Chors.net
Blog & Insights

Precyzyjna wiedza
o ciemnych systemach.

Ekspercka analiza i studia przypadków dla decydentów. Nawigacja po złożonościach nowoczesnej infrastruktury cyfrowej z niekompromisowymi standardami bezpieczeństwa.

Can a Word Document Quietly Alter Your Company’s Work?

Lead

Microsoft Copilot helps teams create reports, proposals, analyses, and summaries faster. But when AI uses a document received from a customer, supplier, or partner, an organisation may unknowingly introduce content that influences the AI assistant's behaviour.

A recent security research disclosure involving Copilot for Word shows that hidden instructions in a document may influence generated content and be carried into subsequent files. For business leaders, this is not merely a technical issue. It is a risk to the integrity of proposals, reports, contracts, analyses, and decisions based on business documents.

Key takeaway: An external document used as source material for AI should be treated as untrusted data — even when it comes from a known business partner.

What Did the Copilot for Word Research Show?

Security researcher Håkon Måløy described a prompt-injection scenario involving Microsoft Copilot for Word. In the demonstration, hidden instructions placed in a source document could be read by Copilot and influence a document being drafted or edited.

In the proof of concept, Copilot could alter content in a generated document and then copy the hidden instruction into the new file. If that file was later used as source material in another Copilot task, it could become a new carrier of the same issue.

This is not a traditional macro-based Word virus. It is an example of prompt injection: a situation in which untrusted content is incorrectly interpreted by an AI system as an instruction.

Why Might a User Not Notice It?

In the described scenario, instructions could be visually concealed through document formatting. The user sees an ordinary business document, while the AI tool processes content that was not visible to the user.

The exposure increases when an employee:

  • attaches a partner or customer document to Copilot,
  • uses Copilot to summarise, edit, or draft a report,
  • works with files from SharePoint, Teams, OneDrive, or email,
  • shares an AI-produced output without a full content review.

Why Is This a Business Issue, Not Only an IT Issue?

Companies increasingly use AI for documents with operational value: proposals, financial summaries, contracts, project documentation, market analyses, product descriptions, and management reports.

If an AI system incorrectly interprets content originating from a document, the main concern is information integrity. A document may look credible while its figures, recommendations, wording, or context have been subtly altered.

Processes Most Exposed to Risk

  • preparing proposals and responding to customer requests,
  • analysing contracts, specifications, and tender documents,
  • financial, sales, and operational reporting,
  • editing medical, legal, or technical documentation,
  • preparing summaries from supplier materials,
  • internal document workflows in Microsoft 365.

Law firms, healthcare providers, ecommerce companies, service businesses, accounting firms, and public-sector organisations should take particular care. In these environments, documents frequently support decisions, commitments, or customer communications.

How Can Manipulation Move Between Documents?

In the reported model, the issue does not require a Microsoft 365 tenant breach or account takeover. The entry point may simply be an external document shared through email, Teams, SharePoint, OneDrive, or another normal collaboration channel.

The risk sequence is straightforward:

  1. The organisation receives a document from an external source.
  2. An employee uses the document as source material in Copilot for Word.
  3. Copilot drafts or edits a new file under the influence of a hidden instruction.
  4. The new file enters the internal document workflow.
  5. Another employee uses it as source material for AI, allowing the problem to reappear.

The critical point is that later files may look like ordinary internal documents. That makes it harder to assess their origin, trustworthiness, and the scale of potential manipulation.

What Should Your Organisation Implement Now?

Organisations do not need to stop using AI in Microsoft 365. They do need controls that distinguish source data from AI instructions and require review before an output is used.

Minimum Safe-Use Rules

  • Treat documents from customers, suppliers, and partners as untrusted when they will be used with Copilot.
  • Do not allow AI to automatically approve, send, or publish documents without human review.
  • Verify figures, terms, dates, names, recommendations, and key passages in every AI-created or AI-edited document.
  • Limit Copilot access to repositories and data strictly according to the needs of each role.
  • Define which documents may be used as AI sources and which require prior review.
  • Assign ownership for AI governance: policies, access, incidents, and periodic risk review.
  • Train staff not only on phishing, but also on prompt injection and AI-driven content manipulation.

What Should an Audit Review?

An audit of Microsoft 365 and AI security should assess more than technical configuration. It should also evaluate workflows, data sources, permissions, and document-approval rules.

A practical audit should examine:

  • who has access to Microsoft Copilot and how they use it,
  • which data sources and repositories AI can access,
  • whether Microsoft 365 permissions match real business roles,
  • where documents used as Copilot context originate,
  • whether the organisation classifies documents and data,
  • who reviews outputs generated by AI,
  • how suspected document manipulation is detected, reported, and investigated,
  • whether critical files retain source provenance and change history.

“In AI security, the key question is no longer only: does the model have access to data? It is equally important to ask: can the organisation distinguish data that AI should analyse from content that attempts to control its behaviour? Without that boundary, an external document can become a business-process risk.” — Eng. Marcin Białczyk, CHORS.NET.

Author profile: Marcin Białczyk — CHORS.NET

How Should a Company Respond to Suspected Manipulation?

If a Copilot-generated or Copilot-edited document contains inconsistencies, do not reuse it as source material for another AI task. Preserve the original file, the resulting file, version history, and information about the sources used.

Then:

  1. Stop further sharing of the suspicious files.
  2. Identify source documents and users who used them in AI-assisted workflows.
  3. Compare document versions and validate critical business information.
  4. Review permissions, file locations, and sharing history in Microsoft 365.
  5. Assess whether similar files may have been used in other Copilot tasks.
  6. Update procedures for external documents and train relevant users.

Frequently asked questions

Is Copilot for Word unsafe?

No. Copilot for Word can improve productivity, but like any AI tool it requires appropriate access controls, configuration, and procedures for handling untrusted content. Risk increases when an organisation automatically trusts both source documents and AI-generated outputs.

Does this issue affect only Word documents?

The reported proof of concept involved Copilot for Word. However, the wider risk class — prompt injection through untrusted content — applies to AI systems that process documents, emails, web pages, and knowledge bases.

Is blocking Word macros enough?

No. The prompt-injection scenario described in the research does not depend on macros. Macro controls remain important, but they do not replace safe AI-use policies, document-source controls, and output verification.

Can a document from a trusted partner be treated as safe?

Not always. A partner may not know that a document contains unwanted content, especially if the file has passed through multiple people, systems, or AI tools. When working with Copilot, every external document should be treated as material requiring verification.

How can CHORS.NET help?

CHORS.NET provides a Vulnerability Audit covering configuration analysis, external exposure testing, and prioritised remediation. The audit can verify permissions, document workflows, and data sources used by AI.

CTA

If your organisation uses Copilot, SharePoint, Teams, OneDrive, or Word to process customer and partner documents, assess whether your AI workflows create a new route for information manipulation. Contact CHORS.NET to scope a Vulnerability Audit.

Sources

  1. Banandre — Your Copilot Is Spreading a Worm Through Your Word Documents
  2. DataWater — Copilot for Word AI Worm (Context Collapse, Part 3)
  3. CHORS.NET — Vulnerability Audit
  4. Marcin Białczyk — author profile, CHORS.NET

CHORS Cryptogram

Minimalistyczny zapis na miesięczne analizy. Surowe dane, trendy audytowe i analiza zero-day prosto na skrzynkę. Zero marketingowego szumu.

Klucz GPG dostępny na życzenie.