Samsung: proprietary code pasted into a public chatbot
Within about 20 days of Samsung permitting ChatGPT use, engineers had pasted proprietary semiconductor source code and internal meeting notes into it on three occasions. Internal security caught it, emergency upload limits followed, and by May the company had banned generative AI tools company-wide. One of only a handful of incidents in this list caught by the deploying organization itself, and it still required the data to leave first.
What the verified record says.
- Organizations
- Samsung
- When
- March 2023
- Failure class
- Data leak data-leak
- Discovered by
- The deployer, through its own audit or accounts deployer-audit Caught by the organization running the AI
- Missing control
- Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group → Watch this kind of control catch a planted failure →
- What would have caught it
- An egress control between staff and public AI tools, so proprietary data cannot leave the network in a paste.
- Sources
-
- TechCrunch primary
- Verification
- Adjusted: the incident is real, and details were corrected against the primary source before publication. Three incidents in about twenty days after an internal permission dated March 11, 2023, detected internally and made public by The Economist Korea on March 30, with a company-wide ban on generative AI tools around May 1. A widely repeated claim that the leaks forfeited trade-secret protection appears in no primary source and is not repeated here. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.
This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built →