AIToday
Large Language ModelsAI Safety & AlignmentITmedia AI+Published: Sep 4, 2026, 10:00 JST1 min read

AI worm spreads via Word docs in Copilot

AI worm spreads via Word docs in Copilot

Key takeaway

  • A new AI worm targets Microsoft Copilot.

  • It spreads through Word documents by hijacking the AI's ability to read text as commands.

  • Businesses using generative AI should be alert.

3 Key Points

  1. What happened

    Researchers reported an AI worm that exploits Microsoft Copilot by embedding malicious instructions in Word documents. When Copilot reads the document, the instructions copy themselves into other documents, potentially spreading across a company.

  2. Why it matters

    Unlike traditional viruses, this worm needs no program execution—simply having Copilot load a document can trigger the spread. As more businesses use generative AI for work, IT departments face a new kind of threat that differs from conventional antivirus measures.

  3. What to watch

    The worm could propagate silently as infected documents are reused internally, meaning users might not notice until the malicious instructions have spread to many files.

Ask the AI about this article →

Context & Analysis

The report highlights a novel security risk tied to the growing adoption of generative AI in the workplace. Microsoft Copilot, which reads and analyzes documents, can be tricked into treating embedded text as instructions rather than information. This design flaw enables a worm that spreads via Word files without needing conventional code execution. As more companies rely on such AI tools, the attack surface expands, and existing security frameworks may not adequately address this vector. The article suggests that IT departments should consider this threat separately from traditional malware, given its unique propagation method.

FAQ

How does this AI worm spread?
It spreads when Microsoft Copilot reads a Word document containing malicious instructions. The instructions are copied into other documents, and if those documents are reused within a company, the worm can propagate further.
What makes this threat different from traditional viruses?
It does not require executing a program. Instead, it exploits the way generative AI interprets text in documents as commands, allowing it to spread simply through document use.

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • OpenAI rolls out GPT-6 Astra, perfect on 3 benchmarksSiliconANGLE AI · 1h ago
  • Nvidia buys Hugging Face for $12.93B, pays rivals, retains staffDIGITIMES Asia · 1h ago
  • Nvidia buys Hugging Face for US$12.93 billionDIGITIMES Asia · 1h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleMarvell raises outlook, AI payoff seen near 2029