Case Study · Data Leak Risk

Samsung employees pasted confidential source code into ChatGPT

What happened

In 2023, Samsung discovered that engineers had been entering confidential information into ChatGPT - including, according to Bloomberg, proprietary source code. The company had no visibility into how public AI tools were being used internally, or what happened to data once it reached a third-party server.

Samsung's response was blunt: it restricted employee use of generative AI and announced it would build internal AI tools instead. Bloomberg reported at least three separate incidents of sensitive data being shared this way.

The business problem

The company didn't have a clear picture of how employees were actually using public AI tools, or what information was being handed to them.

What could have helped

  • Audit actual AI usage before writing a policy for it
  • Maintain an approved-tools list instead of leaving the choice to individual employees
  • Set explicit rules for confidential and proprietary data
  • Give employees a safe, sanctioned alternative - not just a restriction

Where this points

AI Usage AuditAI PolicyAI TrainingSecure AI Implementation

Want to know where your organization stands?

Book a Consultation