Two changes close a gap that has caused plenty of trouble in practice: files that Copilot creates now automatically take on the highest sensitivity label of the sources used. If Copilot cannot apply a label, the user is notified.

Until now, anyone who had a summary produced from three confidential documents received an unprotected file and had to add the classification themselves. In everyday work, that regularly slipped through.

Watermarks for generated media

In parallel there is a policy that adds a visible or audible watermark to generated or altered video and audio content. Important: this policy is off by default and must be actively enabled. For images, users decide for themselves in their settings.

What this means in practice

  • Inheriting the protection level helps, but replaces no order. It only works as well as the source documents are labelled. Where nothing is labelled, there is nothing to inherit.
  • The watermark is a deliberate decision. Anyone sharing generated media externally should enable the policy. Otherwise generated material later becomes indistinguishable from recorded material.
  • Both belong together. Inheritance protects against unintended sharing; the watermark creates traceability.

Our assessment

This is the kind of change that attracts little attention and has a lot of effect. Protection now applies where it belongs: when the file is created, not in later clean-up work.

The honest caveat: this function rewards companies that have already labelled their documents. Where sensitivity labels were never introduced, it changes nothing and becomes a reason to catch up.