{"id":3071,"date":"2025-11-19T04:14:02","date_gmt":"2025-11-19T11:14:02","guid":{"rendered":"https:\/\/catbradley.io\/?p=3071"},"modified":"2025-11-19T04:14:02","modified_gmt":"2025-11-19T11:14:02","slug":"microsofts-new-windows-ai-feature-comes-with-warnings-about-malware-and-data-theft","status":"publish","type":"post","link":"https:\/\/catbradley.io\/?p=3071","title":{"rendered":"Microsoft&#8217;s New Windows AI Feature Comes With Warnings About Malware and Data Theft"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/2025\/11\/windows-ai-feature-comes-with-warnings.png\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" \/><\/p>\n<p>If you ask me, <strong>Microsoft has been one of the biggest driving forces behind Linux adoption<\/strong> in recent years. The way they&#8217;ve been handling Windows, with its forced updates, aggressive telemetry, and <a href=\"https:\/\/itsfoss.com\/news\/microsoft-recall-fails-again\/\">questionable AI features<\/a>, has sent more people to Linux than any marketing campaign ever could.<\/p>\n<p>And they are at it again with a new AI feature that could be tricked into installing malware on your system.<\/p>\n<h2>Isn&#8217;t This Too Much?<\/h2>\n<figure class=\"kg-card kg-embed-card\"><\/figure>\n<p>Microsoft is rolling out a new experimental feature called &#8220;<a href=\"https:\/\/copilot.microsoft.com\/labs\/experiments\/copilot-actions?ref=itsfoss.com\">Copilot Actions<\/a>&#8221; to Windows Insiders. They pitch it as <strong>an AI agent that handles tasks you describe to it<\/strong>. Organize vacation photos, sort your <em>Downloads<\/em> folder, extract info from PDFs, that sort of thing.<\/p>\n<p>It is currently available in Windows 11 Insider builds (<em>version 26220.7262<\/em>) as part of Copilot Labs and is <strong>off by default<\/strong>, requiring admin access to set it up.<\/p>\n<p>But here&#8217;s the catch. Copilot Actions isn&#8217;t just suggesting what to do. It runs in a separate environment called &#8220;<strong><em>Agent Workspace<\/em><\/strong>&#8221; with its unique user account, clicking through apps and working on your files.<\/p>\n<p>Microsoft says it has &#8220;<a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2025\/10\/16\/securing-ai-agents-on-windows\/?ref=itsfoss.com#:~:text=capabilities%20like%20its%20own%20desktop\" rel=\"noreferrer\">capabilities like its own desktop<\/a>&#8221; and can &#8220;<a href=\"https:\/\/support.microsoft.com\/en-us\/windows\/experimental-agentic-features-a25ede8a-e4c2-4841-85a8-44839191dfb3?ref=itsfoss.com#:~:text=interact%20with%20apps%20in%20parallel%20to%20your%20own%20session.\">interact with apps in parallel to your own session<\/a>.&#8221; <strong>And that&#8217;s where the problems start<\/strong>.<\/p>\n<p>In a support document (<em>linked above<\/em>), Microsoft admits that features like Copilot Actions introduce &#8220;<strong><em>novel security risks<\/em><\/strong>.&#8221; They warn about <a href=\"https:\/\/arxiv.org\/html\/2408.00925v1?ref=itsfoss.com\">cross-prompt injection<\/a> (XPIA), where malicious content in documents or UI elements can override the AI&#8217;s instructions.<\/p>\n<p>The result? &#8220;<strong><em>Unintended actions like data exfiltration or malware installation<\/em><\/strong>.&#8221;<br \/>Yeah, you read that right. Microsoft is shipping a feature that could be tricked into installing malware on your system.<\/p>\n<p><strong>Microsoft&#8217;s own warning hits hard<\/strong>: &#8220;<em>We recommend that you only enable this feature if you understand the security implications<\/em>.&#8221; <\/p>\n<p>When you try to enable these experimental features, Windows shows you a warning dialog that you have to acknowledge. \ud83d\udc47<\/p>\n<figure class=\"kg-card kg-image-card kg-card-hascaption\"><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/2025\/11\/windows-11-agentic-features-toggle.jpeg\" class=\"kg-image\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" loading=\"lazy\" width=\"1920\" height=\"1307\" \/><figcaption><i><em class=\"italic\">Source: <\/em><\/i><a href=\"https:\/\/blogs.windows.com\/windowsexperience\/2025\/10\/16\/securing-ai-agents-on-windows\/?ref=itsfoss.com\"><i><em class=\"italic\">Microsoft<\/em><\/i><\/a><\/figcaption><\/figure>\n<p>Even with these warnings, <strong>the level of access Copilot Actions demands is concerning<\/strong>. When you enable the feature, it gets read and write access to your <em>Documents<\/em>, <em>Downloads<\/em>, <em>Desktop<\/em>, <em>Pictures<\/em>, <em>Videos<\/em>, and <em>Music<\/em> folders.<\/p>\n<p><a href=\"https:\/\/www.windowslatest.com\/2025\/11\/18\/windows-11-to-add-an-ai-agent-that-runs-in-background-with-access-to-personal-folders-warns-of-security-risk\/?ref=itsfoss.com#:~:text=While%20Agent%20and,for%20AI%20agents.\">Windows Latest notes that<\/a>, unlike Windows Sandbox, which runs in complete isolation and gets wiped clean when you close it, Copilot Actions operates in &#8220;<em>Agent Workspace<\/em>&#8221; with persistent user accounts that keep access to these folders across sessions. Also keep in mind that the feature can also access any apps installed for all users on a system.<\/p>\n<p><strong>Microsoft says they are implementing safeguards<\/strong>. All actions are logged, users must approve data access requests, the feature operates in isolated workspaces, and the system uses audit logs to track activity.<\/p>\n<p>But you are still giving an AI system that can &#8220;<em><strong>hallucinate and produce unexpected outputs<\/strong><\/em>&#8221; (<em>Microsoft&#8217;s words, not mine<\/em>) full access to your personal files.<\/p>\n<h2>Closing Thoughts<\/h2>\n<p>There is a pattern here. <strong>Microsoft seems obsessed with shoving AI into every corner of Windows<\/strong>, whether users want it or not, whether it&#8217;s ready or not, while simultaneously playing around with the data of its users.<\/p>\n<p><strong>This is why Linux keeps gaining traction<\/strong>. No AI experiments that could install malware, and no fighting against features you never asked for. Plus, the most likely way you will nuke your installation is if you deliberately run something like <code>rm -rf<\/code> yourself, not because Copilot got confused by a malicious PDF.<\/p>\n<p>If Microsoft&#8217;s AI experiments are making you uncomfortable, then <a href=\"https:\/\/itsfoss.com\/best-linux-distributions\/\">there are plenty of Linux distributions<\/a> that respect your privacy and put you in control.<\/p>\n<p><strong>Suggested Reads \ud83d\udcd6<\/strong><\/p>\n<figure class=\"kg-card kg-bookmark-card\"><a class=\"kg-bookmark-container\" href=\"https:\/\/itsfoss.com\/best-linux-distributions\/\">\n<div class=\"kg-bookmark-content\">\n<div class=\"kg-bookmark-title\">Best Linux Distributions For Everyone in 2025<\/div>\n<div class=\"kg-bookmark-description\">Looking for the best Linux distribution that suits everyone? Take a look at our comprehensive list.<\/div>\n<div class=\"kg-bookmark-metadata\"><img decoding=\"async\" class=\"kg-bookmark-icon\" src=\"https:\/\/itsfoss.com\/content\/images\/icon\/android-chrome-512x512-28.png\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" \/><span class=\"kg-bookmark-author\">It&#8217;s FOSS<\/span><span class=\"kg-bookmark-publisher\">Ankush Das<\/span><\/div>\n<\/div>\n<div class=\"kg-bookmark-thumbnail\"><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/thumbnail\/best-linux-distros-for-2024-5.png\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" \/><\/div>\n<p><\/p><\/a><\/figure>\n<figure class=\"kg-card kg-bookmark-card\"><a class=\"kg-bookmark-container\" href=\"https:\/\/itsfoss.com\/news\/microsoft-recall-fails-again\/\">\n<div class=\"kg-bookmark-content\">\n<div class=\"kg-bookmark-title\">Microsoft Recall Exposes Passwords and Banking Data!<\/div>\n<div class=\"kg-bookmark-description\">New tests reveal Microsoft Recall still screenshots sensitive data.<\/div>\n<div class=\"kg-bookmark-metadata\"><img decoding=\"async\" class=\"kg-bookmark-icon\" src=\"https:\/\/itsfoss.com\/content\/images\/icon\/android-chrome-512x512-27.png\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" \/><span class=\"kg-bookmark-author\">It&#8217;s FOSS<\/span><span class=\"kg-bookmark-publisher\">Sourav Rudra<\/span><\/div>\n<\/div>\n<div class=\"kg-bookmark-thumbnail\"><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/thumbnail\/recall-is-still-a-nightmare-1.png\" alt=\"Microsoft's New Windows AI Feature Comes With Warnings About Malware and Data Theft\" \/><\/div>\n<p><\/p><\/a><\/figure>","protected":false},"excerpt":{"rendered":"<p>If you ask me, Microsoft has been one of the biggest driving forces behind Linux adoption in recent years. The way they&#8217;ve been handling Windows, with its forced updates, aggressive&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rss"],"_links":{"self":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/3071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3071"}],"version-history":[{"count":0,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/3071\/revisions"}],"wp:attachment":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}