TL;DR: EchoLeak shows how a crafted message can force Microsoft 365 Copilot to leak data from its context with no click, and Reco AI frames the issue as a gap in how enterprises map agent access before exposure is exploited. The broader problem is that AI agent security still depends on understanding which tools, data, and permissions sit inside the runtime boundary, not just the prompt.
NHIMG editorial: based on content published by Reco AI covering the EchoLeak Microsoft 365 Copilot vulnerability: EchoLeak Vulnerability: What Microsoft's CVE-2025-32711 Revealed About AI Agent Security Gaps
Questions worth separating out
Q: What breaks when prompt injection reaches an AI assistant's trusted context?
A: The boundary between untrusted input and trusted action breaks down.
Q: Why do AI copilots increase the risk of oversharing when data governance is weak?
A: AI copilots can surface information from large content estates that users would not normally find quickly, which turns weak governance into an exposure problem.
Q: What are the signs that an AI assistant has too much runtime access?
A: Watch for assistants that can reach multiple data sources, summarise sensitive material, and trigger workflow actions from the same session.
Practitioner guidance
- Map copilot context boundaries Document exactly which mailboxes, files, chats, and workflow systems each assistant can access during a session, then classify those paths by sensitivity and output risk.
- Constrain external content ingestion Block or segregate untrusted inbound content before it reaches trusted retrieval and response pathways, especially for assistants that can summarise or act on messages.
- Separate read access from action eligibility Do not let a model that can read sensitive data automatically inherit the ability to surface, forward, or trigger downstream actions from that same context.
What's in the full article
Reco AI's full analysis covers the operational detail this post intentionally leaves for the source:
- Step-by-step breakdown of the EchoLeak attack chain and why no click was required
- Reco AI's mapping of Copilot access paths to the exposed context boundary
- Practical exposure-shutdown approach for identifying which connected data sources were in scope
- Source commentary on how the incident changes prompt injection from a model issue into an identity issue
👉 Read Reco AI's analysis of the EchoLeak Microsoft 365 Copilot vulnerability →
EchoLeak and AI agent context exposure: are your controls keeping up?
Explore further
Zero-click AI leakage is a context-governance failure, not a prompt-filtering failure. EchoLeak shows that the attack surface sits in the agent's working memory, retrieval path, and output generation path at the same time. Once malicious content is processed inside the trusted runtime, the model can expose information without a user action that traditional controls can intercept. The implication is that identity security for copilots must govern runtime context, not just authentication.
A few things that frame the scale:
- Gartner predicts that more than 50% of successful cyberattacks against AI agents through 2029 will exploit access control weaknesses.
A question worth separating out:
Q: How should security teams govern copilots differently from ordinary applications?
A: Treat them as non-human identities with context-sensitive privileges. Ordinary application controls assume stable request-response behaviour, but copilots can retrieve, combine, and emit data dynamically. Governance must therefore cover data admission, session scope, and the actions an assistant may take after content is processed.
👉 Read our full editorial: EchoLeak reveals how AI agent context exposure breaks zero-click defenses