Microsoft Copilot (Microsoft 365): Add Agents and Skills from the Plus menu
🚨 The Signal: Copilot users can now easily add specialized AI agents and skills to their prompts using a new menu or direct commands. This expands Copilot's capabilities but increases the potential for data exposure and prompt injection risks.
The Impact
All Copilot users are affected, increasing the risk of unintended data exposure and prompt injection attacks through new agent interactions.
- End Users: Risk of inadvertently sharing sensitive data with unapproved AI agents.
- Security Teams: Increased surface area for prompt injection and data exfiltration via new agent capabilities.
- Admins: New governance challenges for controlling agent access and data interactions.
- Compliance Teams: Difficulty in auditing data flows and ensuring compliance with data handling policies.
The Action
- Review and update existing Copilot data governance policies to include AI agents and skills.
- Implement data loss prevention (DLP) policies specific to Copilot interactions with external agents.
- Educate users on the risks of sharing sensitive information with AI agents and how to identify approved agents.
- Monitor Copilot usage logs for unusual agent interactions or data access patterns.
- Establish a clear approval process for integrating new AI agents and skills into the organizational Copilot environment.
Domain: Agentic-AI · Impact: high · Workload: Other