Une vulnérabilité dans Microsoft 365 Copilot aurait permis aux utilisateurs d’accéder à des fichiers et de les résumer sans générer d’entrées dans les journaux d’audit, compromettant prétendument la traçabilité et la conformité. Le chercheur en sécurité Zack Korman a divulgué le problème à Microsoft, qui l’aurait classé comme « important » et corrigé le 17 août 2025, mais aurait choisi de ne pas notifier les clients ni d’attribuer de CVE.
Gestion pratique des risques d'entreprise et réglementations
The security vulnerability in Microsoft 365 Copilot—which allowed it to access and read internal company files, spreadsheets (such as payroll and taxes), and emails without registering a 'read' event in the Microsoft 365 Purview audit log—exposed organizations to extreme insider threat risks. Insiders could use Copilot to exfiltrate sensitive files without leaving any trace in the logs. This directly violates data logging compliance frameworks (such as SOC 2, HIPAA, and ISO 27001), rendering data exfiltration untraceable and exposing the firm to massive regulatory fines and loss of client trust. Regulatory Impact Alignment: Financial audits, transaction tracking, and internal reporting algorithms must comply with Sarbanes-Oxley (SOX) Section 404 and AICPA SOC 2 Type II regulations. Accounting teams must prevent data leakage by isolating sensitive financial logs from public generative AI models.
Deploying generative search and AI assistants over internal enterprise document repositories often bypasses traditional read-event logging and file access monitors. Organizations cannot assume that existing enterprise security integrations automatically cover generative AI interactions. Logging architectures must be thoroughly verified before deployment. Compliance Audit Standards: For detailed verification audits, this case maps directly under Sarbanes-Oxley Act (SOX) Section 404 & AICPA SOC 2 Type II Safeguards. Systems deploying similar AI features must maintain dynamic security logs and hold systematic compliance records.
Professional compliance incident analysis
Copilot makes internal file access incredibly easy. If your audit logs don't record what the AI reads on behalf of a user, you are completely blind to insider theft and data breaches. Verify your AI logging integrations before you expose your document repositories.
Critical answers regarding AI compliance, auditing, and organizational risks
A critical indexing bug allowed Copilot to read and extract information from internal company files (such as payroll spreadsheets) without writing a corresponding 'file read' event into the Microsoft Purview audit logs, rendering access untraceable.
Copilot indexes all files the user has permission to view. Many firms have loose folder configurations where files are shared widely, allowing Copilot to surface sensitive financial records in chat answers.
Firms must perform a least-privilege access audit (Shadow IT check), configure strict folder blocks preventing Copilot indexing of payroll directories, and verify that all generative reads produce audit logs.
In Australia, a KPMG Australia partner and registered company auditor reportedly uploaded a reference document from an internal AI training course into an AI tool to answer an exam question, in violation of firm policy. KPMG reportedly detected the activity in August 2025 and imposed a penalty of more than A$10,000 of future income after an internal investigation. The partner also reportedly self-reported the matter to Chartered Accountants ANZ, which is investigating the case.
An Israeli farmer, Moshe Har Shemesh, reportedly received a fine generated by a Tax Authority software system whose calculation officials were allegedly unable to explain. When the farmer reportedly sought access to the program or its source code to understand the basis for the amount, the authority allegedly refused, citing security concerns and the difficulty of extracting the embedded guidelines. The dispute reportedly later moved into legal proceedings focused on whether code and automated decision rules constitute information subject to public disclosure.
Charlie the Chatbot, an AI-powered system deployed by the Canada Revenue Agency (CRA), has reportedly been providing inaccurate or incomplete tax-related information to members of the public. An audit by the Auditor General of Canada reportedly found the chatbot produced correct responses in fewer than half of tested cases. The system has been publicly available across multiple CRA webpages since March 2020 and reportedly used by millions of users.