Microsoft Delays Controversial AI Recall Feature After Security Backlash
Microsoft postpones its Windows Recall feature to the Windows Insider Program following severe privacy and security criticism from experts. The company decides to gather feedback and improve safeguards before a broader public release.
Microsoft delays the release of its AI-powered Windows Recall feature to conduct additional security testing. Originally scheduled for a public preview on June 18 for new Copilot+ PCs, the tool now debuts exclusively within the Windows Insider Program in the coming weeks. The company plans to roll it out to all Copilot+ devices later after incorporating feedback from its tester community.
The Recall feature works by taking periodic screenshots of active windows and analyzing them with a local Azure AI model to enable natural language searches of past activity. However, privacy advocates and cybersecurity experts quickly label the tool a privacy nightmare, warning that bad actors easily abuse it to steal sensitive user data. Microsoft initially claims the feature is safe because it encrypts the stored data using Bitlocker.
Critics point out that Bitlocker automatically decrypts the drive upon user login, leaving the Recall database vulnerable to information-stealing malware and physical access. Cybersecurity expert Kevin Beaumont demonstrates how attackers easily modify existing malware to extract the SQLite databases and screenshots for offline analysis. This delay arrives on the same day as a critical ProPublica report regarding Microsoft's security practices and a congressional meeting involving Microsoft President Brad Smith.