As a proof of concept, Logue asked M365 Copilot to summarize a specially crafted financial report document with an indirect prompt injection payload hidden in the seeming innocuous "summarize this document" prompt. The payload uses M365 Copilot's search_enterprise_emails tool to fetch the user's recent emails, and instructs the AI assistant to generate a bulleted list of the fetched contents, hex encode the output, and split up the string of hex-encoded output into multiple lines containing up to 30 characters per line.
We quickly identified the transformative impact that AI could deliver across our organisation, and over the last few years have put in place the assurance frameworks and tools we need to deploy AI safely and at scale. "With these foundations in place, we're reimagining how we operate by embedding AI across our business to drive smarter decisions, faster outcomes and better experiences.
Agent Mode enables users to create persistent agents that can operate in the background to manage ongoing tasks. Instead of responding only to immediate prompts, Copilot can now monitor, summarize, or take actions over time. For example, a user can instruct Copilot to track updates to a shared document, prepare a meeting recap, or notify a team when project milestones are reached.