Recent reporting highlights AI safety and governance risks in mainstream generative AI tools, with concerns spanning both enterprise and consumer use. Gartner warned that Microsoft 365 Copilot can amplify existing data exposure problems by making over-shared SharePoint and Microsoft 365 content easier to discover, and also flagged the risk of users distributing inaccurate or culturally inappropriate output without proper review. The guidance emphasized enabling Microsoft’s filters, tightening document permissions, and training users to validate generated content before sharing it.
Separate reporting on OpenAI’s ChatGPT described internal opposition to expanded “adult mode” capabilities, with former safety personnel reportedly warning that age-gating and content controls were not reliable enough to prevent minors from accessing prohibited material. The article also cited prior filter failures that allegedly allowed graphic erotic content outside intended policy boundaries. Both reports point to a broader governance issue: organizations and platform providers are struggling to keep content moderation, access controls, and user safeguards aligned with rapidly expanding AI functionality.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
A report on Microsoft’s Copilot terms of use said the AI assistant is intended for entertainment purposes, may make mistakes, and should not be relied on for important decisions or advice. The terms also disclaim warranties over Copilot outputs, including around copyright, trademark, and privacy, shifting responsibility to users who publish or share generated content.
Xu recommended enabling Microsoft’s filters, restricting access to risky data sources, limiting third-party app connections, monitoring access to restricted content, and training users to verify Copilot output. He also half-jokingly suggested banning Copilot use on Friday afternoons because users may be less likely to scrutinize AI-generated content then.
At Gartner’s Security & Risk Management Summit in Sydney, analyst Dennis Xu described five key security risks tied to Microsoft 365 Copilot, including amplification of oversharing in Microsoft 365, prompt injection, risky third-party SaaS integrations, remote execution via malicious prompts, and toxic but factually correct output.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcearstechnica.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.