Microsoft Copilot Exposes User Photos to Human Review, Raising Privacy Concerns
Microsoft’s Copilot AI editing tool is under scrutiny after reports revealed that human contractors review uncensored user-uploaded photos and prompts, many of which are sexual or ethically questionable. Separately, Xbox Game Pass Ultimate subscribers will face new cloud gaming limits, and Microsoft has patched a critical Exchange Server vulnerability.
Editor, Lazyfounder

Microsoft’s Copilot AI editing tool is under scrutiny after reports revealed that human contractors review uncensored user-uploaded photos and prompts, many of which are sexual or ethically questionable. Separately, Xbox Game Pass Ultimate subscribers will face new cloud gaming limits, and Microsoft has patched a critical Exchange Server vulnerability.
30 SEC SUMMARY
- Microsoft’s Copilot AI tool exposes user-uploaded photos and prompts to human contractors for review, with many requests reportedly sexual or dubious in nature.
- Contractors evaluate Copilot’s edits but are not tasked with flagging offensive content, raising privacy and ethical concerns.
- Xbox Game Pass Ultimate subscribers will face a 15-hour monthly cap on cloud gaming starting November 2026, despite a recent price adjustment.
- Microsoft patched a high-severity Exchange Server vulnerability (CVE-2026-96940) allowing attackers to access user mailboxes within organizations.
- The UK is Europe’s most targeted country for state-sponsored cyberattacks, with AI accelerating threat timelines.
TABLE OF CONTENTS
- Copilot’s Human Review Process Raises Ethical Questions
- Xbox Game Pass Ultimate Faces Cloud Gaming Limits
- Microsoft Patches Critical Exchange Server Flaw
- UK Faces Surge in State-Sponsored Cyberattacks
- Background on AI Ethics and Data Privacy
- What this means
- Key takeaways
- FAQ
- Sources
KEY HIGHLIGHTS
- Microsoft’s Copilot AI tool sends uncensored user-uploaded photos and prompts to human contractors for review, including sexually explicit or ethically dubious requests.
- Contractors evaluate Copilot’s output quality but are not required to flag offensive content, according to internal documents.
- Xbox Game Pass Ultimate will limit cloud gaming to 15 hours per month starting November 2026, while maintaining unlimited local gameplay.
- Microsoft released a security update for Exchange Server to fix CVE-2026-96940, a high-severity flaw allowing privilege escalation and mailbox access.
- The UK faces 76 state-sponsored cyberattacks in the past year, the highest in Europe, with AI reducing attack timelines from days to minutes.
Copilot’s Human Review Process Raises Ethical Questions
Microsoft’s Copilot AI editing tool is exposing uncensored user-uploaded photos and prompts to human contractors for evaluation, according to reports from The Next Web. Contractors, hired to improve Copilot’s output quality, review tasks that include the original prompt, the uploaded image, and two AI-generated edits. Many of these requests are reportedly sexual or dubious in nature, such as prompts involving upskirt photos, pro-anorexia content, or suggestive imagery of young girls.
The contractors’ role is to assess the quality of Copilot’s edits, not to flag offensive or harmful content. Internal documents and message boards reveal that contractors are instructed to trust their instincts when evaluating tasks, even when the requests are explicitly sexual. One contractor reportedly flagged a set of eight upskirt photos as unsafe, while others noted encounters with pro-anorexia or suggestive content.
At least one contracting company involved in the review process is Prolific, though neither Prolific nor Microsoft has responded to requests for comment. Microsoft’s terms of use were referenced by the company in lieu of a direct statement. OpenAI, another AI developer, also uses human contractors to review real ChatGPT conversations, as previously reported by 404 Media.
One contractor, quoted by The Next Web, questioned the intent behind these prompts, asking, Who is writing these prompts and who is deciding that basically generating porn is what Copilot is now focused on?
Xbox Game Pass Ultimate Faces Cloud Gaming Limits
Microsoft is introducing a 15-hour monthly cap on cloud gaming for Xbox Game Pass Ultimate subscribers, starting in November 2026. The change comes despite a recent price adjustment, where Microsoft lowered the subscription cost from $29.99 to $22.99 per month after backlash over the 2025 price hike.
The new limit applies only to cloud streaming, while downloading and playing games locally remains unlimited. Ultimate subscribers still enjoy exclusive perks, such as day-one access to new releases like Call of Duty, the Fortnite Crew Pack, and 1,000 V-Bucks monthly. The tier also includes over 500 games, subscriber-exclusive discounts of up to 30% off, and increased points rewards compared to lower tiers.
Xbox Game Pass offers four subscription tiers: Essential ($9.99/month), Premium ($14.99/month), PC Game Pass ($13.99/month), and Ultimate ($22.99/month). All tiers are billed monthly, with no option for annual subscriptions.
Microsoft Patches Critical Exchange Server Flaw
Microsoft has released an urgent security update to fix CVE-2026-96940, a high-severity privilege-escalation flaw in Exchange Server. The vulnerability, rated 8.8/10, allows authenticated attackers to access other users’ mailboxes within the same organization. While no active exploitation has been reported, attackers could exploit the flaw using compromised credentials, such as those obtained via phishing or purchased on the dark web.
The patch was included in Microsoft’s September 2026 V2 Exchange Server Security Updates. Exchange Online users are already protected via a server-side fix, but on-premises Exchange Server users must apply the update manually. Affected versions include Exchange Server Subscription Edition RTM, Exchange Server 2016 Cumulative Update 23, and Exchange Server 2019 Cumulative Updates 14 and 15.
Microsoft has urged customers to apply the fix immediately, as corporate email accounts often contain sensitive information like contracts, invoices, and internal discussions. Administrators are advised to run Microsoft’s Exchange Server Health Checker after installing the update. Security updates for Exchange Server 2016 and 2019 are only available through the Extended Security Update (ESU) program, as both versions reached end-of-support last year.
UK Faces Surge in State-Sponsored Cyberattacks
The UK is the most targeted country in Europe for state-sponsored cyberattacks, with 76 observed events in the past year, according to TechRadar. The country ranks fifth globally for cyber threats impacting customers, accounting for 3.8% of global activity.
AI is accelerating the pace of cyberattacks, reducing the timeline from days to minutes. Phishing attacks have surged globally, with voice phishing increasing by 502% over the past year. Ransomware detections have also risen significantly, with a 66% increase in the UK, a 50% rise in the US, and a 276% jump in Germany.
The most targeted sectors in the UK include research and academia (38% of attacks), transport (22%), and government agencies (13%). The findings underscore the growing threat to critical infrastructure and the need for enhanced public-private partnerships to mitigate risks.
Background on AI Ethics and Data Privacy
AI tools like Copilot and ChatGPT rely on human review processes to improve output quality, but these practices have sparked ongoing debates about data privacy and ethical boundaries. For instance, Zoom is expanding its AI-driven productivity tools, aiming to shift from passive meeting assistance to active task completion by 2026. Similarly, OpenAI has faced scrutiny over its handling of user data and compliance with regulatory frameworks like the EU AI Act.
Recent incidents, such as a teen bug hunter’s disclosure of a flaw in Microsoft’s Titan analytics service, highlight the risks of unauthorized access to sensitive data. The increasing reliance on AI and cloud services has amplified concerns about governance, visibility, and resilience in managing AI dependencies amid evolving regulatory and geopolitical landscapes.
What this means
Lazyfounder analysis — our interpretation, not reported fact.
Microsoft’s Copilot revelations underscore the tension between AI innovation and user privacy. While human review is a common practice to refine AI outputs, the lack of safeguards for sensitive or explicit content raises ethical questions, especially when contractors are not empowered to flag harmful material. Founders building AI tools must prioritize transparency about data handling and implement robust moderation frameworks to avoid similar backlash.
For operators, the Xbox Game Pass changes reflect a broader trend of subscription services adjusting pricing and perks to balance profitability and user satisfaction. The cloud gaming cap may frustrate heavy users, but the focus on local gameplay and exclusive perks could help retain subscribers. Meanwhile, the Exchange Server patch is a reminder of the critical importance of timely vulnerability management, particularly for legacy systems.
The UK’s cybersecurity landscape highlights how AI is reshaping threat dynamics. Founders in sectors like research, transport, and government must invest in AI-driven security tools and employee training to mitigate risks. Public-private collaborations will be essential to stay ahead of state-sponsored threats, especially as attack timelines compress.
Key takeaways
- Human contractors reviewing Copilot’s edits see uncensored user photos and prompts, including sexually explicit or dubious requests.
- Contractors evaluate AI output quality but are not responsible for flagging offensive content, per internal documents.
- Xbox Game Pass Ultimate will cap cloud gaming at 15 hours per month starting November 2026, despite a recent price reduction.
- Microsoft patched CVE-2026-96940, a high-severity Exchange Server flaw allowing attackers to access user mailboxes within organizations.
- The UK is Europe’s most targeted country for state-sponsored cyberattacks, with AI accelerating threat timelines.
FAQ
What is Microsoft Copilot exposing to human contractors?
Human contractors reviewing Copilot’s edits see uncensored user-uploaded photos and prompts, many of which are sexual or ethically dubious in nature.
What are the new limits for Xbox Game Pass Ultimate subscribers?
Starting November 2026, Xbox Game Pass Ultimate subscribers will be limited to 15 hours of cloud gaming per month, though local gameplay remains unlimited.
What does the Exchange Server vulnerability (CVE-2026-96940) allow attackers to do?
The vulnerability allows authenticated attackers to escalate privileges and access other users’ mailboxes within the same organization, though cross-tenant access is not possible.
Why is the UK a prime target for state-sponsored cyberattacks?
The UK is Europe’s most targeted country for state-sponsored cyberattacks due to its geopolitical significance, with 76 observed events in the past year. It also ranks fifth globally for cyber threats impacting customers.
How is AI changing the timeline for cyberattacks?
AI is reducing the attack timeline from days to minutes, accelerating the pace of phishing, ransomware, and other cyber threats.
Related on Lazyfounder
Sources
- The Next Web · 2026-09-29
Copilot users’ photos reach human reviewers uncensored, 404 Media reports - Engadget · 2026-09-29
How To Get Your Money's Worth From Xbox Game Pass Ultimate - TechRadar · 2026-10-01
UK faces the most state-sponsored cyberattacks in Europe as AI narrows the attack timeline from days to minutes - TechRadar · 2026-10-06
Microsoft Exchange flaw allows hackers to read mailboxes across an organization, so patch now
This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.
About the author
Editor, Lazyfounder
Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.
More stories by Tarun MottliaGet the LazyFounder Brief
Startup, funding and AI news in a five-minute read. Join the early-access list.


