Companies ground Microsoft Copilot over data governance concerns
theregister.com
theregister.com
The concerns are that most corporate implementations of network roles and permissions are not up to date or accurate, so CoPilot will show data to an employee that they should not be allowed to see. Salary info is an example.
Basically, CoPilot is following “the rules” (technical settings) but corporate IT teams have not kept the technical rules up to date with the business rules. So they need to pause CoPilot until they get their own rules straight.
Edit to add: if your employer has CoPilot turned on, maybe try asking for sensitive stuff and see what you get. ;-)
https://labs.zenity.io/p/links-materials-living-off-microsof...
https://www.youtube.com/playlist?list=PLM_RIPYi59BN6BeHyJQ_9...
For instance, the article says "Microsoft positions its Copilot tool as a way to make users more creative and productive by capturing all the human labor latent in the data used to train its AI models and reselling it.". The Copilot data could make it a lot easier to steal sensitive business procedures and intellectual property - the data would allow any third parties to fully inspect the company procedures and sensitive data in a scale that we've never seen. It would be next to impossible to manage, categorize and protect this data. It's an intellectual property nightmare.
A good version of the technology, which we don't have yet, would allow competitors to create a copy of every employee (in the business sense) and perhaps much more efficiently compete with that company.
That’s not happening. Microsoft Copilot doesn’t train on data it has access to. https://learn.microsoft.com/en-us/power-platform/faqs-copilo...
Certainly not as valuable as the revenue you can make from companies that would instantly cancel their Copliot 365 subscriptions if they heard any hint of data being used for training without permission.
Convincing people that you don’t train on their data remains one of the hardest problems: https://simonwillison.net/2023/Dec/14/ai-trust-crisis/
companies already are cancelling their copilot subscriptions as it's "high cost and low value"
https://www.businessinsider.com/pharma-cio-cancelled-microso...
> Convincing people that you don’t train on their data remains one of the hardest problems:
we attempted to protect our valuable data with copyright
they disregarded these terms, trained on it anyway and claim wholesale reproduction of our work is "fair use"
why wouldn't they do the same with Teams/Sharepoint/Word/everything on Azure
because the contract with a company 10000x our size says they won't? HAHAHAHAHA
the only way to protect your data from entities that have previously disregarded terms in this way is to not let them get their dirty hands on it in the first place
(Update: actually I didn't make that point in the original post, it's from the talk version of this I gave https://simonwillison.net/2024/Jun/27/ai-worlds-fair/#slide.... )
Would you enable a search indexer on all your corporate data that doesn't have any way to control which documents are returned to which users? Probably not.
It's a known issue with SharePoint going back years and has various solutions[0] such as document level access controls or disabling indexing of content.
If we called it what it is though the C-levels probably wouldn't even care about it. They never cared about enterprise document search before and certainly didn't "pivot" to enterprise document search or report on the progress of enterprise document search implementation to the board.
0: https://sharepointmaven.com/3-ways-prevent-documents-appeari...
It is the same problem with a lot of the AI tools right now. Using them for your code, looking at your documents, etc etc. Unless you self host it or use a 'private' service from Azure or AWS (which they say is safe...) who knows where this information is ending up.
This is a major leak waiting to happen. It scares me to think what kind of data has been fed into ChatGPT or some code tool that is just sitting somewhere in a log or something plaintext that could be found later.
Regardless, my other points still stand. All of these tools remain a leak waiting to happen.
I mean, Azure has had several tenancy breaches where attackers could move from one tenant to another
> The risk isn't any greater than Azure getting hacked or something.
example: https://www.theverge.com/2021/8/27/22644161/microsoft-azure-...
they also had their master authentication keys leaked and didn't realise for 2 years
https://www.bleepingcomputer.com/news/microsoft/microsoft-st...
this one allowed the attackers to get into Microsoft executive's email accounts
We googled around to see if there was any information on the web about the tool & there’s nothing on Google which makes sense since it’s a boring internal tool for a financial services company.
Ofcourse it could be a lucky guess or it could be an intern had uploaded the manual to GPT :D
Everything else is just wishful thinking. Like trying to keep a secret whilst only telling one or two friends.
I had a recent exchange with Microsoft and a group of CISOs and how it was explained to US by MS is that Copilot relies on existing file sharing security (OneDrive, Sharepoint) to determine what user could receive as feedback from Copilot. While it seems like a reasonable approach to rely on existing controls it honestly sent shivers down my spine. Anyone who had some experience securing MS platforms data sharing knows those become a total mess overtime for large organizations.
For what it’s worth, Microsoft does have support for customer keys at their E5 licensing level:
https://learn.microsoft.com/en-us/purview/customer-key-set-u...
The law also states that crime is illegal.
I wouldn't walk around Compton late at night with a £5K camera though. Even with insurance.
LLM-based AI is technically banned at my work. For somewhat good reason: most of our work involves confidential, controlled, or classified data. Though I've seen a lot of people, especially the juniors, still using ChatGPT every day.
Also noticed the UI has gotten a lot slower. I'm guessing the two things are related.
If my company wasn't locked into "Microsoft everything" this would push me the last inch to ditch VS completely. I already did at home.
Want to build AI tooling that leverages user data? Great! * Does it gather their data for targeted ads? - neutral. * Does it gather their data to then be resold to others? - -100points, pay more tax, you're rent seeking. * Does it help the user not get phished? - +100points you're actually offering something of value.
I don't believe having humanoid robots in factories helps or is nearly as profitable as humanoid robots that will do my laundry for me.