180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-149
Consumer AI · United States · 2024 · Surveillance by default with weak safeguards

Microsoft built a feature that screenshotted everything you did, and delayed it after researchers showed the data sat unprotected

By Ellie Harris · Filed Announced May 2024; delayed June 2024

Alleged: Microsoft (Windows Recall) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Microsoft built a feature that screenshotted everything you did, and delayed it after researchers showed the data sat unprotected

What happened

It was reported that in 2024 Microsoft announced Recall for its new Copilot PCs. Reporting indicates the feature took screenshots of a user’s screen a few seconds apart and turned them into a searchable timeline of almost everything they had seen or done, from web pages to chats, and that the original design was intended to be enabled by default on eligible Copilot+ PCs. The problem was what those screenshots could contain: reporting found that the filtering did not reliably exclude sensitive information, so snapshots could include passwords and financial details.

Security researchers then showed that the snapshots were stored on the computer without proper protection, so that if an attacker already had access to the machine, the data was easy to find and read, and one researcher released a tool demonstrating how quickly the timeline could be extracted. After a strong public backlash, Microsoft delayed Recall in June 2024, changing the design so it was off by default, encrypting the stored snapshots and requiring a Windows Hello sign-in before the timeline could be opened. Microsoft said it wanted more feedback before releasing the feature widely, and it later reintroduced Recall through a staged rollout in its redesigned form. The security and privacy criticism relates to that first design, before those changes.

What an auditable version would have shown

Before launch, you would want a very clear picture of what Recall captured, where that information was stored, how it was protected and who could access it. You would also want evidence that somebody had tested the store from the perspective of a realistic attacker and recorded what happened, and an answer to one more simple question: did the person actually choose to turn this on? With those records, the risks of creating a searchable history of someone’s activity could have been examined and signed off before launch, rather than being demonstrated by outside security researchers.

Where the gap was

Recall was designed to make recording enormous amounts of information easy. Securing that information was the harder part. A searchable history could contain passwords, messages and financial information, yet the original design was intended to be on by default and the store of sensitive information it created was not properly protected. The person using the computer had also not necessarily made an active choice to create that record in the first place.

What governance should have looked like

A feature that records someone’s activity should start with the person’s choice to use it. Then the information it collects needs to be protected, and the system tested against realistic attacks, before it reaches the public. An EgressGate is designed to control what sensitive information a feature captures and where that information can go, so a record of someone’s activity is not simply left exposed, while an AuthorityGate is designed to make the person’s informed choice part of the decision before the capability is turned on. Together, they address two separate questions: should this information be collected at all, and if it is collected, how is it being protected?

The reference implementation of EgressGate and AuthorityGate is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed, free for any company to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Microsoft (Windows Recall) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →