Microsoft Teams: Intelligent call delegation
🚨 The Signal: AI-powered call delegation in Teams answers calls, gathers context, and schedules follow-ups. This introduces an AI agent as an intermediary for voice communications, potentially handling sensitive information.
The Impact
All Teams users are affected, introducing new risks related to AI processing of sensitive voice data and potential information leakage.
- End Users: Risk of sensitive information being processed by AI without explicit consent.
- Security Team: New attack surface for prompt injection or data exfiltration via AI agent.
- Compliance Team: Challenges in demonstrating compliance for AI-handled communications.
- Admins: Need to understand AI agent's data access and retention policies.
The Action
- Review Microsoft's data handling policies for Teams Intelligent Call Delegation and Copilot.
- Assess existing data classification policies for applicability to voice communications handled by AI.
- Develop user guidance on appropriate information to share with AI call assistants.
- Monitor Microsoft 365 Message Center for further configuration options or controls related to this feature.
Domain: Agentic-AI · Impact: high · Workload: Teams