Laptop shows an AI assistant drafting email replies about voluntary assisted dying in an Australian parliament.
Microsoft Copilot was cited in Australia’s federal parliament on Friday after Liberal MP Andrew Hastie said the software suggested “congratulations!”, “great to hear from you” and “that is wonderful news!” as replies connected to a constituent’s decision to pursue voluntary assisted dying.

The episode is a stark illustration of why AI-generated email language cannot be treated as safe merely because it is fluent. But the public record so far also leaves a basic technical question unanswered: it is unclear which Microsoft feature produced the suggestions, what version was involved, and whether the output came from Copilot’s generative drafting tools or Outlook’s separate Suggested Replies system.

Those are not cosmetic distinctions. They determine whether this was an apparent failure by a large-language-model workflow operating on the message context, or a much narrower failure by the short-form reply suggestions that Outlook can surface automatically.

The Guardian first reported that Copilot suggested the phrases to Hastie after a terminally ill constituent wrote to tell him of plans to end his life through voluntary assisted dying. Hastie raised the incident before the Joint Select Committee on Artificial Intelligence while arguing that Australia should operate AI under Australian control rather than depend on US-based technology.

AAP reporting carried by the Seymour Telegraph corroborated that the three phrases were raised in the hearing, and reported that the constituent had emailed Hastie about the exchange in July. Its account, however, calls the product an “AI chatbot” rather than identifying Microsoft Copilot, and describes the suggestions as replies to the constituent. Neither published account includes a transcript, screenshot, prompt, tenant configuration, message redaction, or product-build information that would settle the workflow.

The critical missing detail is which Outlook feature was involved​

Microsoft markets several overlapping ways to generate or suggest email responses in Outlook. Microsoft 365 Copilot can work with email context to draft and revise replies, including through Copilot Chat and Outlook’s integrated writing tools. Those workflows can use more context, be refined with prompts, and produce a full draft for a user to review.

Outlook also has a separate feature called Suggested Replies. It traditionally presents three short, one-click responses when the service judges that a message can receive a brief answer. Microsoft describes it as a machine-learning feature and offers it across classic Outlook, new Outlook, Outlook on the web, Outlook.com and mobile clients.

The reported output — three brief, upbeat phrases — resembles the format of Outlook Suggested Replies. That is an inference from the wording and format, not confirmation that Suggested Replies produced the text. The Guardian’s identification of Copilot may still be correct: Microsoft has been moving Copilot deeper into Outlook’s drafting and reply experience, and current product documentation describes Copilot features that can analyze mailbox context and help generate responses.

For IT administrators, treating every AI-written phrase in Outlook as “Copilot” is a governance mistake. The controls, licensing, data paths, logs and feedback routes can differ between a traditional client feature and Microsoft 365 Copilot. An organization cannot investigate a bad output properly until it knows which service created it.

Polite language is not a substitute for understanding​

The response suggestions are disturbing because the apparent error is not grammatical. Each phrase is concise, civil and superficially appropriate in a positive announcement. The failure is that the tool seems to have interpreted a life-ending decision as an achievement or celebration.

That is a harder class of error for enterprise users to detect automatically. Content filters can often block profanity, threats, malware or the disclosure of sensitive data. They are less reliable at evaluating whether a cheerful phrase is grotesquely wrong in a particular human situation.

A drafting assistant is especially vulnerable when a message contains both positive linguistic cues — such as a decision having been made — and sensitive context involving death, illness, grief or crisis. If the system weights the former more strongly than the latter, it can produce output that is polished in form and unacceptable in meaning.

Microsoft’s own Outlook documentation repeatedly frames generated and suggested responses as material that users select, edit and send. That human checkpoint is important, but it does not erase the operational risk. In a busy office, inbox suggestions are designed to be consumed quickly. The whole point is to reduce the pause between reading an email and replying to it.

For public offices, healthcare providers, HR teams, legal practices and customer-support organizations, certain messages should therefore be treated as review-only work: no send action should be taken from a one-click or AI-generated response without a person reading the original message and the proposed reply in full.


Australia’s sovereignty argument does not follow from the email failure​

Hastie used the incident to support his broader call for Australian-run AI. Yet the failure described in the hearing is an argument for better contextual safeguards, monitoring and user controls; it does not by itself show that hosting or operating the same kind of system in Australia would make the response appropriate.

The same hearing underscored that tension. The Guardian reported that Australian Signals Directorate director-general Abigail Bradshaw told the committee that her agency relies heavily on US-hosted processing for advanced AI capabilities used in cyber defence. She warned that losing access during a conflict would dramatically reduce the agency’s capability against highly capable malicious actors.

Defence chief AI officer Chris Crozier, meanwhile, described an effort to establish Australian-based infrastructure, including interlinked data centres built with Google and disconnected from the US. The stated objective is understandable: retain local control of compute, applications, data and operational decision-making rather than depend entirely on an offshore provider.

Those goals can coexist. Sovereignty is about control, availability, jurisdiction and resilience. Safety is about a system’s behavior, its evaluation, its monitoring and the way people are allowed to use it. Localizing a model or its infrastructure may address strategic dependence; it does not automatically solve a tool’s tendency to misread emotionally complex messages.

What Microsoft 365 administrators should check now​

The immediate lesson for organizations using Outlook and Microsoft 365 Copilot is not to ban every drafting feature. It is to identify exactly where AI-assisted wording appears and to set a more restrictive practice for sensitive communications.

  • Administrators should inventory whether users have Outlook Suggested Replies enabled, whether Copilot Chat is available in Outlook, and which users have Microsoft 365 Copilot licenses and add-ons.
  • Teams handling health, bereavement, employee relations, legal disputes, safeguarding, suicidality, debt collection or emergency incidents should be told not to use one-click reply suggestions or automatically generated drafts as final language.
  • Organizations should make it easy for users to report a harmful suggestion with the complete context needed to reproduce it, including the Outlook client, platform, account type, feature used, approximate time, message classification and whether the text was generated or selected from a suggestion.
  • Security and compliance teams should determine whether their policies distinguish between ordinary Outlook smart features and Copilot-connected workflows. A generic “AI policy” is not enough if staff cannot tell which feature they are using.
  • Training should focus on the failure mode shown here: a tool can create a sentence that sounds professional while being fundamentally inappropriate for the recipient’s circumstances.

The most important fact in the Australian episode is that the phrases were suggestions, not a reply reportedly sent to the constituent. That human intervention prevented the incident from becoming direct harm. But a safety model that depends on every rushed user noticing every context failure is weak by design.

Microsoft now needs to clarify which product surface generated the suggestions described by Hastie and whether the company can reproduce the result. Until then, organizations should assume that any Outlook feature offering instant language can fail precisely where tone, empathy and judgment matter most.