Microsoft's Windows Recall Allegedly Stores Passwords and Social Security Numbers in Preview Mode

August 1, 2025

Microsoft's Windows Recall, an AI-powered screenshot tool for Copilot+ PCs, was allegedly found capturing sensitive information such as passwords, Social Security numbers, and bank details despite a built-in 'filter sensitive information' feature. Independent testing reportedly uncovered multiple instances of the filter's failure.

Microsoft classified Recall as a preview feature and stated improvements were in progress. This incident highlights the importance of trustworthy AI, safe and secure AI practices, and guardrails for AI. For those interested in shaping responsible AI governance and improving harm prevention measures, consider joining Project Cerebellum through JOIN US.

This incident also underscores the need for effective monitoring, measurement, and management of AI systems using HISPI Project Cerebellum TAIM.

Matched TAIM controls

Suggested mapping from embedding similarity (not a formal assessment). Browse all TAIM controls

Alleged deployer
microsoft
Alleged developer
microsoft
Alleged harmed parties
windows-recall-users, windows-11-users, microsoft-users

Source

Data from the AI Incident Database (AIID). Cite this incident: https://incidentdatabase.ai/cite/1176

Data source

Incident data is from the AI Incident Database (AIID).

When citing the database as a whole, please use:

McGregor, S. (2021) Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. In Proceedings of the Thirty-Third Annual Conference on Innovative Applications of Artificial Intelligence (IAAI-21). Virtual Conference.

Pre-print on arXiv · Database snapshots & citation guide

We use weekly snapshots of the AIID for stable reference. For the official suggested citation of a specific incident, use the “Cite this incident” link on each incident page.