Engineers pasted proprietary semiconductor source code and meeting notes into a public chatbot, prompting a company-wide ban.
In April 2023, Samsung Electronics confirmed three separate incidents in which engineers in its semiconductor division pasted confidential source code, defect logs and an internal meeting recording into ChatGPT to seek debugging help and meeting minutes. The data left the company perimeter and entered the training pipeline of a third-party provider. Samsung subsequently banned generative AI on company devices and stood up an internal alternative. The incident is the most-cited example of shadow-AI data exfiltration in enterprise risk literature.
What caused this
Samsung engineers pasted confidential semiconductor source code and internal meeting notes into ChatGPT to debug and summarise. Because the consumer ChatGPT terms allowed prompts to be used for model improvement, sensitive IP left the corporate perimeter and could not be recalled.
- No enterprise policy on generative AI use at the time of the incident.
- No data loss prevention (DLP) rules covering AI endpoints.
- Employees lacked an approved, safe alternative for the productivity gains they were chasing.
- Classification of source code as confidential was not enforced at egress.
How this could have been avoided
Shadow AI is solved by giving people a sanctioned path, not just blocking the unsanctioned one.
- Acceptable Use Policy for generative AI, naming approved tools, prohibited data classes and consequences (ISO 42001 Annex A.9.2).
- Enterprise-tier AI with contractual no-training guarantees and data residency, offered to all staff who need it.
- DLP and CASB rules blocking source code, customer data and secrets from being posted to consumer AI domains.
- Training with concrete examples of what may and may not be shared.
- Incident playbook for suspected prompt leaks, including legal-hold and key rotation.
Need AI assurance for your organisation?
Talk to AramGRC about ISO 42001 readiness, governance reviews, and incident response playbooks tailored to your sector.
Contact AramGRC for AI assurance →