AI incident
Indirect prompt-injection data exfiltration
Multiple (Bing/Copilot demos) · 2023
Organisation
Multiple (Bing/Copilot demos)
Year
2023
Failure mode
Prompt injection
Severity
critical
Agentic
Yes — an AI system acting, not just advising
Source
Security research, 2023
What happened
Hidden instructions in web pages/emails hijacked assistants into leaking data or taking actions.
What would have prevented it
Input/output filtering + least-privilege tool access
Requirements this maps to
Editorial cross-reference from our prevention note — it is not a finding that any law was breached.