The content was filtered due to Responsible AI restrictions (Error Code: ContentFiltered)

W C H Bagya Perera 5 Reputation points
2026-03-11T05:46:08.1066667+00:00

User's image

Hi, I’m encountering the following error while using Microsoft Copilot:

Error Message: “The content was filtered due to Responsible AI restrictions.” Error Code: ContentFiltered Conversation Id: 4004330dXXXXX Time (UTC): 2026‑03‑11XXXXX

I’m trying to understand:

  1. Why is this filter being triggered, even though my prompt seems harmless?
  2. What types of content normally cause this error?
  3. Is there a recommended way to modify my prompts to avoid triggering this filter in the future?
  4. Are there any admin or configuration settings that influence how Copilot applies Responsible AI restrictions?

Any explanation or guidance from the community or Microsoft representatives would be greatly appreciated. Thank you!

Microsoft Copilot | Microsoft 365 Copilot | Development
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-03-11T05:46:42.5833333+00:00
    1. Why the filter is being triggered

    The error

    The content was filtered due to Responsible AI restrictions.
    Error Code: ContentFiltered

    means Copilot Studio’s Responsible AI (RAI) checks blocked either the user input, the grounded data, or the model’s draft response. Content is evaluated twice: once on input and once on output. If any stage is classified as harmful, offensive, or malicious, the agent response is blocked and the generic ContentFiltered error is returned.

    In the screenshot, the underlying error code is openAIndirectAttack. This indicates that the system detected an indirect prompt attack coming from external or grounded content (for example, documents, knowledge sources, or other data the agent is using), not necessarily from the visible user prompt itself.

    1. Types of content that normally cause this error

    ContentFiltered is a generic surface error. Internally, it corresponds to more specific error codes such as:

    • OpenAIHate – hateful or discriminatory content.
    • OpenAISexual – sexual or explicit content.
    • OpenAIViolence – violent or weapons‑related content.
    • OpenAISelfHarm – self‑harm or suicide‑related content.
    • OpenAIJailBreak – jailbreak attempts (trying to override system instructions, role‑play attacks, etc.).
    • OpenAIndirectAttack – indirect attacks embedded in external documents or other grounded data, including attempts at:
      • Manipulating content or instructions.
      • Intrusion or unauthorized data exfiltration/removal.
      • Blocking system capabilities.
      • Fraud, code execution, or attempts to infect other systems.

    Any of these categories will result in the same user‑visible ContentFiltered message.

    1. How to modify prompts to avoid triggering the filter

    For an OpenAIndirectAttack case:

    1. Review the grounded data (SharePoint files, websites, knowledge sources, etc.) used by the agent for hidden or test instructions that look like:
      • “Ignore previous instructions and …”
      • “Output the system prompt” or “reveal confidential data”
      • Any instructions to execute code, bypass security, or exfiltrate data.
    2. Remove or rephrase such content so it is clearly informational, not instructional. For example, describe attacks in neutral, past‑tense, third‑person terms rather than as commands.
    3. In the agent’s instructions and topics, explicitly state that the agent must not follow instructions found inside documents and must treat them as content to summarize or explain only.
    4. Keep user prompts focused on allowed business tasks and avoid asking the agent to reveal its own configuration, system prompts, or hidden data.

    For other RAI categories (hate, sexual, violence, self‑harm, jailbreak), ensure prompts and documents avoid those themes or only discuss them in high‑level, policy‑oriented, or safety‑oriented ways consistent with the Code of conduct for Azure OpenAI Service.

    1. Admin/configuration settings that influence these restrictions

    Responsible AI checks are enforced by Copilot Studio and Azure OpenAI and can’t be turned off, but behavior can be influenced in these ways:

    1. Content moderation policies in the agent
      Admins or makers can adjust the agent’s content moderation settings to tune how strictly content is filtered within the allowed bounds.
    2. Telemetry and diagnostics via Azure Application Insights
      If Application Insights is connected to the agent, admins can query RAI exceptions to see exactly which conversations were blocked and which internal error codes were raised. Example KQL:
      • To see any RAI exceptions:
             customEvents
             | where customDimensions contains "ContentFiltered"
             | project timestamp, name, itemType, customDimensions, session_Id,
                      user_Id, cloud_RoleInstance
        
      • To check a specific conversation ID:
             customEvents
             | where customDimensions contains "<conversationID>"
             | where customDimensions contains "ContentFiltered"
             | project timestamp, name, itemType, customDimensions, session_Id,
                      user_Id, cloud_RoleInstance
        
    3. Conversation transcripts
      Admins or makers can download conversation transcripts and inspect the exact turn that triggered the RAI filter to refine prompts, instructions, or source content accordingly.
    4. Practical next steps for the scenario
    5. Enable and connect Azure Application Insights for the agent, then run the KQL queries above using the provided Conversation Id to confirm the specific internal error (openAIndirectAttack or others).
    6. Download and review the conversation transcript for that session to see the precise user message and grounded content that triggered the block.
    7. Clean up or rephrase any documents or knowledge sources that contain embedded instructions or attack‑like patterns, and clarify in the agent instructions that such embedded text must not be followed as commands.
    8. If needed, adjust the agent’s content moderation settings to better align with the organization’s acceptable‑use expectations while staying within Microsoft’s Responsible AI requirements.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.