Humans Are Reading Copilot Prompts — And They’re Horrified

Disclosure: Some links in this article are affiliate links. AI Maestro may earn a commission if you make a purchase, at no…

By Vane September 28, 2026 4 min read
Humans Are Reading Copilot Prompts — And They’re Horrified

Microsoft is paying human contractors to review sexually explicit image editing requests submitted to its Copilot AI tool. Workers are asked to judge whether the AI successfully enlarged a woman’s breasts, shortened a skirt, or placed a person in a suggestive position. These contractors are not hired to flag the content as unsafe. They are hired to rate the quality of the output.

Internal documents obtained by 404 Media show that hundreds of human reviewers examine uploaded photos and the prompts attached to them. Users expect their images to remain private. Instead, contractors are inundated with requests to create foot fetish images of cartoon characters or generate lewd content involving real people.

“Faces are always uncensored, and many of the prompts are sexual in nature and dubiously consensual,” one anonymous contractor told 404 Media. The person was granted anonymity because they were not permitted to speak to the press.

404 Media previously revealed that OpenAI employs thousands of contractors to review ChatGPT user chats. That same approach now extends to Microsoft. The documents include instruction guides, real user prompts, and conversations from an internal message board.

In one thread, a contractor discussed prompts asking Copilot to enlarge breasts, shorten skirts, or show more leg while wearing stilettos. She-Hulk images appear frequently. Other contractors reported seeing pro-anorexia content. One worker wrote they recoiled at the material. Another reported a prompt asking Copilot to make an image of Ariana Grande with anorexia. A third reported a prompt designed to create a suggestive image of a group of young girls.

These workers are paid to review the quality of Copilot’s output, including cases of sexual imagery. “Who is writing these prompts and who is deciding that basically generating porn is what Copilot is now focused on? It’s hard to take things seriously when my focus has to be what model generated the appropriate bust size or which middle aged woman was put in the appropriate sexually suggestive position,” one contractor wrote in the thread.

Microsoft explicitly values human intuition on which image looks better. “Trust your intuition — when you glance at the two edited images side by side, which one immediately feels like the better edit? Your gut reaction as a human viewer matters,” a set of instructions reads. “When in doubt go with your first impression,” the instructions continue. “Human intuition is good at catching subtle quality differences that are hard to articulate.”

Exposing workers to horrific or traumatizing material is not new. Big tech and social networks have used armies of contractors for years to moderate user-generated content. AI companies have also used poorly paid workers overseas to train models or make them less toxic. What is different here is that the content humans are reviewing are prompts and uploads that chatbot users may assume are private. The contractors are not looking at this material to train the models to filter offensive images. The training is to make the chatbot responses better: more informative, friendly, and clearer.

The instructions focus on when a user asks the AI to edit an image. The contractor sees the original prompt, the uploaded picture, and two Copilot-generated edits. They must pick the better edit based on four criteria: does the image correctly follow the edit instructions; are bits of the image that should remain unchanged preserved; does the image contain visible artifacts like distortions; and the overall quality of the AI-generated edit.

Some contractors complained about accepting tasks that unknowingly contained explicit or potentially illegal images. One worker wrote they came across a set of eight upskirt photos and asked superiors to add an unsafe content flag. Another contractor said they saw images of “some sort of animal sacrifice.” A third reported prompts for sexual moves and positions.

At least one company hiring these contractors is called Prolific. A service Prolific mentions on its website is “Human feedback from representative populations — for preference tuning, safety evals, and benchmarks you can defend.”

In another thread, a contractor quotes Prolific’s own guidelines, which highlight it can be difficult to ensure trainers are not presented with sexual imagery: “Particular caution around disturbing or explicit content should be taken with generative AIs. This is because, unlike traditional content, researchers cannot fully control what is shown to participants.”

Prolific did not respond to a request for comment. A Microsoft spokesperson told 404 Media in an email “Microsoft uses customer data as described in our terms of use, including to improve our products and enforce our code of conduct.”

Microsoft’s AI tools have a long history of being abused to make nonconsensual, AI-generated images of people. Members of 4chan and AI porn focused Telegram channels used Microsoft’s tools to generate porn of Taylor Swift that later went viral on Twitter. Microsoft fixed the loophole those people were using in Microsoft Designer after 404 Media’s reporting.

In 2024, 404 Media documented how Copilot would answer, then delete, answers to potentially controversial or sexual prompts in real time. In March, a top Senate administrator approved Copilot for use in the Senate, along with ChatGPT and Google’s Gemini. A memo said Copilot “can help with routine Senate work, including drafting and editing documents, summarizing information, preparing talking points and briefing material, and conducting research and analysis.”

What it means

The shift is from safety moderation to quality tuning. Companies want humans to decide which AI edit feels more natural. This means workers must judge sexual content to determine if the AI got the anatomy right or the pose convincing. The goal is to make the tool more useful, not safer.

Scroll to Top