Copilot 'AI Worm' Raises Flag About Governance, AI Productivity Tools

An AI researcher says hidden prompts in Word documents can influence Microsoft Copilot output and potentially spread through document workflow, raising new governance concerns around AI-productivity tools.

An AI researcher whose work uncovered a security finding affecting Microsoft 365 Copilot, has drawn attention to a broader issue: how organizations are governing AI-generated content and the documents used to create it.

Researcher Håkon Måløy discovered a self-propagating AI worm affecting Copilot for Word. In a blog post, Måløy said that an attacker could hide instructions within Word documents that Copilot may interpret as commands when generating or editing content. Those instructions could then be copied into newly created files, potentially influencing Copilot-assisted workflows.

[RELATED: Why Many IT Teams Still Run Both Intune And Configuration Manager]

Microsoft confirmed the reported behavior earlier this year and implemented mitigation measures, Måløy said in his post. He also said that subsequent testing showed that a modified version of the technique could still reproduce a broader class of attack, and that the underlying vulnerability class remains exploitable.

In a statement to MES Computing, a Microsoft spokesperson said the company addressed the researcher's findings through a coordinated vulnerability disclosure process and employs multiple safeguards designed to block malicious instructions and keep AI systems aligned with user intent. Microsoft continues to strengthen those protections as threats evolve, the spokesperson said.

Microsoft also encourages its customers to "install the latest updates, use multiple layers of security protection, treat content from unknown sources with caution, and review AI-generated content before using or sharing it," the spokesperson added.

The disclosure is timely as many midmarket organizations are shifting from pilot programs and have started incorporating Microsoft Copilot into everyday workflows.

[RELATED: Copilot, Claude Outages Within 24 Hours Raise AI Reliability Concerns]

While Måløy's finding does not act like typical malware and requires the human trigger of Copilot-assisted document creation; it shines a light on the potential of AI tools inheriting risks from content they are asked to analyze, summarize or generate.

Microsoft's response also highlights an emerging reality for IT leaders: technical safeguards alone may not be enough. Organizations deploying AI productivity tools still need governance processes that help employees evaluate AI-generated output, validate external content, and understand how AI systems interact with business information.

As midmarket organizations adopt Copilot and other AI-productivity tools, IT leaders may need to reassess whether existing governance security controls adequately address AI-assisted workflows. The challenge is no longer just managing who accesses what but also managing the information AI systems are allowed to interpret and act upon.

Editor's note: This article has been updated to include Microsoft's comment.