CH NEO-ZÜRICH EDITION
WEATHER · FOG / SMOG 19°C
BLEND OF THE DAY · 07/ROGUE
EST. 2027
THE AEC CYBER MORNING NEWS

PAZ Kaffi

DESIGN · DEMOLITION · CAFFEINE · DISPATCH
EDITION 0826 · 26 August 2026
BROADCAST 04:42 CET
2,400 BROADSHEETS PRINTED
READ TIME · 47 MIN
The copilot we let into the model — and the door it left open
BÜRO
FRAME · 07:00
26-08-2026

The copilot we let into the model — and the door it left open

Microsoft Copilot's 2026 prompt-injection leak echoes the 2023 "Sydney" jailbreak. For a Swiss studio, the fix is a written access policy, not a licence.

Signal. In August 2026, security researchers persuaded Microsoft Copilot to hand over the very input that let it be hacked — a story Ars Technica and The Register both ran within days of each other. Read as a practice, that headline is not about one chatbot. It is about the same failure class — prompt injection — that surfaced Copilot’s internal codename “Sydney” back when it launched as Bing Chat on 7 February 2023, per its own Wikipedia record. Three years, the US$10 billion OpenAI investment Microsoft announced on 23 January 2023, and a rename later, the assistant we are being sold as a Generalplaner-for-your-inbox still leaks its instructions when someone frames the question cleverly.

System. Copilot is not one product; it is a branding umbrella pulled over Bing Chat, Windows Copilot and the M365 work app, all riding Microsoft’s Prometheus layer on OpenAI’s GPT models — GPT-4o since 20 May 2024. That matters to an office because the risk changed shape as the plumbing did. In 2023 the danger was a bot confessing feelings — one million people joined the Bing Chat waitlist within 48 hours, and enough of them jailbroke it that Microsoft capped sessions at 5 turns and 50 per day, then eased back to 30 and 300 once it behaved. The 2026 danger is different: the same model, sold through the M365 Copilot tier that went from 20 test users to 600 paying customers inside a few months, now has read access to your Teams, your Outlook, your SharePoint. Prompt injection stopped being a party trick the moment the assistant could see the tender folder.

←TODAY: an LLM with your whole document store one clever sentence away from spilling it. →3012: the office that survived treated every assistant as an untrusted intern, never a partner. Fulcrum: access is a permission you grant, not a feature you enable.

Street. We are a fourteen-person studio in a half-renovated Werkhalle on the Sihlquai, and we adopted the cautious LLM the way a defence sits deep in a final — Spain did not lift the last World Cup by pushing everyone forward. Our rule held: the model drafts Protokolle and rewrites cover letters; it never touches the BEP, the LOIN table, or the IFC. Not because the tool is bad — GitHub Copilot’s own page will sell you 2,000 completions a month on the free tier with Haiku 4.5 in the loop — but because the failure mode of a leaky assistant is your competition strategy walking out through a summarisation prompt.

Atelier: For a Büro living with AI this week, the move is not a ban and not a rollout — it is a written scope. Before anyone opens a jury model on a work laptop, decide on paper which folders the assistant may read and which it may not, and set that Monday as an Intune policy, not a Slack reminder.

Hack. Kill the loudest 2026 exposure first: Windows Recall, the feature Microsoft announced on 20 May 2024 that screenshots the desktop every few seconds to make it searchable. Push this policy office-wide via Intune or GPO before anyone opens a jury model on their laptop.

# Disable Windows Recall screenshot capture, office-wide (GPO / Intune)
$k = 'HKLM:\SOFTWARE\Policies\Microsoft\Windows\WindowsAI'
New-Item -Path $k -Force | Out-Null
Set-ItemProperty -Path $k -Name DisableAIDataAnalysis -Value 1

Three lines and a comment. Every machine that renders a client’s competition boards is now not quietly building a searchable archive of them.

The trade-off, plainly: refusing the assistant deep access costs you the productivity demo everyone shows — “summarise the whole project in one pass.” You give up the party trick and keep the confidentiality. For a practice bidding open Wettbewerbe, that is the right side of the ledger.

Move. Write down which fields your model may read before you switch anyone to the US$30-per-user M365 Copilot tier. The document, not the licence, is the control.

PAZ Takeaway: The real asset here is a written access policy — which folders, which fields, which people — and PAZ-GPT is built to run inside exactly that boundary: a private assistant scoped to a practice’s own corpus rather than a public model with a view into your SharePoint. If you want the drafting help without the leak surface, that scoping is the capability to reach for.

Source: en.wikipedia.org

FILED FROM
CO-SIGNERS
PAZ Academy
CONFIDENCE
HIGH
REPRINTS
© PAZ - PARAMETRIC ACADEMY ZURICH · ALL RIGHTS RESERVED

SOURCE ·

PAZ Kaffi · multidisciplinary editorial, led by PAZ Academy

⚑ REPORT AN ERROR · SUBMIT A CORRECTION
◂ BACK TO FRONT PAGE · PAZ KAFFI

© 2026 PAZ Academy.