Microsoft Copilot users who upload photos for AI editing may be unknowingly sharing them with a workforce of human contractors who review the images, prompts, and generated outputs, including highly explicit and disturbing material[10][2][12].
Internal documents obtained by 404 Media describe a workflow in which contractors are shown a user’s original prompt, the uploaded photo, and two AI-generated edits, then asked to choose the better result based on whether the edit follows instructions, preserves unrelated parts of the image, avoids visual artifacts, and looks good overall[10][11][9]. Faces in the source photos are reportedly not blurred, and workers have documented queues filled with sexualized requests, including upskirt images, edits that enlarge breasts or shorten skirts, prompts to place women in sexual positions, fetish imagery involving cartoon characters, and pro-anorexia depictions of celebrities[10][5][6]. The contractors are paid to score output quality rather than to flag illegal or abusive content, meaning nonconsensual scenarios and potential child exploitation material can pass through the process without being escalated for moderation[10][3][8].
Coverage from multiple outlets indicates that at least hundreds of reviewers participate in these rating tasks, amplifying the privacy risk for anyone whose photo is uploaded to Copilot—whether or not they have an account themselves[10][12][8]. People submitting images may reasonably assume that AI edits are machine-only, but in practice their photos and prompts can be exposed to human viewers, including highly sensitive medical, sexual, or intimate material[2][9]. That exposure extends to bystanders and third parties whose likeness appears in an image a user sends to Copilot, creating a privacy and consent gap with potential implications under data protection laws in regions such as the EU and UK[2][9].
Microsoft’s own privacy documentation acknowledges that Copilot conversations and associated files may be stored for up to 18 months and subjected to automated and human review for product improvement and safety, and earlier consumer-facing FAQs stated that data “including the images or files you upload” could be used for AI training unless eligible users opt out[7][9]. More recent guidance for the updated consumer Copilot app says prompts, responses, and uploaded file contents are not used to train foundation models, but still notes that some interactions can be reviewed to improve the service, leaving unclear whether image-rating tasks fall outside any opt-out controls available to users[7][2]. When questioned by reporters, Microsoft has not provided a direct answer on whether customers can keep their uploads out of these quality-review queues, nor has it detailed how potentially illegal content in the rating stream is handled[10][8][9].
These revelations land against a backdrop of earlier concerns about Copilot’s image systems, including public warnings from a former Microsoft machine learning engineer in early 2024 about guardrail bypasses in the DALL-E 3–powered Copilot Designer tool and a loophole that allowed nonconsensual intimate deepfakes of Taylor Swift. At the time, the engineer said internal feedback channels were swamped with more than a thousand product messages a day and focused only on the most serious cases, underscoring how difficult it can be to police misuse at scale. Together with the new reporting, that history paints a picture of AI image tools whose safety and privacy controls have struggled to keep pace with user behavior.
For security and privacy teams, the Copilot image-review pipeline represents a concrete data exposure risk that should be treated like any other external processing of sensitive information. Enterprises allowing staff to use Copilot for image editing or content generation should assume that photos, prompts, and outputs may be seen by human raters and retained for many months, and update acceptable-use policies accordingly[7][9]. Minimizing uploads of personally identifiable or intimate imagery, tightening guidance for marketing and design teams, and scrutinizing contractual data-processing terms with Microsoft can help limit the impact if reviewed content later becomes subject to legal discovery, regulatory inquiry, or breach scenarios. Until users have a clear, enforceable way to opt out of human review, the safest stance is to treat Copilot as a public system for anything that could harm individuals or organizations if exposed.
References
- Copilot photo uploads can reach human reviewers, and faces reportedly aren’t blurred
- Report finds that Microsoft Copilot’s human reviewers can see users’ uploaded photos and sexualized AI edits
- Microsoft Copilot Reviewers Flooded With Sexualized Image Prompts
- Copilot users’ photos reach human reviewers uncensored, 404 Media reports
- Privacy FAQ for Microsoft Copilot
- Microsoft contracts humans to review Copilot’s creepiest images
- Microsoft Copilot Image Uploads May Be Seen by Human …
- Humans Are Reading Copilot Prompts — And They’re Horrified
- Images uploaded to Microsoft Copilot are reviewed by humans, and sensitive content such as sexually explicit images are also subject to review.
- Human Contractors Are Seeing All Your Horny — and Creepy — AI Prompts
