All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Contractors working on Microsoft Copilot are manually reviewing photos uploaded to the AI agent, according to internal documents obtained by 404 Media.[1] According to a reviewer, the faces aren't blurred.
The documents show that hundreds of contractors see some Copilot users' prompts, uploaded photos, and AI-generated edits, and then rate which edit came out better as part a manual review process.
According to Microsoft’s FAQ, "an opt-out of human review is not available."[2]
Here’s what the contractors see, why the privacy setting you may have already turned off doesn't cover it, and how to limit what a reviewer can see.
What Microsoft's fine print does and doesn't promise
How to limit what a Copilot reviewer can see
Bottom line
Inside the Copilot rating job
The documents 404 Media reviewed describe a rating job and includes instruction guides, real user prompts and images, and posts from an internal contractor message board.
A contractor sees three things: what a Copilot user typed, the photo they uploaded, and two versions of the edit Copilot produced. The contractor then picks the better edit using four criteria:
- whether it followed the request
- whether the rest of the image stayed intact
- whether it has visible glitches
- how good it looks overall
These workers aren't content moderators. According to 404 Media, their job is to judge quality, and their instructions tell them to trust their gut as a human viewer.
Those same workers see real people's faces. One contractor told 404 Media that "faces are always uncensored" in the images they review. Contractors also described seeing sexual editing requests involving real people, including requests to alter women's clothing and bodies. Many of those requests appeared to be made without the pictured person's consent.
At least one company supplying the workers is Prolific, a firm that recruits people for research and AI feedback work. It didn't respond to 404 Media's request for comment.
A Microsoft spokesperson told the outlet the company uses customer data as described in its terms of use, including to improve its products.
Microsoft isn't alone in employing human reviewers to rate model outputs. Two weeks earlier, 404 Media reported that OpenAI has hundreds of contractors reading real ChatGPT prompts to improve its models. If you've already wondered whether ChatGPT is safe to confide in, the same question now applies to Copilot.
The reporting doesn't show that every Copilot upload gets reviewed. It shows that some users' photos and prompts reached contractors, and there's no way for you to know whether yours did.
What Microsoft's fine print does and doesn't promise
Microsoft's Privacy FAQ for Copilot describes what it does when it prepares uploaded images for AI training. It says it de-identifies them, including by removing metadata and blurring faces. The contractor who spoke to 404 Media described the opposite.
Both accounts can be true. The blurring language sits in the FAQ's section on model training, so it may cover a different process than this rating work. Microsoft hasn't said which applies.
The FAQ is less ambiguous about human review. It says some Copilot conversations get human review "for product improvement and digital safety purposes." It also says human review is required when a Code of Conduct violation is suspected, and that users can't opt out of it. Microsoft hasn't said whether the photo-rating work falls under that policy.
This is where many people could get tripped up. Copilot does let you opt out of having your conversations used for AI model training. That's a separate setting. Nothing Microsoft has published says turning it off keeps human reviewers away from your uploads.
The new app makes the picture murkier. That FAQ applies to the older version of Copilot. Microsoft released an updated app on August 18, 2026. Its privacy pages say prompts, responses, and file contents aren't used to train foundation models, but they don't address human review either way. 404 Media didn't specify which version its documents covered.
You also don't have to use Copilot yourself to end up in front of a reviewer. Your face could be in a photo a friend, coworker, or stranger uploaded. Microsoft's FAQ asks users not to share images of others without their consent, but nothing technically stops them.
Most people don't know any of this happens. In a DuckDuckGo survey of 1,944 U.S. adults, 53% didn't know, or weren't sure, that most chatbots train on users' conversations by default.
People are clear about what they'd want instead. In an All About Cookies survey, 97% of Americans said there should be protections against platforms using their likeness or personal data to train AI. Another 45% said that kind of use should be opt-in only.
How to limit what a Copilot reviewer can see
You can't turn human review off. You can control what a reviewer would find.
- Upload as if someone might look. Before you share a photo, ask whether you'd be comfortable with a stranger seeing it. Right now, that's the only safeguard that fully works.
- Keep other people's faces out of it. Ask before uploading photos of friends, family, or coworkers, and be especially careful with photos of kids.
- Crop before you upload. If the edit doesn't involve anyone's face, like removing a trash can from a backyard shot, crop the face out or pick a different photo.
- Turn off model training. In the older Copilot app, you can stop your conversations from being used for training. It won't stop human review, but it limits how else your data gets used. Similar settings exist elsewhere, like Meta's AI training opt-out.
- Delete what you've already shared. Microsoft says uploaded files are stored for up to 18 months, and you can delete conversations anytime. Deleting won't undo a review that's already happened, but it shortens how long your photos sit on Microsoft's servers. Our guide to deleting your ChatGPT history walks through a similar cleanup.
Bottom line
Contractors rating Copilot photo edits see users' faces uncensored, according to one of them, and Microsoft's own FAQ says you can't opt out of human review. Turning off model training doesn't change that. Until Microsoft says otherwise, treat anything you upload to Copilot as something a stranger might see.