A recent investigation by 404 Media has brought to light a concerning privacy issue regarding Microsoft Copilot. Internal documents reveal that hundreds of contract workers hired by Microsoft have the ability to view user-uploaded photos, including those with explicit facial information, as well as the original prompts sent to the AI and the resulting edited outputs.
Unrestricted Access to Sensitive Data
Joseph Cox, a reporter at 404 Media, detailed his findings, stating that these contractors can access images uploaded by users, the raw prompts submitted to Copilot, and even the before-and-after versions of AI-generated edits. These individuals are not content moderators but are tasked with rating the quality of AI-generated content, providing feedback based on their intuitive assessment as general viewers.
“Faces are never blurred, and many prompts are sexual in nature, with content that is clearly non-consensual,” one contractor told 404 Media.
This situation raises significant privacy concerns, especially given Microsoft’s own statements. The company’s Copilot privacy FAQ mentions that uploaded images are anonymized, with faces blurred before being used for AI training. However, this statement appears to primarily address the AI training process and may not fully encompass the human review process for quality assessment.
Contractors Recruited via Third-Party Platforms
The recruitment of these contractors is handled by third-party companies. At least one such company identified is Prolific, which specializes in sourcing individuals for research projects and AI feedback work. This practice suggests a layer of detachment between Microsoft and the individuals directly accessing user data.
The implications of this revelation are substantial. While AI tools like Copilot offer powerful capabilities, the potential for sensitive personal information, including intimate photos and potentially private conversations, to be viewed by third-party contractors is a serious breach of user trust. This issue highlights the ongoing challenges in ensuring data privacy and security within the rapidly evolving landscape of AI technologies. Users may need to exercise greater caution regarding the types of information they share with AI services, even those provided by major technology companies.
Microsoft has not yet issued a formal statement addressing the specifics of this report, but the findings from 404 Media are expected to prompt further scrutiny and calls for enhanced privacy safeguards within AI platforms.









