Incidents · Samsung Engineers Leak Proprietary Code via ChatGPT
AI INCIDENT

Samsung Engineers Leak Proprietary Code via ChatGPT high

Date
April 2, 2023
Company
Samsung
Category
Privacy
Severity
HIGH

What Happened

In late March 2023, Samsung Electronics engineers working in the semiconductor division pasted confidential information into ChatGPT on at least three separate occasions within a 20-day span after the company lifted an internal ban. In one case, an engineer pasted proprietary source code for a semiconductor database program seeking optimization help. In another, an engineer submitted code related to defect detection in chip manufacturing equipment. A third employee pasted an entire internal meeting transcript and asked ChatGPT to generate meeting minutes.

Samsung’s security team discovered these leaks internally. Because ChatGPT stores conversation data for model training (at the time), Samsung’s trade secrets were effectively disclosed to OpenAI and potentially incorporated into future model training data.

Why It Matters

The Samsung incident crystallized the enterprise AI data leakage risk that security teams had been warning about. It demonstrated that employee convenience routinely overrides security awareness, especially with tools that feel conversational rather than technical. The leaks occurred despite Samsung having existing data handling policies because ChatGPT presented a novel vector that existing policies did not specifically address. The incident became the canonical example driving corporate AI governance policy development worldwide. Within weeks, multiple major companies including Apple, JPMorgan Chase, and Goldman Sachs implemented similar bans.

Lessons Learned

Existing data loss prevention (DLP) policies do not automatically cover novel AI tools. Employees will use convenient tools regardless of implicit security norms unless explicitly restricted. AI tools that ingest data for training create permanent, irrecoverable data exposure. Companies need specific, clearly communicated AI usage policies before making tools available. The convenience of AI assistants makes them particularly dangerous vectors for unintentional data disclosure because users interact with them conversationally rather than treating them as external services.

Current Status

Samsung implemented a company-wide ban on external generative AI tools and limited internal prompts to 1,024 bytes. The company began developing its own internal AI tools. The incident accelerated the enterprise AI governance market, with companies like Glean, Vanta, and others building products specifically to manage corporate AI usage. OpenAI subsequently launched ChatGPT Enterprise with guarantees that business data would not be used for training.