Eigen RadarAI
Analysis

Private Viva conversations enter Copilot's answers

Microsoft 365 Copilot now grounds answers in private Viva Engage content that a user may access. 404 Media reported that an Israel-funded operation publishes AI-written policy articles aimed at language models. Attnlocate researchers tested a method for locating the untrusted context span steering an agent's tool call.

Artificial Intelligence··Midday
Blank conversation cards inside a translucent boundary pass through an authorized aperture into a luminous assistant context while irregular outside fragments remain excluded.

Private communities enter the grounding pool

Microsoft 365 Copilot began using content from private Viva Engage communities and events as grounding for answers in its August 25 update. That content had previously been outside Copilot's scope. Microsoft says a user can see only material available under their existing permissions. The announcement does not detail what happens to an indexed copy when community membership ends or how long content is retained; the safeguard it describes is limited to the access check when an answer is produced.[1]

A web campaign writes for machine readers

Foreign Agents Registration Act filings reviewed by 404 Media show that the Hanover Institute for Public Policy website is funded by Israel and operated by advertising firm Piro Inc. The site published more than 100 policy articles in less than a month. Pangram judged the three articles it tested to be entirely AI-written apart from their bibliographies. An llms.txt file makes the content easier for language models to ingest, while Piro markets its service as AI Story Optimization intended to influence how chatbots describe an organization.[2]

Attnlocate first finds the span doing the steering

Attnlocate locates the context span influencing an agent's tool call in attention patterns and then evaluates the authority of the source that supplied it. Tests covered indirect prompt injection and tool poisoning across 10 agent configurations from five model families; the researchers report mean AUROC of 0.956 and a 0.934 true-positive rate at a 0.067 false-positive rate. Those figures do not establish performance for every content type in a live product. Private-community permission, the provenance of web content and the authority of text influencing a tool call are different controls; meeting in one context channel creates a shared authority question, but one control may not substitute for the others.[3], [1], [2]

References

  1. News sourceMicrosoft LearnMicrosoft 365 Copilot brings private Viva Engage conversations into its answers↩1↩2
  2. News source404 MediaAn Israel-funded think tank publishes AI-written articles aimed at what chatbots repeat↩1↩2
  3. News sourcearXivAttnlocate finds the untrusted text span steering an agent↩