Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Risk»Operational risk»Your AI’s guardrails just failed. Now what? (Page 15)
Operational risk

Your AI’s guardrails just failed. Now what?

April 17, 20265 Mins Read
AI guardrails - two green coloured digital rails hold a flow of digital data with bounds.

For weeks in January and early February 2026, Microsoft 365 Copilot read and summarised confidential emails despite sensitivity labels and data loss prevention (DLP) policies being correctly configured to block such behaviour. This was confirmed by Microsoft in Service Advisory CW1226324. The bug affected emails in users’ Sent Items and Drafts folders, meaning legal communications, business agreements, or sensitive health information could all be processed by an AI that explicit organizational policies said should never touch.

Microsoft claimed that users only accessed information they were already authorised to see. This may be technically accurate, as Copilot operates within the user’s mailbox context, but sensitivity labels weren’t in place to stop users from reading their own email; they were there to stop the AI from processing confidential content. For several weeks, the AI processed it anyway.

A single point of failure

The incident made visible the fact that every control designed to keep Copilot away from confidential data – sensitivity labels, data loss prevention (DLP) policies, and access restrictions – lived inside the same platform as Copilot itself. There was no independent layer, no secondary check, no safety net.

Nobody builds a vault where the door lock, the alarm, and the surveillance cameras all run through a single circuit breaker. But that’s what happened here. Microsoft was the AI provider, the security control provider, and the only entity with visibility into whether those controls were working. Therefore, when the guardrails failed, organizations had no independent way to detect the failure.

An industrywide problem

It’s important to note that Copilot is a powerful tool, and code bugs happen to every vendor. The team identified the issue and rolled out a fix. For that they deserve credit. The problem isn’t that Microsoft had a bug. The problem is that the architecture led to a single bug causing a governance failure that had no independent detection for weeks.

This pattern isn’t unique to Microsoft. Whether it’s Copilot, Google Gemini for Workspace, Salesforce Einstein, or any other enterprise AI tool, the AI platform typically provides the governance controls and organizations trust those controls to work. When they don’t, there’s nothing underneath.

The World Economic Forum’s 2026 Global Cyber Security Outlook found that data leaks through generative AI are now the top cyber security concern of CEOs. Yet roughly one-third of organizations still have no process to validate AI security before deployment.

The WEF report also warned that without strong governance, AI agents can accumulate excessive privileges or propagate errors at scale. To combat this, they recommend continuous verification, audit trails, and zero-trust principles that treat every AI interaction as untrusted by default. The Copilot incident demonstrates why those recommendations exist.

Compliance exposure

If Copilot processed emails containing protected health information, organizations may need to assess whether this constitutes a reportable breach under the Data Protection Act 2018. The question isn’t whether the user was authorised, it’s whether the AI’s processing was authorised under the business associate agreement. Microsoft’s public statement doesn’t resolve that analysis.

Under GDPR, Article 32 requires appropriate technical measures for security of processing. If an organization’s sole measure was a vendor’s sensitivity labels that failed for weeks, that’s a difficult argument to take to regulators. The EU AI Act’s Article 12 adds a further layer. If the only records of what the AI accessed come from the vendor that had the failure, organizations lack the independent documentation the regulation demands.

What the fix looks like

Of course, the answer isn’t to stop using AI, as such tools deliver real productivity gains. The answer is to stop trusting AI platforms to govern themselves. Defence in depth is not a new concept. We’ve applied it to network security for decades through firewalls, intrusion detection, endpoint protection, and network segmentation. We all know that multiple independent layers, each capable of catching what the others miss, are a good thing. Yet, for AI governance, we’ve been operating with a single layer for too long.

Defence in depth for AI governance requires an independent data layer between AI platforms and sensitive content. AI doesn’t get direct access to repositories. It authenticates through an external governance layer that enforces policies independently. Purpose binding that restricts which data classifications AI can access, least-privilege controls, continuous verification, and audit trails that the organization controls.

Make sure this doesn’t happen to you

Every major technology shift creates a moment where organizations decide whether to bolt security on after the fact or build it into the architecture from the start. We saw it with cloud migration and remote work. Now we’re seeing it with AI.

The organizations that treat this bug as a wake-up call to build independent AI governance at the data layer will be able to scale AI adoption with confidence. They’ll satisfy regulators with independent evidence and be able to protect sensitive data through architecture that doesn’t depend on trust.

The labels were in place and the policies were configured. The AI read the confidential emails anyway. Make sure this doesn’t happen to you. Ensure you have an independent governance layer that will catch it.

The author

Tim Freestone is Chief Strategy Officer, Kiteworks

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleHuman-driven cyber security is coming to an end, signals new report
Next Article Identifying scenarios of interest under deep uncertainty

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
The word Glossary surrounded by letter tiles to illustrate The International Resilience Glossary.

DRI International publishes updated International Glossary for Resilience

February 27, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?