Blog Shadow AI May 2, 2023 4 min read

The Copy-Paste That Ended Samsung's ChatGPT Experiment

Three Samsung engineers pasted proprietary chip code into ChatGPT in three separate incidents within the same month. It is still the textbook shadow-AI case, and the numbers say the pattern has only gotten bigger.

By the AuthorityGate Architect Team

In March 2023, Samsung's semiconductor division let engineers use ChatGPT to speed up their work. Within about three weeks, that permission produced three separate incidents that became the textbook case for what "shadow AI" looks like in practice - not a hacker, not malware, just employees trying to do their jobs faster.

One engineer, debugging a facility measurement database program, pasted the faulty source code into ChatGPT to ask for a fix. Another pasted code used to identify defective manufacturing equipment, looking for an optimization. A third uploaded a meeting recording and asked ChatGPT to turn it into notes. None of them did anything a security team would call malicious. All three did something no governance process had evaluated: sent proprietary, competitively sensitive data to a third party with no contractual guarantee about how it would be stored, trained on, or resurfaced.

Three glowing incident folders on a review table, each dated within the same month, connected by a warm-gold ribbon to a shared point on a facility network diagram
Three separate incidents, twenty days apart, before anyone connected them.
3separate incidents in a single month
20 daysbetween the first paste and the companywide ban
4xyear-over-year rise in shadow AI detections, Verizon 2026 DBIR
98%of organizations report unsanctioned AI use, per industry research

What Samsung actually found

Samsung found out after the fact - the way most organizations find out about shadow AI, which is to say, after the data has already left the building. The response was blunt: a companywide ban on ChatGPT and other public generative AI tools, and a fast-tracked internal alternative. Effective, but reactive. The policy that would have prevented this - "sensitive source code doesn't go to third-party AI tools" - was obvious in hindsight and completely absent in the moment three different engineers needed it.

Three engineers, three incidents, twenty days. The only unusual thing about Samsung's case is that someone eventually added it up and made it public.

Why the pattern hasn't gone away

This wasn't a sophisticated attack. It was three ordinary employees making a reasonable-seeming choice, three separate times, because nothing in their workflow stopped them or even asked the question. Two and a half years later, the scale says this hasn't improved, only grown: shadow AI detections are up sharply year over year, and separate research puts unsanctioned AI use at the overwhelming majority of organizations, with a large share of employees admitting they have shared sensitive work data with an AI tool without permission.

The AuthorityGate take

The lesson Samsung's incident still teaches isn't "ban the tool." It's "don't rely on employees to know where the line is if nothing tells them in the moment." A policy that lives in a handbook nobody reads doesn't stop a paste. A control that sits in the actual path of the action - before the data leaves, not after a quarterly review notices it did - does.

That's the difference between governance as a document and governance as an enforced boundary: policy checked at the moment of action, not discovered after the leak already happened.

Most companies' version of this story never gets counted, let alone published. Samsung's did, and the gap it exposed - no checkpoint between an employee's intent and a sensitive paste - is still open at most organizations running AI tools today.

Share this post: LinkedIn

Go deeper

Every agent action, validated before it takes effect

AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.