tech

Critics scoff after Microsoft warns AI feature can infect machines and pilfer data

Integration of Copilot Actions into Windows is off by default, but for how long?

Critics scoff after Microsoft warns AI feature can infect machines and pilfer data

TL;DR

  • Microsoft's Copilot Actions, an experimental AI agent for Windows, can perform tasks but poses security risks.
  • Known AI flaws like hallucinations and prompt injection can lead to data theft and malware installation.
  • Microsoft advises experienced users to enable the feature only after understanding the security implications.
  • Critics compare the warnings to those for macros, questioning their effectiveness in preventing exploitation.
  • IT admins will have control over enabling/disabling Copilot Actions at account and device levels.
  • Concerns exist about users' ability to detect AI exploitation and the eventual transition of experimental features to default.
  • Microsoft's security goals for agentic features include non-repudiation, confidentiality, and user approval.