Excel: Excel canvas

🚨 The Signal: Excel's new Copilot-generated canvas creates interactive data views that auto-update. This introduces new AI-driven data summarization and visualization, increasing potential for data exposure and prompt injection risks.

The Impact

All users are affected, with a risk of unintended data exposure through AI-generated summaries and prompt injection vulnerabilities.

  • End users: Risk of inadvertently exposing sensitive data via AI-generated summaries.
  • Security teams: New attack surface for prompt injection against Excel data.
  • Data owners: Increased potential for data exfiltration through AI-driven summarization.
  • Compliance teams: Challenges in auditing AI-generated content for sensitive information.

The Action

  1. Review and update Microsoft Purview DLP policies to specifically address AI-generated content in M365 Apps.
  2. Educate users on responsible AI usage, data sensitivity, and prompt engineering best practices to prevent data leakage.
  3. Implement or refine sensitivity labels for Excel workbooks containing sensitive data to ensure proper handling by Copilot.
  4. Monitor Microsoft 365 audit logs for Copilot interactions with highly sensitive Excel data.
  5. Assess existing data governance frameworks for applicability to AI-generated content and interactive canvases.

Domain: Agentic-AI · Impact: high · Workload: M365 Apps