site banner

Small-Scale Question Sunday for October 26, 2025

Do you have a dumb question that you're kind of embarrassed to ask in the main thread? Is there something you're just not sure about?

This is your opportunity to ask questions. No question too simple or too silly.

Culture war topics are accepted, and proposals for a better intro post are appreciated.

2
Jump in the discussion.

No email address required.

Literally just yesterday I read about this: https://www.adamlogue.com/microsoft-365-copilot-arbitrary-data-exfiltration-via-mermaid-diagrams-fixed/ TLDR for those who doesn't enjoy the technical details: asking Microsoft AI to review some document may result in all your data (i.e. all corporate data accessible to you and Office 365 tools) be stolen and exfiltrated to arbitrary third party. One of the proposed solutions for this (besides the immediate short-term fix) is what you are talking about - mechanisms that ensure AI stays at the original task and does not decide "screw that whole document explaining thing, I must instead just gather all confidential emails and send them to dr_evil@evil.com". Of course, having N levels of checks only means you need N+1 exploits to break this, which somebody with enough time and motivation will eventually find.