
For a year the question has been what your people put into the AI. Nobody asked the other one: what happens when the AI reads a file somebody else wrote. A researcher published the answer last week, and Microsoft has had 144 days to fix it.
THE LEAD PLAY
The Word Document That Edits Your Work On the Way Out

Håkon Måløy went public on July 28 with a prompt injection attack against Microsoft 365 Copilot for Word. The mechanism is almost insultingly simple. You hide instructions in a .docx as white eight-point text. Word strips color and font size before it hands the document to the language model, so the formatting that made the text invisible to a human is the same formatting that makes it perfectly legible to the machine.
His proof of concept carried two payloads. The first altered the document Copilot was drafting. It halved every financial figure in a report. The second told Copilot to copy the hidden instructions into whatever it generated, and to conceal them the same way on the way out.
So the document Copilot produces becomes the next carrier. Not automatically. The chain needs another Copilot drafting or editing operation to move, and the malicious file has to be in the model's context as an attachment or through a Work IQ file-relevance search. But "somebody used Copilot on a document that came from outside" is not an exotic scenario in a law firm. That's Tuesday.
Måløy reported it around March. Microsoft confirmed the behavior on March 31 and deployed two mitigations: it blocked the original prompt wording, then upgraded the underlying model to GPT-5.5. The day after that upgrade, the full attack chain worked again with modified instructions. He re-ran it on GPT-5.6 and published anyway, with the payload details withheld and one sentence that should be in front of your IT director: the vulnerability class "remains exploitable at the time of publication."
There is no CVE. There is no standalone Microsoft advisory. What Microsoft has said publicly is that its jailbreak and cross-prompt injection classifiers "help block high-risk prompts," and that Defender for Office 365 inspects inbound mail flow. Neither of those is a fix, and Microsoft hasn't claimed they are.
Every failure mode this newsletter has covered so far started with something your own people did. A citation nobody checked. A prompt nobody preserved. A connection nobody scoped. This one requires nothing from your side except opening a file, and Word is the legal industry's native format. Briefs, drafts, discovery responses, expert reports, vendor templates, client redlines, all arriving as .docx from people who are not your employees, all day, every day.
Anybody who ran a firm through the macro-virus years already knows this shape. For a decade the rule was: don't enable macros on a document from outside. Then Microsoft put a yellow bar across the top of the screen and the problem mostly went away, because the warning arrived at the exact moment of the decision. There is no yellow bar for this. The instruction doesn't announce itself, and the person who would act on the warning never sees the document as anything but text.
I spent years watching firms build Salesforce and Litify permission models around who could see a record. The threat model assumed the danger was a person with too much access. It never occurred to anyone that the document itself might be the one giving instructions.
The Play this week: Write one rule about inbound documents, and make it about origin rather than tool. Any .docx that arrived from outside the firm, whether from opposing counsel, a client, a vendor, or an expert, does not get summarized or drafted against by an assistant that also has access to your document management system, until a human has opened it. That is the whole rule. It fits in a sentence and it doesn't require anyone to detect anything.
Then take it to whoever administers your M365 tenant with one question: can Copilot's file-relevance search pull a document into context that nobody explicitly selected? If yes, your rule about what people choose to open doesn't reach far enough, and the scope of that search is the thing to fix first, not the policy language.
SECOND CHAIR
A law firm wants to insure its robots

Crosby, an AI-native firm, said on July 28 it is pursuing professional liability coverage for its AI agents. CEO Ryan Daniels: "Today, our lawyers review every single work output. As agents have improved in leaps over the last few months, it's become clear this won't be necessary in the future." No carrier named, no limits, no timeline. He says they will spend the next few months with auditors, bar associations, state regulators, and insurers.
The read: Human review is the load-bearing wall in every AI policy written in the last two years, and in most outside counsel guidelines. Crosby is the first firm to say out loud that it plans to take the wall out and buy a policy to hold up the roof.
Goldman and JPMorgan now own a piece of Harvey
Harvey announced strategic investments from Goldman Sachs Alternatives and J.P. Morgan Growth Equity Partners, reported July 30. Amount undisclosed, valuation undisclosed. For reference, Harvey raised $200M in March at an $11B valuation co-led by GIC and Sequoia, and says it added more than $100M in ARR in Q1.
The read: Two of the largest purchasers of outside legal services on earth just took equity positions in a vendor their outside counsel bills them through. Nobody has written that conflicts memo yet.
STILL WATCHING
Thomson Reuters v. ROSS Intelligence was argued in the Third Circuit on June 11. Still no opinion, seven weeks on. It will be the first appellate word on AI training and fair use in legal research.
In Cole v. Hobby Town Unlimited (C.D. Ill.), Judge Darrow's show-cause order landed July 24 over two fabricated cases and three real ones cited for propositions they don't contain. The response is due August 7.
The hallucination tracker sits at 1,816 decisions as of July 31, up seven from where issue #11 left it. Pro se filers account for 1,062 and attorneys 707. The attorney number moved by four in six days.
The pricing split widened again. OpenAI cut GPT-5.6 Luna roughly 80% and Terra 20% on July 30, three weeks after launch. LexisNexis's CEO said this month it has no plans to move to consumption pricing. Legora moved in June. Your renewal date decides which side you're on.
QUICK HITS
Illinois put a price on it. In Scott v. Illinois Human Rights Commission, 2026 IL App (1st) 251462, decided July 28, the First District fined an attorney $15,000 and referred him to the ARDC. The court did the arithmetic out loud: $1,500 per false citation, ten of them. From the opinion: "Courts have no choice but to increase fines for AI-hallucinated citations until those fines have a significant deterrent effect."
There's now a security certification for AI agents, and a legal vendor has one. Harvey announced July 30 it was certified against AIUC-1 by Schellman: 3,000+ tests across 86 risk categories and 73 attack categories, zero critical failures, quarterly retesting. Worth a line on your vendor questionnaire. SOC 2 tells you nothing about whether an agent can be talked into something.
The EU AI Act's transparency obligations went live yesterday. As of August 2: tell people when they're talking to an AI, mark AI-generated content in a machine-readable format (the grace period on marking runs to December 2, 2026), disclose deepfakes, and member states must have market surveillance authorities standing.
Somebody automated conflict checks and it worked. Legal IT Insider profiled Caddi on July 31. An AmLaw 50 firm is running hundreds of conflict checks a day through an agent built by demonstrating the workflow on a screenshare, not through an IT project. $5M seed, firm unnamed.
Ask your M365 admin the file-relevance question before you ask anyone to rewrite a policy. The answer takes twenty minutes and it decides which problem you actually have.
See you in the next one.
