The receipts / Privilege separation

Samsung: proprietary code pasted into a public chatbot

March 2023 Caught internally, one of the few

Within about 20 days of Samsung permitting ChatGPT use, engineers had pasted proprietary semiconductor source code and internal meeting notes into it on three occasions. Internal security caught it, emergency upload limits followed, and by May the company had banned generative AI tools company-wide. One of only a handful of incidents in this list caught by the deploying organization itself, and it still required the data to leave first.

Primary source: TechCrunch

The record

What the verified record says.

Organizations
Samsung
When
March 2023
Failure class
Data leak data-leak
Discovered by
The deployer, through its own audit or accounts deployer-audit Caught by the organization running the AI
Missing control
Privilege separation. Permissions enforced by infrastructure, not by instructions. Full definition and the other incidents in this group Watch this kind of control catch a planted failure
What would have caught it
An egress control between staff and public AI tools, so proprietary data cannot leave the network in a paste.
Sources
Verification
Adjusted: the incident is real, and details were corrected against the primary source before publication. Three incidents in about twenty days after an internal permission dated March 11, 2023, detected internally and made public by The Economist Korea on March 30, with a company-wide ban on generative AI tools around May 1. A widely repeated claim that the leaks forfeited trade-secret protection appears in no primary source and is not repeated here. Verified against the primary source on August 12, 2026. Published on this site August 13, 2026, updated September 1, 2026.

This record is one of 26 in The receipts, each checked against a primary source before it is published. How the list is built