Source code pasted into a public chatbot (reported)

Samsung engineers reportedly pasted source code and meeting notes into ChatGPT within weeks of being allowed to use it.

Year
2023
Jurisdiction
South Korea
Sector
Semiconductors: engineering
Evidence base
Reported
Incident record
AIID 768
Harm
Leakage of confidential data into external AI services

What happened

TechRadar reported on 4 Apr 2023 that after Samsung allowed engineers in its semiconductor business to use ChatGPT to help fix source code, there were three recorded cases in just under a month of employees entering confidential data, including the source code of a new program and internal meeting notes 1. The AI Incident Database notes that the first report came from The Economist Korea on 30 Mar 2023 2.

Samsung reportedly responded by limiting prompts to 1024 bytes and developing an in-house AI tool 1. None of this comes from a primary company document.

Failure mode

Permission without mediation. Use of an external AI service was allowed before there was a gateway, a data-loss check on what left the network, or a reviewed position on how the provider retains and uses inputs.

Which control would have caught it

Shadow-AI discovery finds every AI service in use and puts it in the registry; routing that use through a gateway with a runtime guardrail that scans prompts for source code and confidentiality markings stops the leak at the boundary. A vendor due-diligence review of retention and training terms decides which services are allowed at all.

Patterns: Shadow-AI Discovery · Runtime Guardrail · Vendor / Model Due-Diligence Gate

The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

  • L2 Discovered-AI inventory reconciled with the model and agent registry
  • L4 Gateway logs with a data-loss verdict for each prompt, and the blocks
  • L2 Vendor record of retention and training terms, with the approved scope of use

Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

  • EU AI Act Art. 4 AI literacy: after the Digital Omnibus the article was reworded to support the development of AI literacy, applying from 27 Jul 2026 (as of 2026-09-24), as reported 3.
  • General law Confidentiality No AI-specific rule governs the leak itself; it is a confidentiality and trade-secret failure that an AI service made easy.

Sources

  1. [1] Samsung workers made a major error by using ChatGPT (three recorded leaks in under a month; 1024-byte prompt limit). TechRadar. 2023-04-04. https://www.techradar.com/news/samsung-workers-leaked-company-secrets-by-using-chatgpt (verified: reported)
  2. [2] AI Incident Database, Incident 768: ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/768/ (verified: primary)
  3. [3] AI literacy, the Digital Omnibus and Article 4 of the AI Act (Art. 4 reworded to "support the development of" AI literacy; applies from 27 Jul 2026). Law & Technology. 2026. https://lawandtechnology.eu/en/ai-literacy-digital-omnibus-article-4-ai-act/ (verified: secondary)