What the Copilot AI worm is, in plain terms
The Copilot AI worm is a demonstrated attack that hides malicious instructions inside an ordinary Word document, then uses Microsoft Copilot for Word (the AI assistant built into Word) to copy those instructions into new files as people work. Nobody has to click a dodgy link or install anything. The document itself becomes the carrier, and your own AI assistant does the spreading.
For a small business, the short answer is this: any Word file that arrives from outside, or even one that has passed through several hands inside your own team, could contain instructions you cannot see. If you feed that file to Copilot, you may be handing control of the AI to whoever wrote those hidden instructions. That is the risk, and the rest of this guide explains how it works and what to do about it.
How the trick actually works
The attacker writes a set of instructions into a Word document and formats them as white text on a white background. A person reading the file sees a normal contract, proposal or report. The hidden text is invisible to the eye but perfectly readable to software.
This is a technique called “prompt injection”. A prompt is simply the instruction you give an AI tool. Prompt injection means smuggling extra commands into that tool disguised as ordinary content, so the AI carries them out as if you had typed them yourself.
The moment it spreads
When someone asks Copilot to draft, summarise or edit based on that document, Copilot reads everything in the file, including the hidden text. It cannot tell the difference between the genuine request from the user and the concealed instructions planted by the attacker. It treats both as the job.
Following those hidden instructions, Copilot edits the document and quietly writes the same concealed commands into the new version. That new file is now a carrier too. The next person who opens it and uses Copilot passes the problem along again. Because real employees are creating and editing these files through normal daily work, the spread is very hard to spot and even harder to trace back to its source.
Where this came from, and why it matters now
Security firm Malwarebytes reported that a researcher tricked Microsoft Copilot for Word into behaving like a self-spreading “worm”. A worm, in security terms, is malicious code that copies itself from one place to another without anyone needing to click or install it. That self-copying behaviour is exactly what makes this demonstration worth your attention.
This is a demonstrated technique reported by a security firm, not a wave of attacks sweeping through UK inboxes. Treat it as an early warning about how AI assistants can be misused, rather than a live emergency. The value in understanding it now is that you can build good habits before this style of attack becomes common.
Why there is no simple fix
According to Malwarebytes, the researcher could still reproduce the full attack even after Microsoft rolled out several fixes and upgraded to newer AI models. That is the uncomfortable part. This is not a single bug that a patch closes for good.
The reason is structural. Current AI systems cannot reliably separate trusted instructions from the user and untrusted content pulled from a document. Both sit in the same place in the AI’s working memory, so the AI weighs them the same way. Experts warn this class of attack may never be fully solved, because the confusion is baked into how these tools read and act on text.
What “structural” means for you
It means you cannot rely on the vendor to make the problem disappear entirely, and you should not wait for a fix before changing how you handle documents. The realistic defence is process, not a product: control what goes into the AI, and check what comes out. That is a habit any business can adopt without new software.
What this means for your business
You do not need to panic, and you do not need to stop using Copilot. What you need is a more cautious attitude to documents that arrive from outside, or that have travelled through many hands. The risk here is not a virus in the traditional sense. It is your own AI assistant being quietly redirected to do something you never asked for.
The practical worry for an SME is not dramatic sabotage. It is subtle. Hidden instructions could nudge Copilot to insert misleading wording into a contract, alter figures in a quote, or plant instructions that keep spreading through your document library. Because the changes look like normal edits, a busy team can miss them. This is a good moment to think about how your firm handles AI tools generally, and our guide to using ChatGPT and Copilot at work under UK GDPR covers the wider governance you should have in place.
A practical plan to reduce the risk
You can lower your exposure with a handful of simple rules. The table below lays out the main options, when each one fits, and what it costs you in effort. Approximate effort is a guide only and will vary with your setup.
| Control | What it does | Effort | Best for |
|---|---|---|---|
| Treat outside files as untrusted | You review any document from beyond your organisation before feeding it to Copilot | Low, a habit | Every business using Copilot |
| Check Copilot output before sharing | You read edited files before reusing or sending them on | Low, a habit | Teams that pass files around often |
| Reveal hidden formatting | You spot white-on-white text by selecting all and changing colour, or using formatting tools | Low to medium | Reviewing high-value contracts and quotes |
| Turn Copilot off in Word | You remove the risk entirely on machines that do not need it | Low, one setting | Staff who never use Copilot |
| Restrict Copilot centrally | Admins limit Copilot’s visibility across Microsoft 365 | Medium, admin task | Firms with an IT admin or provider |
How to spot hidden text yourself
You can often reveal concealed instructions in a Word document by pressing Ctrl and A to select everything, then changing the font colour to something bold like red. Text that was hidden in white will suddenly appear. It is not foolproof, because attackers can hide content in other ways, but for the white-on-white trick described here it is a quick check before you trust a file.
How to turn Copilot off in Word
If you do not use Copilot and want it off, go to File > Options > Copilot and untick “Enable Copilot”. That removes the assistant from that copy of Word, so a document with hidden instructions has nothing to act on. If you are still weighing up whether the assistant earns its place, our comparison of Microsoft Copilot and Google Gemini for business will help you decide before you commit.
How admins can restrict Copilot
If you run Microsoft 365 for a team, an administrator can limit Copilot’s visibility and availability through the Admin Center settings. That lets you switch the assistant off for staff who do not need it while keeping it for those who do, which shrinks the number of machines where a poisoned document could do anything at all.
Building this into your wider security
This threat does not sit on its own. It belongs alongside the everyday cyber hygiene every small firm should already have. The UK’s National Cyber Security Centre publishes clear, jargon-light guidance for small businesses, and it is worth a read even if security is not your job.
A sensible baseline is to work towards a recognised standard so your defences are consistent rather than ad hoc. Our explainer on Cyber Essentials for UK small businesses walks through what the scheme covers and why it helps. The document habits in this guide slot neatly into that broader routine.
Do not forget the data angle
If a hidden instruction ever caused Copilot to expose or misuse personal data, you would be dealing with a data protection issue as well as a security one. The Information Commissioner’s Office is the UK regulator here, and its guidance on AI and personal data is a useful reference when you set your internal rules. Knowing where a breach would leave you legally is part of taking the risk seriously.
Mistakes people actually make
The failures here are rarely technical. They are about assumptions and habits, and they are easy to avoid once you name them.
- Trusting a file because it came from a known contact. A supplier or client can pass on a poisoned document without knowing it. Familiar sender does not mean safe content.
- Assuming a patch has fixed it. The researcher reproduced the attack after fixes and model upgrades. Do not drop your document checks because you heard the problem was solved.
- Skimming Copilot’s output. When the AI edits a file, people tend to trust the result and move on. Read what it produced, especially in contracts, quotes and anything with numbers.
- Leaving Copilot on everywhere by default. Every machine with the assistant enabled is a place a poisoned file could act. If a member of staff never uses it, switch it off for them.
- Treating this as an IT-only problem. The people opening documents are your whole team. The habit has to reach everyone who touches shared files, not just whoever manages the software.
- Copying files onward without a glance. Reusing an old template or forwarding a document without checking it can keep a hidden instruction alive and spreading.
Getting the benefits without the exposure
None of this means AI assistants are a bad idea. Used with sensible checks, they save real hours on drafting, summarising and admin. The point is to pair the convenience with a light review step, not to abandon the tools.
If you are just getting started, our guide to how UK small businesses can start using AI without a tech team shows where the quick wins are. And if you want to put AI to work on specific jobs safely, the five AI workflows a ten-person firm can run this quarter gives you practical starting points that are easy to supervise.
Frequently asked questions
Is the Copilot AI worm a real virus on my computer?
Not in the traditional sense. There is no malicious program installed on your machine. The instructions live inside a Word document as hidden text, and the “spreading” happens when Copilot copies them into new files. The risk is your AI assistant being redirected, not your operating system being infected.
Should I stop using Microsoft Copilot?
No, unless you do not need it. The sensible response is to keep using it while checking what you feed in and what it produces. If a member of staff never uses Copilot, turning it off for them removes the risk on that machine at no cost to productivity.
Will a Microsoft update fix this for good?
Probably not completely. Malwarebytes reported the attack could still be reproduced after Microsoft’s fixes and newer AI models, because the underlying confusion between trusted and untrusted text is structural. Keep updating your software, but do not treat any single update as the end of the matter.
How would I even know a document was affected?
You often cannot tell by reading it, which is the whole problem. You can reveal white-on-white text by selecting all content and changing the font colour, though that is not guaranteed to catch every method. The more reliable defence is caution with outside files and a quick review of anything Copilot edits.
Does this affect other AI assistants too?
Prompt injection is a general weakness in AI tools that read documents, not a flaw unique to Copilot. The specific worm behaviour reported here concerns Copilot for Word, but the underlying lesson applies whenever an AI reads untrusted content. If you are comparing assistants, our look at which AI assistant fits your firm covers how the main tools differ.
What to do next
- Set a two-part habit today. Tell your team to treat any document from outside the business as untrusted before feeding it to Copilot, and to read Copilot’s output before sharing or reusing the file. Write it down as a simple rule everyone can follow.
- Decide who actually needs Copilot. Turn it off in Word for staff who do not use it via File > Options > Copilot, and have your admin limit Copilot’s visibility across Microsoft 365 for the rest through the Admin Center settings.
- Fold this into your wider security. Review your basics against the NCSC’s small business guidance and work towards Cyber Essentials so your defences are consistent rather than one-off.
- Review your high-value templates. Check contracts, quotes and reusable documents for hidden text now, so you are not unknowingly carrying and spreading poisoned instructions in your own files.
A quick review beats an untraceable problem spreading quietly across your business. Check what goes into Copilot, and check what comes out, before you pass a file along.
Image: Dominic’s pics (BY) via Openverse





