When you upload a photo to Microsoft Copilot and type a prompt to edit it, you likely assume the interaction stays between you and the software. According to a report by 404 Media, that assumption may not hold. Some apps have been found secretly tracking users without clear disclosure, and the concern over hidden data access extends to AI tools as well.
Human contractors were reportedly shown users’ original prompts, uploaded images, and two AI-generated edit options as part of a quality evaluation process. The reviewers’ stated job was not content moderation.
They were reportedly asked to pick the better of two edits based on quality criteria: whether the edit followed the user’s instruction, preserved unchanged areas of the image, avoided visual artifacts, and looked better overall.
What Contractors Reportedly Saw
Contractor accounts described repeated exposure to disturbing and sexualized material that quality-review assignments would not typically be expected to involve.
Contractor discussions reviewed by 404 Media allegedly described repeated exposure to sexualized requests, imagery involving young girls, upskirt photos, animal-sacrifice images, and fetish content. Evaluation materials attributed to Microsoft-related documentation by 404 Media reportedly told reviewers to rely on immediate intuition when comparing images side by side.
An anonymous contractor told 404 Media: “Faces are always uncensored, and many of the prompts are sexual in nature and dubiously consensual.”
The reporting does not establish that every Copilot prompt or uploaded image is reviewed by a person. It supports the narrower claim that at least some contractors were shown user-submitted material during quality evaluations.
Microsoft’s Terms and Response
Microsoft’s privacy statement says Copilot data, including prompts and related content, may be used to provide, improve, monitor, troubleshoot, and protect the service. De-identified data may also be used to develop and fine-tune AI models. Europe already restricts Microsoft and other cloud providers from handling sensitive government data, reflecting broader policy concern about how such companies manage personal information.
When contacted by 404 Media, Microsoft said it uses customer data as described in its terms, including to improve products and enforce its code of conduct. That statement does not address how many contractors can access consumer uploads, or what automated screening occurs before material reaches a human reviewer.
Microsoft’s consumer Copilot terms define a prompt broadly, covering text, images, files, audio, and video. Those same terms prohibit adult content, child sexual exploitation and abuse material, disturbing content, and nonconsensual image edits or deepfakes. The terms restrict what users may submit, but they do not resolve what filtering happens before material reaches a human reviewer.
One distinction matters here: enterprise Copilot carries stronger data protections, including commitments against using organizational data to train foundation models without permission. Those protections do not automatically extend to consumer Copilot.
Prolific’s Role and Unresolved Questions
The involvement of contractor platform Prolific raises additional questions about reviewer safeguards and user disclosure.
At least one contractor company identified in the 404 Media report was Prolific, a platform that supports human feedback, preference tuning, and AI benchmarking tasks. Prolific’s own researcher guidance acknowledges the risk of exposing participants to explicit generative-AI content. It recommends a harmful-content prescreener and content warnings for relevant studies.
Several material questions remain unanswered. The reporting does not establish how many contractors had access to user uploads, or what share of image-editing tasks received human review. It also does not confirm whether users receive a clear disclosure at the point of upload that a person may see their material.
Microsoft’s transparency documentation states that uploaded images are deleted within 30 days after a conversation ends and that automated detection systems screen uploads, including for child safety-related material such as child sexual exploitation and abuse material. Those disclosures do not fully resolve questions about metadata handling or how reliably automated filtering intercepts prohibited content before it reaches a quality-review queue. Neither Microsoft nor Prolific has been shown to have violated a specific law based on the available reporting.
What This Means for You
The gap between user expectation and reported contractor access is the practical issue for anyone who uploads personal images to a consumer AI service.
If you use Copilot’s image-editing tools, your prompts and uploaded photos may be visible to human contractors under certain conditions, not just processed by software. Microsoft’s terms permit this use, though the extent and circumstances of human review are not clearly disclosed at the point of upload.
Until Microsoft provides clearer guidance on when human review applies and what filtering precedes it, treat any image you upload to a consumer AI service as potentially visible to a person. Knowing how to stay safe with your personal data across digital services is increasingly important in this environment.




























