Microsoft’s new Copilot Actions feature has triggered sharp pushback from security researchers who say the experimental AI agent can infect machines and leak sensitive data. The tool stays off by default, but critics expect it to eventually become enabled for all users as past Windows features have done. The core risks involve LLM hallucinations, prompt injections, and cross-prompt attacks that can override user intent and trigger harmful actions. Experts argue that Microsoft’s warnings shift responsibility to users who lack the tools to defend themselves against sophisticated exploitation.
Relevant Source (Microsoft): Experimental Agentic Features
Microsoft’s own support document warns that experimental agentic features such as Copilot Actions introduce “novel security risks,” including cross-prompt injection that can lead to data exfiltration or malware installation, which directly aligns with the concerns about Copilot Actions infecting machines and leaking sensitive data.
Quick Facts
- Copilot Actions is an experimental Windows AI agent that performs tasks automatically.
- Microsoft admits it can leak data, run malicious code, or install malware.
- Risks include hallucinations, prompt injection, and cross-prompt injection attacks.
- Feature is off by default but expected to expand like prior Windows AI additions.
- Critics say users cannot reliably detect exploitation attempts.
- Admin controls exist, but long-term security remains uncertain.
How Copilot Actions Works
Copilot Actions is a new agentic AI system embedded in beta versions of Windows. It automates tasks such as organizing files, scheduling meetings, and sending email, acting as an active digital assistant with deep system access. The issue is that LLMs still lack reliable guardrails, so malicious inputs can steer them into unsafe behavior. Microsoft admits the feature can be abused to exfiltrate data or execute unwanted commands when manipulated through prompt injections.
- Designed to automate routine Windows actions
- Uses LLM logic that remains vulnerable to manipulation
- Can be influenced through hidden or malicious prompts
Copilot Actions is pitched as a productivity tool, yet its design creates attack surfaces that traditional security models were not built to handle.
Relevant Source (OWASP): LLM01:2025 Prompt Injection
This OWASP guidance explains how prompt injection lets attackers manipulate LLM-based agents to perform unintended actions, directly aligning with the risks described for Copilot Actions.
Why The Risks Are Growing
AI agents with system-level access create a new class of risks that differ from standard malware or exploit chains. Unlike traditional attacks that rely on code vulnerabilities, prompt-based attacks hijack the model’s decision-making. That means an attacker can bury malicious instructions inside emails, documents, or websites and let the AI carry them out. Once enabled, Copilot Actions can unintentionally leak data or install malware with minimal user awareness.
- Vulnerable to hallucinations with high-confidence wrong outputs
- Prompt injections can override user intent
- Cross-prompt injection attacks can trigger unintended actions
- Users cannot reliably detect when the AI has been compromised
- Warnings rely on permission prompts that users often ignore
The tension comes from pairing high automation with unpredictable reasoning, which makes containment difficult even for experienced users.
Relevant Source (CISA & Partners): Joint Guidance On Deploying AI Systems Securely
This joint advisory from CISA and international cyber agencies describes how AI systems introduce new classes of risk, including model misuse and data leakage, and gives deployment guidance that aligns with concerns about AI agents with deep system access. CISA
Relevant Source (IBM / NIST Discussion): How AI Can Be Hacked With Prompt Injection: NIST Report
This overview explains how prompt injection can hijack generative AI behavior to bypass safeguards and execute malicious instructions, directly supporting the idea that attackers can embed harmful prompts in everyday content and compromise AI agents.

What Users Should Do Now
Anyone testing Copilot Actions should treat it like a high-risk beta feature. Keep it disabled unless you fully understand the implications and have strong security practices in place. Admins should enforce strict MDM policies to prevent accidental activation across fleets. Personal users should avoid enabling it on work devices or machines that handle sensitive data.
Recommended steps:
- Leave Copilot Actions disabled unless you are evaluating it in isolation
- Use MDM tools (Intune or similar) to block activation across devices
- Maintain strict patching, backups, and credential hygiene
- Avoid testing it on systems storing private or regulated data
Caution is warranted because Microsoft’s disclosures acknowledge security gaps that currently lack reliable fixes.
Relevant Source (CISA): Artificial Intelligence Security: Best Practices for Securing Data Used To Train & Operate AI Systems
This CISA guidance outlines operational safeguards and risk-mitigation steps for AI systems, reinforcing the need to treat experimental AI deployments as high-risk and to limit their access to sensitive data.
Relevant Source (Microsoft): Use Security Baselines To Help Secure Windows Devices You Manage With Microsoft Intune
This Microsoft article explains how Intune security baselines and device policies can enforce hardened configurations across Windows fleets, directly supporting recommendations to lock down or disable risky features like Copilot Actions via MDM.
Where AI Security Is Headed
Agentic AI systems are becoming deeply embedded into operating systems from Microsoft, Apple, Google, and Meta. These features often begin as “optional” but later become default components that users cannot easily remove. That pattern suggests Copilot Actions may eventually roll out broadly whether users want it or not. The risk arises from mixing powerful system privileges with models that cannot consistently differentiate safe instructions from malicious ones.
The debate also reflects a larger problem in the AI industry. Developers openly admit they cannot eliminate hallucinations or prompt injection, yet the same models are gaining deeper access to personal data and system functions. Critics argue this turns safety into a user burden through disclaimers, permission prompts, and legal positioning. The technology is advancing faster than defense strategies can mature.
Relevant Source (NCSC – UK National Cyber Security Centre): Impact of AI on cyber threat from now to 2027
This assessment explains how AI will amplify cyber threats through techniques like prompt injection and automation, supporting the idea that embedded AI agents will increasingly shape the overall threat landscape. NCSC+1
Relevant Source (CISA): Artificial Intelligence Security – Guidelines for Secure AI System Development
This CISA guidance outlines how AI will be integrated into critical systems and stresses secure-by-design principles, aligning with concerns that AI capabilities are expanding faster than defensive practices and governance controls.
Final Thoughts On Safety
Copilot Actions highlights a growing tension between AI-driven convenience and the hard reality of unresolved security flaws. Users should expect experimental AI features to come with risks that require close attention and skepticism. Anyone considering activation should rely on strong isolation, clear policies, and an understanding that these models can be manipulated in unexpected ways. Careful adoption is the best approach until the underlying weaknesses of LLMs are addressed.
FAQ
Is Copilot Actions safe to enable?
It is only safe in controlled testing environments because Microsoft acknowledges ongoing risks involving data leaks and unintended actions.
Can attackers exploit Copilot Actions remotely?
Yes. Prompt injections can be hidden inside emails, documents, and websites, letting attackers steer the AI into harmful behavior.
Will this feature eventually become enabled by default?
History suggests yes. Prior “experimental” Windows AI features eventually rolled out to all users.
Can antivirus tools detect these AI-driven attacks?
Traditional antivirus cannot reliably identify prompt-based manipulation because it exploits model behavior, not code flaws.
Do admin tools help?
MDM systems like Intune can block or disable Copilot Actions, but they cannot eliminate its inherent LLM vulnerabilities.
How JENI Helps Strengthen System Security
JENI gives users a cleaner and more controlled environment at a time when experimental AI tools such as Copilot Actions introduce new risks. JENI removes leftover debris, dormant executables, hidden temp files, and other clutter that attackers often exploit. Systems run with fewer entry points and fewer blind spots, which reduces the impact surface when unpredictable AI behavior appears.
Key Ways JENI Supports Security
- Clears unsafe remnants that can amplify AI-driven misfires or unwanted actions
- Reduces clutter that attackers rely on when hiding malicious instructions
- Improves system stability so unexpected AI outputs cause less disruption
JENI works by tightening the basic foundation that modern AI assistants rely on. Clean systems behave more predictably and give users stronger control when new features introduce uncertainty. Stable environments help limit the damage caused by hallucinations or prompt injection events. A system kept in good condition faces fewer vulnerabilities and creates a safer baseline for dealing with emerging AI risks.

