New Microsoft Recall feature is a 'security nightmare' and could make Copilot+ PCs a top target for cyber criminals
The Microsoft Recall feature on new Copilot+ PCs could create security nightmares for enterprise users, according to cyber experts


Microsoft has stirred up privacy concerns in the tech industry after announcing its latest AI feature that will continually record users’ devices, including sensitive information.
On Monday 20 May, Microsoft announced its latest AI-enabled feature ‘Recall’ for Copilot+ PCs at its Build conference in Seattle.
The feature, being exclusively rolled out to Copilot+ PCs, will capture encrypted screenshots locally on the device to enable users to search back through their activities.
One aspect of the new feature that has been a particular cause for concern in the tech community is that sensitive information including passwords, financial information, or private keys will not be hidden in the snapshots.
All of the data captured by Recall will be stored on the device’s local hard disk and encrypted, and Microsoft has said Recall screenshots will not be shared between users or with itself for advertising purposes.
In an interview with Business Insider, Satya Nadella, CEO at Microsoft, explained because the Recall feature takes place locally on the edge, user information will remain safe and only available on that device.
But this does not dispel worries around the information cyber criminals may be able to access if they are able to compromise Copilot+ PCs.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The announcement has drawn widespread criticism by those in the security and data protection community, including Kevin Beaumont, director of emerging threats at the Arcadia Group.
In a blog post discussing the announcement, Beaumont described the move as essentially integrating an infostealer into the base Windows operating system (OS).
“Microsoft are inventing a new security nightmare using Copilot, which will undoubtedly lead to increased fraud for consumers and other woes for businesses.”
Concerns over Recall have already reached fever pitch, with the UK’s Information Commissioner’s Office (ICO) considering a probe into the feature.
A spokesperson for the data watchdog told ITPro it had serious concerns about the new feature and confirmed it has contacted the tech giant over potential data protection risks.
“We expect organizations to be transparent with users about how their data is being used and only process personal data to the extent that it is necessary to achieve a specific purpose,” the spokesperson said.
“Industry must consider data protection from the outset and rigorously assess and mitigate risks to peoples' rights and freedoms before bringing products to market.
“We are making enquiries with Microsoft to understand the safeguards in place to protect user privacy.”
New Microsoft Recall feature is a cyber criminal's dream
Recall will use local AI models and onboard Copilot+ devices to process all of the captured data and make it searchable, even for images.
The search functionality will be semantic rather than keyword-based, which means it will return results based on the meaning of the query, rather than simply matching search terms with similar words that have appeared on your screen previously.
Microsoft said Recall will not be turned on by default, and users can limit which snapshots the feature will collect by specifying the applications or websites in which their activity should not be recorded.
It added content with digital rights management (DRM) will not be stored, nor will any activity conducted in Microsoft Edge’s InPrivate browsing sessions.
RELATED WHITEPAPER
Jake Moore, global cyber security advisor at enterprise security firm ESET, told ITPro the feature will give hackers new opportunities to target Windows users.
“Enabling a feature which has the ability to capture screen data not only offers even more data to the company behind the software but also opens up another avenue for criminals to attack,” Moore said.
“Whilst this feature is not on by default, users should be mindful of allowing any content to be analyzed by AI algorithms for a better experience.
“Although it may produce better results, there is a balance that must be kept regarding functionality versus privacy and so users must remain aware of the potential risks should any sensitive data ever become compromised.”
Ultimately, Moore argued that the feature appears to create more problems than it solves, offering hackers a golden ticket for stealing sensitive information.
“Creating and storing more private data seems unnecessary when cyber criminals continually look for any given vulnerability to exploit.”

Solomon Klappholz is a former staff writer for ITPro and ChannelPro. He has experience writing about the technologies that facilitate industrial manufacturing, which led to him developing a particular interest in cybersecurity, IT regulation, industrial infrastructure applications, and machine learning.
-
Should AI PCs be part of your next hardware refresh?
AI PCs are fast becoming a business staple and a surefire way to future-proof your business
By Bobby Hellard Published
-
Westcon-Comstor and Vectra AI launch brace of new channel initiatives
News Westcon-Comstor and Vectra AI have announced the launch of two new channel growth initiatives focused on the managed security service provider (MSSP) space and AWS Marketplace.
By Daniel Todd Published
-
Microsoft justifies 365 price increases after MP concerns
News Microsoft’s UK VP of external affairs has defended the tech giant's price increases
By George Fitzmaurice Published
-
Microsoft is ending support for the Remote Desktop app – here are three alternatives you can try instead
News Microsoft has announced plans to end support for its Remote Desktop application in just over two months.
By George Fitzmaurice Published
-
GitHub just launched a new free tier for its Copilot coding assistant – but only for a select group of developers
News Limited access to GitHub Copilot in VS Code is now available free of charge
By Nicole Kobie Published
-
Recall arrives for Intel and AMD devices after months of controversy
News Microsoft's Recall feature is now available in preview for customers using AMD and Intel devices.
By Nicole Kobie Published
-
Everything you need to know about the Microsoft outage
News After a day of chaos, the worst of the Microsoft outage appears to have passed, but some problems still remain
By Emma Woollacott Published
-
With one year to go until Windows 10 end of life, here’s what businesses should do to prepare
News IT teams need to migrate soon or risk a plethora of security and sustainability issues
By George Fitzmaurice Published
-
Microsoft is doubling down on Widows Recall, adding new security and privacy features – will this help woo hesitant enterprise users?
News The controversial AI-powered snapshotting tool can be uninstalled, Microsoft says
By Nicole Kobie Published
-
Microsoft pulls Windows update after botched patch causes blue screens, reboot loops
News Microsoft has pulled a Windows 11 update ahead of next week's Patch Tuesday after encountering a raft of issues
By Nicole Kobie Published