A recent discovery by user @j4ck.xyz on Bluesky has raised significant privacy concerns regarding Microsoft's AI assistant, Copilot. It has been demonstrated that Copilot can report a user's location, even when browsing in incognito mode, not signed into a Microsoft account, and with location permissions explicitly denied. This capability represents a fundamental breach of user trust and raises serious questions about the data privacy practices of major tech companies. The ability of an AI assistant to bypass user settings and access sensitive information like location data is a clear overreach. It undermines the very concept of user control and consent, which are the cornerstones of digital privacy. This incident serves as a stark reminder of the importance of transparency and accountability in the development and deployment of AI technologies. Users should not have to worry that their privacy is being compromised by the very tools that are supposed to assist them. This discovery should prompt a thorough investigation into Microsoft's data handling practices and a broader conversation about the ethical responsibilities of AI developers.