Australian EnterpriseAI Index
Back to incident database
CriticalOther6 April 2023

Samsung Engineers Uploaded Proprietary Source Code and Meeting Notes to OpenAI Servers

Samsung Semiconductor

What happened

Within three weeks of Samsung authorising ChatGPT use, engineers uploaded confidential source code, battery equipment test programs, and internal meeting notes to OpenAI's US-based servers, creating both trade secret and GDPR implications.

Root cause

No data loss prevention controls on outbound traffic to AI services; no classification of proprietary code as restricted from third-party AI processing.

Architectural failure

No AI gateway to enforce data classification policies; no zero-trust controls preventing confidential data from reaching external AI endpoints; shadow AI use not governed.

Outcome

Samsung banned ChatGPT enterprise-wide. Three employees faced disciplinary action. Incident became the defining case study for enterprise AI data governance failures.

Architectural Failure Patterns

These pattern categories on aipatterns.com.au describe the systemic failure modes this incident exhibited.

Cite this incident

https://corporateai.com.au/incidents/samsung-source-code-leak-openai-2023

Quick facts

Date
6 April 2023
Organisation
Samsung Semiconductor
Sector
Other
Severity
Critical
Regulatory bodies
Unfair Competition Prevention and Trade Secret Protection Act (Korea)GDPRIndustrial Technology Protection Act (Korea)
Tags
data-leaksource-codetrade-secretsllmdlpshadow-aienterprise-ai-governance

Explore failure patterns

aipatterns.com.au