Aller au contenu

Copilot: humans see your photos. What about the rest?

Contractors grading Copilot's photo edits see users' pictures, faces included. It is not just Microsoft. What each service allows, and the setting to check tonight.

Advertisement

You send Copilot a photo of yourself on the beach, with a simple request: remove the passer-by in the background.

Somewhere, someone you will never meet sees your photo, your face and your request. In front of them, two edits proposed by the AI. Their job: say which one is better.

This is not a hypothesis. It is what an investigation published on 28 September by the American outlet 404 Media describes.

What the investigation revealed

404 Media obtained internal documents: work instructions, real examples of requests and photos, and the forum where the people doing this work talk. There are "at least hundreds" of them, according to the outlet, recruited notably through the Prolific platform, which declined to comment.

Their job is not surveillance. It is to grade the quality of Copilot's edits, to help the AI improve. But to grade an edit, you have to see the original photo.

"Faces are always uncensored," one of them says. And many requests are sexual, sometimes targeting real people who never asked for anything.

The most troubling detail lies in Microsoft's own documentation. Its Copilot privacy FAQ says that, for uploaded images, the company takes steps such as "blurring images of faces". Yet since 18 August a new Copilot app has been in service, and its help pages no longer mention either blurring or human review.

Why humans read

This is not peculiar to Microsoft. It is how AIs learn what a good answer is: you show two to a person, they pick the better one, and the model adjusts. Millions of times.

On 14 September, the same outlet reported that OpenAI also employs hundreds of contractors who read real requests sent to ChatGPT, sometimes whole conversations, without seeing users' names. OpenAI says it removes personal data before review, while acknowledging that sensitive details can slip through. Anthropic confirmed to the outlet that it also uses human review.

In other words, the question is not whether a human can read what you write to an AI. It is under what conditions, and whether you can avoid it.

The setting to check tonight

Every major assistant offers an option so your conversations are not used to improve its models. That is the first thing to do.

ChatGPT. In settings, under "Data controls", the option "Improve the model for everyone". Switched off, your conversations are no longer used for training. For a one-off question, "Temporary chat" does not appear in your history and is not used for training, but OpenAI may keep a copy for up to 30 days for safety reasons.

Gemini. In "Gemini Apps Activity", the "Keep Activity" option. Switched off, your future conversations are no longer used for training, but Google keeps them for 72 hours. Careful: a conversation already reviewed by a human is not deleted when you delete your activity. It can be kept for up to three years.

Claude. In the privacy settings, the option that allows or refuses the use of your conversations to improve Claude. If you accept, your data can be kept for five years; otherwise, thirty days. "Incognito chats" are never used for training.

Copilot. In your profile, under privacy, two training options: on written conversations and on voice conversations. Your exchanges are kept for 18 months by default.

What no setting prevents 🔍
Switching off training does not switch off everything. At OpenAI, Anthropic and Microsoft, a conversation flagged by safety systems (suspected abuse, prohibited content) can be examined by humans, whatever your setting. Microsoft puts it in black and white: when a breach of the rules is suspected, you cannot opt out of human review. And OpenAI gives this advice on its own page: do not enter sensitive information you would not want reviewed.

The simple rule

Settings reduce the risk. They do not remove it. The safest protection is still what you choose not to send.

Before sharing a photo or a document with an AI, ask yourself one question: would I accept a stranger seeing this? If the answer is no, don't. That goes especially for photos of other people, above all children, for ID documents, and for anything to do with health.

And if a service ever warns you that your data has leaked, here are the right reflexes.

A letter, not a diary

We talk to an assistant the way we would write in a notebook: alone, in the evening, with no witness. That is what makes it so useful, and what makes this investigation so unsettling.

But a conversation with an AI is less like a locked diary than a letter. It goes out, it is read by a machine, and sometimes, somewhere, by someone else.

Write knowing the envelope can be opened.

Advertisement