Microsoft's Recall AI feature stored sensitive data in a way researchers called a security risk

Microsoft's Recall feature, which takes continuous screenshots of a PC and makes them searchable with AI, was found to store that data, including passwords and sensitive content, in an unencrypted local database. The backlash forced Microsoft to delay and re-engineer the feature.

Microsoft · Incident May 30, 2024 · Indexed Jun 3, 2026 · 2 sources

The feature quietly captured everything on screen and stored it where an attacker on the device could read it.
What
Microsoft's Recall feature, which takes continuous screenshots of a PC and makes them searchable with AI, was found to store that data, including passwords and sensitive content, in an unencrypted local database.
Incident date
May 30, 2024
Who
Microsoft
Failure mode
Data Leakage
AI surface
Copilot
Severity
High

What happened

In 2024 Microsoft announced Recall, which silently captured screenshots of user activity and indexed them for AI search. Researchers showed the data, including passwords and sensitive on-screen content, sat in an accessible local store, making it a target for attackers. After widespread criticism Microsoft delayed Recall and added encryption and opt-in controls.

What broke inside the model

Failure path · mode profile · Data Leakage
  1. 01 · TriggerA request triggers retrieval or context loading.
  2. 02 · Model stepThe context pulls in another user's content.
  3. 03 · Control gapNo boundary enforces isolation at the moment of output.
  4. 04 · FailurePrivate data crosses into the response.
  5. 05 · ConsequenceOne user sees another's data, and disclosure follows.

One user's content crosses the retrieval boundary into another's response.

The system surfaced data that should have stayed contained: another user's record, a secret, or training data. The failure sits at the boundary between what the model can access and what it should reveal, a boundary that was never enforced at the moment of generation.

Public visibilityHigh
Regulatory exposurePossible
Customer impactMany customers
Financial impactEstimated
Time to disclosureWeeks

Feature delayed and re-engineered after security backlash

  1. PressMicrosoft Recall: security and privacy concerns (BBC News)bbc.com
  2. PressMicrosoft Recall security analysis (Wired)wired.com
Permalinkhttps://failureindex.ai/failures/microsoft-recall-ai-feature-stored-sensitive
CitationAI Failure Index. "Microsoft's Recall AI feature stored sensitive data in a way researchers called a security risk" (FI-0051). Realm Labs. https://failureindex.ai/failures/microsoft-recall-ai-feature-stored-sensitive (indexed Jun 3, 2026).
Share cardA branded image of this record for posts and slides.

Data fields CC-BY 4.0, prose citation permitted. Incident ID FI-0051. Full dataset at /data.

Note from Realm Labs, the Index steward

How Realm would have caught this

Controls for this failure mode
  • Prism
  • OmniGuard
  • AI Detection & Response (AIDR)

Realm can detect when a response is about to emit data that falls outside the bounds of the current user and context, and block or redact it inline, at the moment of generation rather than after the data has left.