Not a week passes that I don't find more evidence that Copilot was a rush job from Microsoft and has serious limitations for enterprises.
https://learn.microsoft.com/en-us/purview/dlp-microsoft365-copilot-location-learn-about
@malwarejake I'd love to see the thread model they worked from that was judged an acceptable risk ... or maybe they don't have one?
https://arxiv.org/pdf/2511.08295