For nearly a month, Microsoft’s AI assistant ignored the labels enterprises use to protect sensitive data. The fix took two weeks to acknowledge. The audit trail never came.
Microsoft confirmed this week that a bug in Microsoft 365 Copilot allowed its AI to read and summarize confidential emails that were supposed to be off-limits. Emails tagged with sensitivity labels. Emails protected by data loss prevention policies. The kind of emails that exist behind guardrails specifically because their contents could trigger compliance violations, expose trade secrets, or blow up negotiations.
Copilot ignored all of that and summarized them anyway.
The bug, tracked internally as CW1226324, affected emails in users’ Sent Items and Drafts folders. If those emails carried confidentiality labels, Copilot was supposed to leave them alone. Instead, a “code issue” (Microsoft’s term) allowed the AI’s chat feature to pick them up, process them, and serve summaries back to users. In some cases, it surfaced emails from shared mailboxes to people who didn’t have permission to view them.
Customers first reported the issue on January 21st. Microsoft didn’t acknowledge it until February 3rd. The fix started rolling out in early February, but as of this writing, Microsoft hasn’t disclosed how many organizations were affected, hasn’t provided a full remediation timeline, and hasn’t offered tenants an audit trail showing which queries accessed which protected items during the exposure window.
That last part matters. A lot. Organizations bound by HIPAA, GDPR, SOX, or SEC disclosure rules need to prove that confidential data wasn’t improperly accessed. Without audit logs, they can’t. Microsoft is essentially saying: trust us, we fixed it. For regulated industries, trust isn’t a compliance strategy.
“A Bug We Fixed” Is the Wrong Frame
Microsoft wants this to be a story about a code error that got patched. That framing only works if you don’t look at the pattern.
Last August, security researchers at Zenity demonstrated at Black Hat how prompt injection attacks could make Copilot silently harvest emails and exfiltrate data through invisible Unicode characters. The technique, called ASCII smuggling, let attackers embed data into clickable hyperlinks that looked normal to users but contained stolen information. Microsoft classified that one as critical severity.
Before that, in March 2024, the U.S. House of Representatives banned all congressional staff from using Copilot on government devices. The reason: the Office of Cybersecurity determined it could leak House data to non-approved cloud services. Microsoft responded with promises about future federal compliance tools.
In January 2026, researchers at Varonis published details on a “Reprompt” attack, a single-click technique that could silently exfiltrate personal data from Copilot sessions. And just this month, Zenity Labs disclosed that Copilot Studio’s “Connected Agents” feature, enabled by default on all new agents, allows lateral movement between AI agents without explicit administrator approval.
This isn’t one bug. This is a pattern. And the pattern points to something that can’t be patched with a code fix.
The Structural Problem Nobody Wants to Name
Copilot doesn’t have its own access control system. It inherits permissions from the Microsoft 365 environment underneath it. If a user can see a file, Copilot can see that file. If a folder has overly broad sharing settings (and after years of collaboration sprawl, most do), Copilot can access everything in it. At machine speed. Across every document, email, and Teams conversation the user has touched.
Research from Concentric AI found that 16% of business-critical data in typical organizations is overshared. That’s 802,000 files on average, sitting in environments with inherited access, unreviewed permissions, and collaboration settings nobody has audited since 2019. Copilot doesn’t create that mess. But it makes it exploitable in ways that weren’t possible before.
Security Magazine ran a piece titled “The Copilot Problem: Why Internal AI Assistants Are Becoming Accidental Data Breach Engines.” The core observation: an employee asked their AI assistant a routine question, and the answer referenced emails, legacy files, and internal records the user didn’t know still existed. No hack. No policy violation. The system worked exactly as designed.
That’s the part Microsoft doesn’t want to talk about. The DLP bypass was a bug. The oversharing exposure isn’t. It’s the architecture working as intended, in environments that were never built to withstand an AI that can read everything.
Every security vendor on the planet will use this story to sell data governance tools for the next six months. Permission hygiene. Sensitivity audits. Zero-trust frameworks for AI access. They’re not wrong. Oversharing is real, and Copilot makes it exploitable faster. But that framing also happens to be the version of the story with a product attached to it.
Two Weeks and No Receipts
The version without a product attached is simpler and worse.
Sensitivity labels worked for years. DLP policies worked for years. Microsoft built functioning guardrails, and then a code regression broke them. That happens in software. What happened next is the part that should keep CISOs awake.
Customers reported the issue on January 21st. Microsoft acknowledged it on February 3rd. Thirteen days where affected organizations didn’t know their confidentiality controls were broken. When the fix finally started rolling out, Microsoft provided no audit trail. No scope disclosure. No way for affected tenants to trace which Copilot queries accessed which protected items during the exposure window.
For a company running HIPAA workloads, that’s not an inconvenience. That’s a compliance investigation with no evidence trail. You can’t go to an auditor with “Microsoft says they fixed it.” You need logs showing what was accessed, by whom, and when. Those logs don’t exist.
The architecture debate will dominate the next quarter of conference talks and vendor pitches. It’s the comfortable conversation, the one where the answer is “buy better tooling.” But tooling doesn’t explain why Microsoft sat on customer reports for nearly two weeks. Tooling doesn’t explain why the remediation came without documentation that regulated industries need to prove compliance wasn’t violated.
The bug is patched. The permissions debate will continue. Neither of those is the actual story. The actual story is that when Microsoft’s own safeguards failed, their response left customers unable to prove what happened during the window. For organizations where proof isn’t optional, that’s the thing that can’t be fixed retroactively.
Decagon, the San Francisco-based maker of AI customer service agents, announced a $250 million Series D on January 28, tripling its valuation to $4.5 billion in six months. The round was led by Coatue Management and Index Ventures, with participation from a16z, Accel, Bain Capital Ventures, ChemistryVC, Definition Capital, and Starwood Capital.
The company has now raised over $481 million since launching in 2023. That funding trajectory — $5M seed to $4.5B valuation in under three years — makes Decagon AI agents impossible to dismiss as hype.
From Stealth to Category Leader
Co-founded by CEO Jesse Zhang and CTO Ashwin Sreenivas, Decagon builds conversational AI agents that handle customer inquiries across chat, email, and voice for enterprise clients. The roster includes Notion, Webflow, Substack, Duolingo, Avis Budget Group, Deutsche Telekom, and Chime.
The company signed more than 100 new enterprise customers in 2025. Across the platform, Decagon reports average deflection rates exceeding 80% — four out of five customer interactions resolved without a human agent.
The core differentiator is what Decagon calls Agent Operating Procedures (AOPs) — natural language instructions that compile into structured logic. Teams teach the AI the same way they onboard a human. Readable by people. Executable by machines. That distinction matters in an industry plagued by black-box systems.
The AI Agent Category Gets Real
Decagon’s round is not an outlier. It is a data point in a pattern. AI agents — systems that take autonomous action rather than just generating text — are becoming the defining product category of 2026. Enterprise customer service is the entry point because the economics are brutal and obvious: call centers are expensive, turnover is high, and speed expectations keep rising.
The company recently expanded beyond reactive support. Decagon is now deploying proactive AI concierge agents that initiate outreach — like calling travelers to rebook flights immediately after cancellations. That moves the product from cost center to revenue driver.
The Competition Is Not Standing Still
Decagon AI agents are not operating unopposed. Sierra Technologies, co-founded by former Salesforce CEO Bret Taylor and ex-Google executive Clay Bavor, competes directly in the enterprise AI agent space. Salesforce itself is pushing its own AI agent products. The category is large enough for multiple winners, but the window for establishing dominance is narrowing.
The Valuation Question
A $4.5 billion valuation for a company founded in 2023 raises the obvious question: is this justified? The counterargument is real enterprise revenue, named customers, and measurable deflection metrics. This is not a company selling a vision. It is selling software that replaces headcount. Enterprises calculate the ROI in a spreadsheet.
The funding history tells the story of acceleration: $5M seed in June 2024, $30M Series A the same month, $65M Series B in October 2024, $131M Series C in June 2025, $250M Series D in January 2026. Each round larger. Each interval shorter.
Laterstack Editorial Take
Laterstack exists to sharpen critical thinking by connecting tech, policy, and power to everyday life — across class, industry, and influence. An 80% deflection rate is not a product metric. It is a headcount decision. The CEOs and board members signing these contracts know exactly what they are buying — fewer people on payroll with the same or better output. Federal lawmakers tracking AI’s labor impact should stop asking “will AI take jobs” and start asking “how fast and in which zip codes.” The capital flooding into AI is not theoretical anymore — it is showing up in staffing plans.
What This Means for Everyday People
Customer service jobs are the canary in the coal mine for AI agent deployment. The Bureau of Labor Statistics counts roughly 2.9 million customer service representatives in the U.S. alone. An 80% deflection rate is not a marginal improvement — it is a structural reduction in the humans needed.
For consumers, the experience may improve: faster responses, 24/7 availability, consistent quality. But the human fallback is shrinking. When the AI cannot help, the remaining humans will handle only the hardest cases — and there will be fewer of them.
Decagon’s $250 million is a bet that AI agents are not a feature. They are a product category. The enterprises writing the checks agree.
What is Decagon and how much did it raise?
Decagon builds AI customer service agents for enterprises. It raised $250 million in Series D funding at a $4.5 billion valuation, tripling its value in six months.
Who are Decagon’s competitors in AI customer service?
Key competitors include Sierra Technologies (co-founded by former Salesforce CEO Bret Taylor) and Salesforce’s own AI agent offerings.
What is Decagon’s deflection rate?
Decagon reports average deflection rates exceeding 80%, meaning four out of five customer interactions are resolved by AI without human intervention.
Resolve AI, a startup building an autonomous site reliability engineer, has reached a headline valuation of $1 billion in a Series A led by Lightspeed Venture Partners, according to people familiar with the deal.
The funding marks one of the most aggressive bets yet on AI systems designed to maintain and repair software infrastructure without human intervention. Resolve AI’s product automatically identifies, diagnoses, and resolves production issues in real time, a role traditionally handled by highly trained site reliability engineers.
Sources said the round used a multi tranched structure that has become common among in demand AI startups. In this setup, part of the investment was priced at a $1 billion valuation, while the remainder was purchased at a lower price, resulting in a blended valuation below the headline figure.
Resolve AI’s annual recurring revenue is approximately $4 million, according to two people familiar with the company’s finances. The total size of the funding round was not disclosed. Resolve AI and Lightspeed declined to comment.
The company was founded less than two years ago by Spiros Xanthos, a former Splunk executive, and Mayank Agarwal, Splunk’s former chief architect for observability. The two met more than two decades ago while studying at the University of Illinois Urbana Champaign and previously co founded Omnition, which Splunk acquired in 2019.
Their new startup tackles a growing pain point across the tech industry. As software systems spread across increasingly complex cloud environments, companies struggle to hire enough experienced reliability engineers to keep systems running. Outages are costly, reputation damaging, and difficult to predict.
Resolve AI’s pitch is simple but ambitious. Replace reactive human troubleshooting with automated systems that can detect problems early and fix them instantly. By reducing downtime and cutting operational overhead, companies can shift engineering talent away from constant firefighting and toward building new products.
The startup raised a $35 million seed round last October led by Greylock, with participation from World Labs founder Fei Fei Li and Google DeepMind scientist Jeff Dean. It now competes with Traversal, another AI powered SRE startup that raised a $48 million Series A led by Kleiner Perkins with backing from Sequoia.
Investor appetite suggests that autonomous infrastructure management is becoming a core layer of the modern software stack, not a niche tool.
What This Means for Everyday People
For everyday users, autonomous reliability tools could quietly change how digital services behave. Fewer outages, faster fixes, and more stable apps mean less frustration when banking apps crash, healthcare portals fail, or workplace software freezes mid task. At the same time, these systems reduce the need for human oversight, raising questions about accountability when automated tools control the backbone of daily digital life.
For press, tips, or inquiries:
hello@laterstack.com
Related Laterstack Startup Stories
Cursor Buys Graphite as AI Coding Arms Race Accelerates
Known Is Betting Voice AI Can Fix Dating by Getting People Offline Again
Hidden Geothermal Energy Found by Startup Using AI