Two office workers review family photos on screens, with an eye icon suggesting digital image analysis.
If you have ever asked Microsoft Copilot to tidy up a family photo or put a hat on your dog, you probably assumed only software saw it. A new investigation says that isn't always true. According to 404 Media, human contractors are reviewing Copilot users' prompts and uploaded images, according to internal documents obtained by 404 Media. What those reviewers say they have been looking at is disturbing in its own right.

The story matters to anyone who uses consumer Copilot on Windows, the web or mobile. It also matters to IT admins who have to explain to staff why the free Copilot and the one tied to a work account are not the same product.

What 404 Media found​

The reporting rests on internal documents of Microsoft Copilot contractors, including instruction guides, user prompts and pictures, and the contractors' internal message boards.

The workflow it describes is a standard AI quality-rating setup. The instructions seen by 404 Media focus on what contractors do when a Copilot user asks the AI to edit an image. The contractor is shown the user's original prompt, the uploaded picture, and then two Copilot-generated edits.

The reviewer then picks the better edit. According to 404 Media's account, they judge it on four criteria:

  • Instruction-following: did the edit do what the user asked?
  • Preservation: did everything that should stay the same actually stay the same? The example given is a prompt to "add a cup on the table," where nothing except the cup should change.
  • Artifacts: are there visible flaws such as distortions or unnatural textures?
  • Overall quality: how good does the edit look?

Those four points are laid out in the contractor instructions. The guidance also asks reviewers to go on instinct. "Trust your intuition... which one immediately feels like the better edit?"

The key detail is that the uploaded photo is part of what gets graded. As Superpowerdaily summarized it, the upload is part of what the reviewer assesses, not merely an input supplied to Copilot.

Section summary: Reviewers reportedly see your original photo, your prompt and two AI edits, then choose the better edit largely on gut feel.

What the reviewers say they saw​

These workers were hired to grade quality, not to moderate content. The AV Club put it plainly: these contractors were not hired to moderate these images. That makes what showed up in their queues more troubling, because they had to look closely at it to do the job.

404 Media describes a workforce that is constantly bombarded with lewd or sexually explicit photo editing requests and images that users have uploaded, including upskirt photos or putting women into sexual positions. According to AI Weekly's summary, reviewers also described foot fetish imagery involving cartoon characters, and pro-anorexia content sitting in the queue they were asked to rate. Gadget Review's account adds imagery involving young girls and animal-sacrifice images, both drawn from contractor discussions that 404 Media reviewed.

Some quotes from the contractors:

  • One told 404 Media: "Faces are always uncensored, and many of the prompts are sexual in nature and dubiously consensual,"
  • Another reported: "I just came across an image set that consisted of eight upskirt photos."
  • A third wanted to know: "Who is writing these prompts and who is deciding that basically generating porn is what Copilot is now focused on?"

Grading a sexualized edit means judging whether it was sexualized enough. According to 404 Media, contractors are then asked to review whether the generated image successfully fulfilled the prompt — such as, did the image generator make the woman's AI-enlarged breasts big enough.

The workers raised welfare concerns too. One contractor wrote about receiving a set of upskirt photos and asked for an unsafe-content flag, so reviewers would know what a task contained before accepting it.

On scale, 404 Media's reporting says a workforce of at least hundreds of human reviewers are sometimes looking at that prompt and whatever images they upload. The word "sometimes" is important. Nothing in the reporting shows that every Copilot upload reaches a person. It also doesn't say what share of image-edit requests are sampled for review, or which app versions and account types were involved.

Section summary: The workers say the queue included upskirt shots, sexualized edits of real women, fetish content and pro-anorexia requests, with faces uncensored. The reporting describes a sampled review process, not review of every upload.

Microsoft's response, and who hired the workers​

Microsoft's official answer was brief. Microsoft said it uses customer data under its terms, including for product improvement and conduct enforcement. But it did not clarify whether users can keep uploaded images out of these ratings.

The contractor platform named in the reporting has said nothing publicly. 404 Media identifies Prolific as at least one company hiring contractors for the work; Prolific did not respond to its request for comment.

Prolific's own guidance for researchers, dated December 11, 2025, anticipates this kind of risk:

  • Studies involving disturbing or explicit content should carry a content warning.
  • Researchers should use Prolific's Harmful Content Prescreener, so only participants who say they are comfortable with such material are recruited.
  • For generative-AI studies, researchers can't fully control what participants see, and they remain responsible for any explicit content shown.

Nothing public shows whether these Copilot rating tasks ran under those study rules, or whether the safeguards were applied. That is an open question, not evidence of wrongdoing. Nothing reported so far shows that Microsoft or Prolific broke a specific law.

What Microsoft's own documents say about human review​

This is where the story goes beyond the headline. Microsoft does disclose human review, but the disclosure is in support pages, not at the moment you upload a photo.

Human review is acknowledged, and you can't opt out. Microsoft's Privacy FAQ for Copilot says some conversations get both automated and human review for product improvement and digital safety. It also says conversations may be reviewed when a Code of Conduct violation is suspected. It is explicit that an opt-out of human review is not available. Elsewhere, the FAQ says trained AI experts may review conversations to build, evaluate and improve model accuracy and safety.

Training opt-out and human review are separate controls. The same FAQ says signed-in consumer users can stop their future conversations from being used to train Microsoft's generative AI models. That setting does not turn off human review. Many people who flipped that switch may reasonably think they have "opted out."

The face-blurring claim sits next to the contractor's account. For training data, the FAQ says Microsoft takes steps to de-identify uploaded images and files, including removing metadata and blurring faces. The contractor's statement that "faces are always uncensored" doesn't necessarily contradict that. The FAQ describes the training pipeline, and edit-quality rating may be a different process. But neither document tells users which protections apply at the rating stage. That gap is exactly what Microsoft hasn't answered.

Retention depends on the feature. Two Microsoft documents give different figures:

Microsoft documentWhat it saysScope
Transparency Note for Copilot (for individuals)Images deleted within 30 days after the conversation endsImages uploaded to Copilot Vision
Privacy FAQ for CopilotUploaded files stored securely for no longer than 18 monthsFile and image uploads generally; the FAQ says it covers the older Copilot app

So there is no single "deleted in 30 days" rule for every upload. The FAQ also notes that a new Copilot app arrived on August 18, 2026, with its own privacy guidance. Readers on the new app should check which document applies to them.

Automated screening exists, but its limits are unclear. The Transparency Note says uploaded chat images are scanned for child sexual exploitation and abuse imagery, and apparent cases are reported to the National Center for Missing and Exploited Children as US law requires. It also says prompts pass through input classifiers meant to filter harmful content. The same note admits that mitigations may occasionally fail. It doesn't say what happens to legal but objectionable content, such as upskirt photos or sexualized edits of adults, before it reaches a rating queue.

Microsoft's consumer terms prohibit adult content, nonconsensual image edits and deepfakes. The reporting suggests some users submit that content anyway, and that some of it ends up in front of reviewers.

Consumer versus work accounts: the part admins need​

The FAQ excludes several groups from consumer model training:

  • people signed in with organizational Entra ID accounts
  • Microsoft 365 Copilot users
  • Copilot conversations inside Microsoft 365 consumer apps such as Word and Outlook
  • users under 18
  • people who aren't signed in
  • users who have opted out

Commercial customers are covered by Microsoft's Enterprise Data Protection commitments instead.

That is a training exclusion, not a promise that no human ever looks at anything. Still, the practical advice for IT is clear. If employees are editing images with personal-account Copilot, they are working under consumer terms. Pointing them to the work-account experience is the policy fix, not a workaround.

What you should actually do​

  1. Treat consumer AI uploads as potentially visible to a person. Microsoft's own FAQ says not to share confidential or sensitive personal data you wouldn't want used as its privacy materials describe.
  2. Think about the other people in your photos. Photos of children, partners or colleagues carry their faces into a system you don't fully control, and they never agreed to it.
  3. Turn off model training if you want, but know its limits. It reduces one kind of reuse. It doesn't stop human review.
  4. Delete old conversations. The FAQ says you can delete past Copilot conversations from your history at any time.
  5. Use work accounts for work. Admins should make sure staff aren't doing business image editing in personal Copilot.

The bigger picture​

None of this is unique to Microsoft. As the AV Club pointed out, since the beginning of the AI boom, companies like OpenAI have used human contractors in Venezuela and Kenya to evaluate output, correct it, and refine prompts for a couple of bucks per task. Human feedback is how these models improve.

The problem is disclosure. "Some conversations are subject to human review" in a support FAQ is technically accurate. It is not the same as telling someone, right when they upload a photo of a friend, that a stranger might grade the result. It also shows how poorly protected the workers are: people paid to judge image quality ended up asking for warnings before seeing upskirt photos.

The biggest questions remain unanswered:

  • How many reviewers can see uploads?
  • What share of image edits get sampled?
  • What filtering happens before an image reaches a rating queue?
  • Will users ever see a clear notice at the point of upload?

Until Microsoft answers them, the safest assumption is that your uploaded photo might be seen by a person.

 

References

  1. Humans Are Reading Copilot Prompts – What They Have Seen Will Stun You - Gadget Review Gadget Review 2026-09-28T17:45:41+00:00
  2. Superpowerdaily superpowerdaily.com
  3. Copilot photo uploads can reach human reviewers, and faces reportedly aren’t blurred - Digital Trends Digital Trends 2026-09-29T12:17:09+00:00