Listen to this article
In March 2023, Samsung's semiconductor division let engineers use ChatGPT to speed up their work. Within about three weeks, that permission produced three separate incidents that became the textbook case for what "shadow AI" looks like in practice - not a hacker, not malware, just employees trying to do their jobs faster.
One engineer, debugging a facility measurement database program, pasted the faulty source code into ChatGPT to ask for a fix. Another pasted code used to identify defective manufacturing equipment, looking for an optimization. A third uploaded a meeting recording and asked ChatGPT to turn it into notes. None of them did anything a security team would call malicious. All three did something no governance process had evaluated: sent proprietary, competitively sensitive data to a third party with no contractual guarantee about how it would be stored, trained on, or resurfaced.
What Samsung actually found
Samsung found out after the fact - the way most organizations find out about shadow AI, which is to say, after the data has already left the building. The response was blunt: a companywide ban on ChatGPT and other public generative AI tools, and a fast-tracked internal alternative. Effective, but reactive. The policy that would have prevented this - "sensitive source code doesn't go to third-party AI tools" - was obvious in hindsight and completely absent in the moment three different engineers needed it.
Three engineers, three incidents, twenty days. The only unusual thing about Samsung's case is that someone eventually added it up and made it public.
Why the pattern hasn't gone away
This wasn't a sophisticated attack. It was three ordinary employees making a reasonable-seeming choice, three separate times, because nothing in their workflow stopped them or even asked the question. Two and a half years later, the scale says this hasn't improved, only grown: shadow AI detections are up sharply year over year, and separate research puts unsanctioned AI use at the overwhelming majority of organizations, with a large share of employees admitting they have shared sensitive work data with an AI tool without permission.
The AuthorityGate take
The lesson Samsung's incident still teaches isn't "ban the tool." It's "don't rely on employees to know where the line is if nothing tells them in the moment." A policy that lives in a handbook nobody reads doesn't stop a paste. A control that sits in the actual path of the action - before the data leaves, not after a quarterly review notices it did - does.
That's the difference between governance as a document and governance as an enforced boundary: policy checked at the moment of action, not discovered after the leak already happened.
Most companies' version of this story never gets counted, let alone published. Samsung's did, and the gap it exposed - no checkpoint between an employee's intent and a sensitive paste - is still open at most organizations running AI tools today.
Sources
Go deeper
Every agent action, validated before it takes effect
AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.