKS USES CHATGPT TO SUGGEST DRINKS BASED ON MOOD AS EXPERT WARNS OF HIDDEN DOWNSIDES
The AI assistant, nicknamed Archy, can take drive-thru orders and may also help managers spot restaurant slowdowns. (McFranchisee)
McDonald’s tried AI drive-thru ordering before
This new test follows McDonald’s earlier AI drive-thru experiment with IBM. That program involved more than 100 restaurants. McDonald’s ended the test in 2024 after customers complained about order accuracy. Some mistakes also went viral, creating an embarrassing moment for McDonald’s and raising questions about whether the technology was ready for the drive-thru. Customers reported wrong items, strange quantities and other order mix-ups. That history is why this new test will get extra attention.
This time, McDonald’s is working with Google technology. McFranchisee also claimed every McDonald’s in the U.S. is getting Google Edge Cloud hardware in anticipation of the rollout. McDonald’s seems to believe the newer system can perform better than the last one. The real test will come when regular customers use it during real drive-thru rushes.
How McDonald’s AI drive-thru could help customers
If McDonald’s gets this right, the most obvious benefit is speed. An AI ordering system does not get tired during a long shift. It may also help more customers order in the language they prefer. That could make a busy drive-thru feel less frustrating, especially during breakfast or late-night hours.
The system may also ask clearer follow-up questions and catch missing details before the order reaches the kitchen. That would be a win for customers who want to get in, get their food and get on with the day.
The biggest problem with AI drive-thru orders
The biggest concern is accuracy. AI can still misunderstand people. That gets frustrating fast when you are trying to grab lunch between errands or get your kids fed from the back seat. A wrong order wastes time. It also puts workers in the position of fixing a mistake the machine made.
There is also the customer service side. Some people like hearing a real person at the speaker. Others may find an AI voice cold or annoying, especially if the system gets confused.
Then there is the privacy question. If an AI system takes your order, customers may wonder what gets collected, how long it is kept and who can access it. McDonald’s has not publicly explained those specifics for this current ArchIQ test.
ALEXA+ LETS YOU ORDER FOOD LIKE A REAL CONVERSATION
A drive-thru menu board stands outside a McDonald’s restaurant in Hercules, Calif., on Oct. 23, 2024, amid an E. coli outbreak linked to onions in Quarter Pounder sandwiches that has sickened dozens and killed one person across the U.S. (David Paul Morris/Bloomberg via Getty Images)
How to avoid AI drive-thru mistakes
Before you leave the drive-thru, take a moment to check the order screen. Make sure the items match what you said. Listen when the system repeats your order. Keep your receipt until you confirm the food is right.
Also, avoid sharing extra personal details at the speaker box. Your order should only require your food choices and payment.
If the AI gets confused, ask for a crew member. You do not need to keep going back and forth with a machine over fries.
What this means for you
For now, you probably will not notice a change at your local McDonald’s. The ArchIQ test appears limited to five U.S. restaurants, and the company has not said when it could expand.
Still, this gives customers a preview of where fast food may be heading. AI could soon play a bigger role in how restaurants take orders and manage the kitchen. That may speed up the line, though it could also make the experience feel less personal.
Watch the CyberGuy Live replay: Lock Down Your Phone in 30 Minutes
Your phone holds your email, passwords, photos, banking apps and personal data. In this free CyberGuy Live replay, Kurt the CyberGuy walks you step by step through simple phone security fixes you can do at your own pace. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Watch the replay and get our checklist here: CyberGuyLive.com
Kurt’s key takeaways
McDonald’s clearly wants AI to play a bigger role in its restaurants. From a business point of view, the idea makes sense. Shorter drive-thru lines could help franchisees and customers. Better restaurant data could also help managers fix problems faster. But I still want the human backup. Food orders can be messy because people are messy. We change our minds. We talk over each other. We forget the extra ketchup until the last second. AI may handle much of that one day. For now, I would treat it like any busy drive-thru interaction. Speak clearly. Check the order. Do not pull away until you know your food is right.
Would you trust an AI voice to take your McDonald’s order, or do you still want a real person on the other end of the speaker? Let us know by writing to us at Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
Technology
Midjourney goes from generating cat images to full-body ultrasound scans
Midjourney CEO David Holz just showed off the company’s first hardware product and plans to build a San Francisco spa, which he admitted is a bit different from the “cat pictures” produced by its AI image generator. Dubbed The Midjourney Scanner, it’s an ultrasound-based full-body scanner that uses a ring of sensors to capture vertical slices of the inside of your body, looking at the composition of your muscle, fat, bone, and organs to start. Holz said ideally, you could do this once a year or every single day, as it “aims for image quality comparable to MRI in many ways.”
He mentioned that one way he’d like to use it would be to see how his body changes in response to diet and workout changes, saying, “I’m not the most measured man on Earth yet, you know, but maybe I want to have that daily [measurable information].” A set of job listings advertises the company’s goal as trying to “build and launch the world’s first full-body ultrasound CT scanner, ultimately bringing safe, fast, and high fidelity preventative scanning to billions via a magical spa experience.”
The Midjourney Scanner was developed in a partnership with ultrasound tech company Butterfly Network, which said it uses “40 Butterfly Ultrasound-on-Chip imaging modules per system.”
The scanning process starts with stepping onto a platform that drops down into the water on rails through a ring of thousands of transducers that create ultrasonic waves. It then records the ripples passing through your body to analyze them and create detailed 3D images. The scan takes about 60 seconds. Holz said about a dozen people have been scanned so far.
It starts by stepping into a shallow pool of golden light. You then begin to descend into the water. Your body passes through a ring of underwater sensors, each acting like a dolphin, using its echolocation. The sensors send ultrasonic sound waves through your body from every angle. With enough waves, and enough angles, we form an image of what’s happening inside your body.
It combines those sensors with two petaflops of processing power. But after watching the livestreamed reveal, I’m still unclear on what Midjourney’s AI image generation tech exactly has to do with the Midjourney Medical effort, beyond an alternative business for otherwise-unused AI compute.
Holz hopes to put 10 of the scanners into a Midjourney Spa location in San Francisco’s Union Square that will open before the end of 2027 and offered to scan the hands of attendees at its launch event. The Midjourney Spa will have a gym, saunas, and cold plunges to go along with the hot tub–equipped scanning rooms where visitors will get into the water to be scanned.
He did mention that various medical applications would require FDA clearances, but for now, Midjourney Medical says it’s working on “body composition maps” that don’t require the same level of clearance as diagnostic imaging. It also says the “library of scans” users create can be shared with doctors, AI health tools, or others, and that, “We take data privacy seriously — more details on our data policies will come as we get closer to launch.”
Holz suggested that eventually these scans could become better than an MRI, without radiation, powerful magnets, or other complicating factors, to get a look at what’s going on inside people’s bodies “real fast.” In response to a question, he imagined a future where the FDA had a class of devices to look at “weird” things and allowed people to “just try to get as much data as we can.”
-
Entertainment2 minutes agoReview: ‘Sugar,’ with Colin Farrell as an alien private eye, gets a new and improved second season
-
Politics12 minutes agoPolitical watchdog fines Newsom for failing to report $5.5M in solicited donations on time
-
Sports24 minutes agoGoalkeeper Raúl Rangel’s elite play and South Korea’s mistake help Mexico advance
-
World32 minutes agoUS-Iran talks postponed as Israel attacks Lebanon
-
News57 minutes agoLuigi Mangione’s lawyers withdraw plans for psychiatric defense
-
New York2 hours agoVideo: Knicks Fans Celebrate With Ticker-Tape Parade
-
Los Angeles, Ca2 hours agoArmed, dangerous CHP pursuit suspect tied to double homicide in Pomona
-
Detroit, MI3 hours agoFirst responders honored after rescuing 12 people from capsized sailboats near Belle Isle