Excel: Excel canvas
🚨 The Signal: Excel's new Copilot-generated canvas creates interactive data views that auto-update. This introduces new AI-driven data summarization and visualization, increasing potential for data exposure and prompt injection risks.
The Impact
All users are affected, with a risk of unintended data exposure through AI-generated summaries and prompt injection vulnerabilities.
- End users: Risk of inadvertently exposing sensitive data via AI-generated summaries.
- Security teams: New attack surface for prompt injection against Excel data.
- Data owners: Increased potential for data exfiltration through AI-driven summarization.
- Compliance teams: Challenges in auditing AI-generated content for sensitive information.
The Action
- Review and update Microsoft Purview DLP policies to specifically address AI-generated content in M365 Apps.
- Educate users on responsible AI usage, data sensitivity, and prompt engineering best practices to prevent data leakage.
- Implement or refine sensitivity labels for Excel workbooks containing sensitive data to ensure proper handling by Copilot.
- Monitor Microsoft 365 audit logs for Copilot interactions with highly sensitive Excel data.
- Assess existing data governance frameworks for applicability to AI-generated content and interactive canvases.
Domain: Agentic-AI · Impact: high · Workload: M365 Apps