THU, AUGUST 20, 2026
Independent · In‑Depth · Practitioner‑Tested
General

Copilot Personal vs Copilot Enterprise: What CoSnitch Changed About the Answer

One of these was affected by a critical one-click data theft flaw. The other was not, and the reason matters.

🕐 6 min read 👁 10 views 📅 Aug 19, 2026
THE VERDICT

● CoSnitch hit Personal only. Microsoft states enterprise customers were unaffected and no customer action is required.

● But do not read that as enterprise being safe. SearchLeak, an earlier Varonis finding this year, turned Microsoft 365 Copilot Enterprise into a silent exfiltration channel.

● The real difference: who controls the connectors. On Personal, the user does. On Enterprise, an admin does — and that is the whole security argument.

Head to head

Copilot Personal Microsoft 365 Copilot
Affected by CoSnitch Yes, patched 18 Aug 2026 No, per Microsoft
Affected by SearchLeak Not the reported target Yes
Who approves connectors The individual user Tenant administrator
Typical reach Personal Gmail, Drive, Calendar Corporate mail, SharePoint, Teams
Blast radius if breached One person Whatever that account can reach
Central audit trail None Tenant logging available

The distinction that actually matters

Reading "enterprise was unaffected" as "enterprise is safer" gets the causation backwards. Both products expose the same architectural pattern: an assistant with broad connector access, a persistent memory store, and a model that will explain its own behaviour to anyone who asks patiently.

What Enterprise adds is not a different architecture. It is governance over that architecture — an admin decides which connectors exist, tenant logging captures access, and there is somebody whose job it is to review it. On Personal, the person approving Gmail access is the person who wanted the feature five seconds earlier.

THE GAP NEITHER PRODUCT CLOSES

The CoSnitch memory poisoning wrote no process, no file, no network connection and no log entry. It was visible only inside Copilot's memory interface. Tenant logging does not help if the artefact never touches a logged surface. Enterprise governance narrows who can connect what. It does not yet see inside assistant memory.

What to do on each

If you are on... Do this
Copilot Personal Read your memory entries, then remove every connector you are not using
Microsoft 365 Copilot Audit tenant-approved third-party apps and confirm your tooling can see assistant-originated access
Both, personally and at work Keep personal mail off the work assistant and vice versa. Mixed reach is the real risk
Deciding between them Enterprise, for anything touching company data. The governance layer is the product

FAQ

Was Microsoft 365 Copilot affected by CoSnitch?

Microsoft says no, and that no customer action is required. CoSnitch was scoped to Copilot Personal.

So is the enterprise version secure?

It has better governance, not different architecture. SearchLeak, disclosed earlier this year by the same researchers, did affect Microsoft 365 Copilot Enterprise.

Does tenant logging catch memory poisoning?

Not on the evidence from CoSnitch. The memory write produced no logged artefact at all — it appeared only in the assistant's own memory interface.

What is the single highest-value control?

Reducing connectors. Every integration you remove shrinks the blast radius of every future flaw in this class, on either product.

⚖ Our Verdict

CoSnitch hit Personal only, but Enterprise adds governance rather than different architecture. Neither sees inside memory.