LIVE FEED
FIRST LOOK ATLAS OWASP MEDIUM Moderate risk · Monitor closely RELEVANCE ▲ 5.8

Microsoft Copilot Gains Local File Access via Hybrid Intelligence

FIRST LOOK MEDIUM ↗ RAPID
  • What shipped: Microsoft Copilot gains local file access and multi-step OS action execution via Hybrid Intelligence on Windows.
  • Who benefits: Enterprise security teams and endpoint administrators who must now govern AI agent access to local files and OS-level actions on Windows devices.
  • Next steps: Audit which user and device populations will receive Hybrid Intelligence Copilot features and determine opt-in/opt-out scope before rollout. · Extend existing DLP and endpoint detection policies to monitor AI-initiated file operations, including rename, compress, and email-attachment actions. · Establish behavioural baselines for legitimate Copilot file access patterns to enable anomaly detection when chained file operations occur.
Microsoft Copilot Gains Local File Access via Hybrid Intelligence

Defender Impact

Microsoft’s Hybrid Intelligence expansion of Copilot marks the first broadly deployed instance of a consumer-grade AI agent with sanctioned local file access and multi-step OS action authority on Windows endpoints. Security teams now have a concrete, vendor-defined agentic pattern to assess, baseline, and govern — which is more actionable than defending against hypothetical agentic behaviour.

Capability Overview

Announced at Microsoft’s Windows and Surface event on 7 October 2026, Hybrid Intelligence is Microsoft’s architectural approach to blending on-device and cloud AI inference. Under this model, Copilot can query local file systems, take OS-level actions (file search, renaming, compression), and chain those actions with cloud-dependent tasks like drafting and sending emails — all within a single natural-language instruction.

The demo scenario — gathering tax documents, renaming them, zipping the folder, and drafting an accountant email — illustrates a capability pattern defenders should recognise: multi-step, cross-context autonomous execution touching local storage, file metadata, and outbound communications simultaneously. This is not a single-tool call; it is an orchestrated agentic workflow operating across endpoint and cloud surfaces.

Microsoft has positioned Hybrid Intelligence as an efficiency play, reducing round-trips to the cloud for tasks that can be partially resolved on-device. The feature is expected to roll out to Copilot over the coming months, with a new Windows search experience also announced as part of the same initiative.

Defensive Advances

The formalisation of this capability by a major platform vendor is itself a defensive advance: it gives security teams a defined, documented behaviour to build policy around, rather than having to anticipate undocumented or shadow AI tool usage by end users.

Endpoint policy surface is now explicit. Defenders can begin designing Copilot-aware endpoint policies — governing which directories Copilot can access, what file operations are permitted, and which outbound actions (email attachment, cloud upload) require additional authorisation.

Behavioural baseline opportunity. The chained action pattern (search → rename → zip → email) creates a detectable signature. Security teams with endpoint telemetry can now baseline legitimate Copilot-initiated file operations and flag deviations — for example, unexpectedly large archives or unusual destination addresses.

Data residency clarity from Hybrid Intelligence. The explicit local/cloud split gives data governance teams a framework for determining which operations remain on-device (lower risk for sensitive data) versus which are cloud-routed (requiring data classification checks before Copilot access is enabled).

Residual Gaps

Several maturity questions remain before defenders can fully govern this capability:

Permission scoping is not yet detailed. The announcement does not specify the granularity of file-system access controls — whether Copilot can be restricted to specific folders, whether it respects existing NTFS permissions transparently, or whether enterprise policy can limit access to non-sensitive directories only.

Audit logging maturity is unknown. Multi-step agentic actions require comprehensive, tamper-evident logging to support incident investigation. It is not yet clear whether Copilot’s Hybrid Intelligence actions will appear in Microsoft Purview audit trails or equivalent enterprise logging at action-level granularity.

Consent and oversight UI is unspecified. The demo showed Copilot acting on a single natural-language instruction without visible confirmation steps. Enterprises will need to understand what human-in-the-loop checkpoints exist by default and how to enforce additional approval gates for sensitive operations.

Integration with existing DLP controls. Whether Hybrid Intelligence respects Microsoft Purview sensitivity labels during file operations — particularly before compressing and emailing — is a material gap that should be resolved before wide enterprise deployment.

Framework Mapping

  • AML.T0086 (Exfiltration via AI Agent Tool Invocation): Copilot’s ability to autonomously attach and send files maps directly to this technique; defenders should ensure outbound email actions are logged and reviewable.
  • LLM08 (Excessive Agency): The multi-step autonomous execution pattern is a textbook excessive agency scenario; governance controls should define the permitted action scope explicitly.
  • AML.T0051 (LLM Prompt Injection): Local files ingested during search operations could contain adversarial instructions; defenders should consider whether file content can redirect Copilot’s subsequent actions.
  • LLM06 (Sensitive Information Disclosure): Cloud-routed processing of locally sensitive files requires data classification awareness before Copilot access is broadly enabled.

Deployment Considerations

Organisations should treat the Hybrid Intelligence rollout as an endpoint policy event, not just a productivity update. Sequence deployment by data sensitivity: begin with devices and user populations that handle non-sensitive data, establish telemetry baselines, then extend to regulated environments only after audit logging and DLP integration are confirmed.

Prioritise a Copilot-specific data access policy before rollout — defining permitted directory scope and prohibited file types. Co-ordinate with Microsoft Purview administrators to ensure sensitivity labels are respected during file operations.

Defender Checklist

  • Identify which Windows endpoints and user groups are in scope for Hybrid Intelligence rollout
  • Define permitted and restricted directory access scope for Copilot file operations
  • Confirm whether Microsoft Purview audit logging captures Copilot-initiated file actions at operation level
  • Review DLP policies to ensure sensitivity-labelled files are blocked from unsanctioned Copilot email actions
  • Establish SIEM alerts for anomalous Copilot file patterns (large archives, unusual recipients)
  • Test prompt injection resilience: verify that file content cannot redirect Copilot to unintended actions
  • Define human-in-the-loop approval requirements for high-risk operations (external email, bulk file moves)

References

◉ AI THREAT BRIEFING

Stay ahead of the threat.

Twice-weekly digest of critical AI security developments — every story mapped to MITRE ATLAS and OWASP LLM Top 10. Free.

No spam. Unsubscribe anytime.