Microsoft spent a year redesigning Recall's security after researchers extracted everything in 2 seconds. The new version? Researchers extracted everything again. The database also has secret tracking fields Microsoft never told anyone about. They built a vault, got robbed, rebuilt it, got robbed again. Microsoft made a huge deal about requiring your face or fingerprint for Recall. Turns out that's only for setup. After that, a 4-digit PIN unlocks your entire visual history. Like putting a retinal scanner on your front door but leaving the back door open with a Post-it saying "1234.".
What they claim: Microsoft requires Windows Hello biometrics (face/fingerprint) to set up Recall. Implies biometric auth gates access to Recall data.
What we found: Beaumont found biometrics only required for INITIAL SETUP. After that, a PIN works. "Will create false sense of security — almost every news article says biometrics are now needed." Feature cannot be fully uninstalled from Copilot+ PCs.
What they claim: Privacy statement positions data sharing as user choice. Setup presents privacy toggles. "You are in control."
What we found: Windows 11 eliminated local account during setup — MUST create Microsoft account before reaching privacy settings. Advertising ID generated during mandatory account creation. Workarounds progressively closed. NPU, Recall, Copilot present regardless of settings — disable but cannot uninstall.
What they claim: NPU (45 TOPS) marketed as enabling "amazing new AI experiences" and "creativity." "Most AI-ready Windows PC."
What we found: NPU runs ~80% utilisation during Recall — screenshots, OCR, semantic indexing continuously. Not a general-purpose chip; surveillance-architecture chip. Microsoft required 45 TOPS minimum because the surveillance workload demands it. NPU driver has CVE-2024-53034 (critical memory corruption).
What they claim: Recall docs: "snapshots aren't sent to Microsoft" and not used to train AI. M365 Copilot: "prompts and responses NOT used to train Microsoft AI models."
What we found: Gaming Copilot defaults to training AI on user text and voice conversations. Microsoft confirmed this. Set to train by DEFAULT — opposite of stated Recall policy. Two AI screenshot products, same company, same year, opposite data policies.
What they claim: Microsoft markets preinstalled apps as "Windows experience." Users can "manage installed apps through Settings."
What we found: Copilot cannot be normally removed. Users report OneDrive/Copilot reappear after uninstall — Office auto-repair and Windows Update reinstall them. EU users can uninstall Edge (DMA) confirming Microsoft knows how but chooses not to elsewhere. Each app feeds separate data pipeline.
What they claim: Microsoft: "Recall processes content locally and securely stores it on your device." "Snapshots aren't sent to Microsoft" and data is "always encrypted" with keys in VBS Enclave.
What we found: March 2026: TotalRecall Reloaded bypassed VBS Enclave via AIXHost.exe injection. Extracted screenshots, OCR text, CSV metadata in plaintext. Beaumont confirmed: "yep, you can just read the database as a user process." Also found undisclosed tracking fields. SECOND time researchers fully extracted the Recall database.
What they claim: Microsoft: "committed to making privacy a core value" with GDPR compliance and EU Data Boundary commitments.
What we found: France CNIL (2016): excessive telemetry. Netherlands DPA (2017/2018): law breach, sensitive data inference. Canada OPC (2018): insufficient consent. EDPS (2024): EU Commission's own M365 use violates law. Only actual fine: EUR 60M for Bing cookie banners. Zero euros fined for Windows OS telemetry.
What they claim: Microsoft: "Privacy is a fundamental right." "Built for secure, productive work."
What we found: 15 documented incidents 2015-2025, escalating each release. Wi-Fi Sense, GWX dark pattern, Cortana 45-page privacy docs, CNIL notice, EFF confirmation, Netherlands breach, Office 365 covert telemetry, mandatory accounts, Recall plaintext DB, TotalRecall, Gaming Copilot silent install, VBS bypass. Every release: more collection, more toggles that do less.
What they claim: Privacy dashboard offers six categories of controls. Diagnostic data can be set to "Required" minimum. "Choose how much data to share."
What we found: Even with ALL visible settings disabled, MAPS (Microsoft Active Protection Service) sends metadata about every file you create. Used to be called "Microsoft SpyNet" with a visible off switch. In Windows 11, switch removed. EFF confirmed (2016) data sent with all settings disabled; CompanionLink confirmed same in March 2026.
What they claim: After Recall backlash, Microsoft made it opt-in. Nadella and Davuluri stressed they "listened to feedback" and AI features respect user choice.
What we found: Oct 2025: Gaming Copilot silently installed via Xbox Game Bar, enabled by default, no consent. Sends screenshots to Azure cloud — not local. Beaumont confirmed network traffic to undocumented endpoints even when widget CLOSED. Previously uninstalled Copilot reinstalled. Removing requires admin PowerShell.