What Happened
In April 2023, barely three weeks after Samsung’s semiconductor division allowed employees to use ChatGPT, engineers leaked confidential information to the platform on at least three documented occasions. In one instance, an engineer pasted proprietary source code for a semiconductor program into ChatGPT to check for bugs. In another, a worker input internal meeting notes for summarization. A third case involved uploading chip design data to optimize test sequences.
Because ChatGPT retains conversation data for model training by default (at the time), this effectively meant Samsung’s trade secrets were ingested into OpenAI’s training pipeline.
Timeline
Samsung’s semiconductor division permitted ChatGPT use in mid-March 2023. The leaks occurred within the first three weeks of permitted use. Internal reporting revealed the incidents in April. By May 2, 2023, Samsung issued a company-wide ban on all generative AI tools including ChatGPT, Google Bard, and Bing. The company simultaneously announced development of an internal AI tool for employee use.
Impact
The immediate impact was the loss of proprietary data with no clear mechanism for retrieval or deletion from OpenAI’s systems. Samsung’s semiconductor division handles some of the world’s most valuable intellectual property, making even partial exposure a significant competitive risk.
The broader impact was catalytic for the enterprise AI policy movement. Samsung’s ban made global headlines and prompted hundreds of corporations to develop formal policies governing employee use of generative AI tools. Companies including JP Morgan, Apple, Verizon, and Deutsche Bank implemented similar restrictions.
Response
Samsung’s response was immediate and comprehensive. The company banned all external generative AI tools, limited internal ChatGPT-like tool inputs to 1,024 bytes, warned employees that violations could result in termination, and began developing an in-house alternative. The company also reportedly consulted with OpenAI about the possibility of removing the leaked data from training sets, though the feasibility of this was unclear.
Lessons Learned
The Samsung incident demonstrated that the most significant AI privacy risk often comes not from the AI systems themselves but from human users inputting sensitive information without understanding the data retention implications. It revealed that simply permitting AI tool use without comprehensive training and guardrails creates immediate exposure.
The case also highlighted the tension between productivity benefits and data security. The engineers who used ChatGPT were trying to work more efficiently, not to cause harm. This well-intentioned but uninformed use pattern became the template that enterprise AI governance policies now specifically address.