News, Trends, and Insights for IT & Managed Services Providers
News, Trends, and Insights for IT & Managed Services Providers
A white cube with a colorful abstract shape inside.

Microsoft’s Copilot has faced significant security failures, having ignored sensitivity labels for confidential emails on two separate occasions within eight months, impacting organizations like the U.K.’s National Health Service. According to a report by BleepingComputer, the latest incident began on January 21, 2026, and lasted four weeks, where no security tool flagged the breach. This follows a critical vulnerability known as “EchoLeak,” which allowed a malicious email to exfiltrate data without any user action, highlighting a design flaw in how AI systems handle trusted and untrusted data. A survey by Cybersecurity Insiders revealed that 47% of Chief Information Security Officers have witnessed AI agents exhibiting unauthorized behavior.

Why do we care?

EchoLeak demonstrated that Copilot cannot reliably distinguish between a trusted instruction and an attacker-controlled instruction embedded in an email. That’s an architectural enforcement failure.  Eight months later, Copilot ignores sensitivity labels for four weeks in production, affecting the NHS, and no security tool flags it.  Both incidents stem from the same root cause: Copilot aggregates across permission boundaries without an AI-specific enforcement layer.

MSPs who sold Copilot into regulated environments based on Microsoft’s compliance marketing are now holding a tool with two documented control failures and a monitoring stack that demonstrably cannot detect those failures in real time.

The bad decision here is waiting for Microsoft’s patch and moving on. AI inference operating outside the classification enforcement plane isn’t fixed with a patch; it requires an architectural rebuild Microsoft hasn’t announced. If you can’t document how AI access is enforced, monitored, and contractually scoped, you shouldn’t be selling it into regulated environments.

Choose your upgrade:

Get the full benefits of Business of Tech Plus

Insider Access

$12/month

Perfect for MSPs and ITSPs that want full interviews, early access, and ad-free listening

  • Programmatic Ad-free private podcast feedSame show, little interruptions
  • Channel Chatter previews1–2 topics with light insights
  • Early access to interview episodesHear it days before public release
  • Monthly Insider BriefTighter analysis you can share internally
  • Extra audio segmentsCut interviews, behind-the-scenes commentary, quick competitive notes
  • Become an Insider for $12/month

    Leadership Access

    $149/month

    Perfect for MSPs and Vendors that run a team and need the extended tactics, executive summaries, and weekly alignment brief

  • All Insider Access benefits plus . . .
  • Invite your teamIncludes access for 5 team members with option to add more
  • Vendor Strategy BriefsThe entire library, plus new analysis every month
  • Channel ChatterAll topics, full insights, complete vendor discussion + sentiment list
  • Quarterly State of the Channel Briefing
  • Monthly AMA submission priorityAsk Dave direct questions, and skip the line
  • Get the Leadership Edge for $149/month

    Vendor Partner

    $500/month

    Perfect for channel companies or vendors looking to deepen their engagement with the show.

  • All Leadership Access benefits plus . . .
  • Get highlighted as a show sponsor You'll get placement in the show notes, throughout the website, and on our dedicated sponsors page.
  • Enjoy regular shout outs You'll be featured in a rotating format during the show
  • Become a show sponsor for $500/month

    Search all stories