What happened
Microsoft Defender introduced (announced in the July 30, 2026 'What's New' roundup) a public-preview capability that identifies and quarantines emails containing malicious AI/prompt-injection instructions before delivery, targeting attacks that hijack Copilot and other AI assistants that summarize/act on inbox content.
Why it matters
Moves prompt-injection defense upstream to pre-delivery blocking rather than post-hoc detection only, closing a gap as attackers increasingly target AI assistants via indirect injection in everyday business email.
Applicability
Organizations using Microsoft 365 Copilot / Defender for Office 365 should evaluate enabling this preview control for inbox-borne AI threats.