---
title: "Source code pasted into a public chatbot (reported)"
description: "Samsung engineers reportedly pasted source code and meeting notes into ChatGPT within weeks of being allowed to use it."
canonical: https://aigovernanceengineer.com/cases/chatbot-code-leak-reported
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-26
---

# Source code pasted into a public chatbot (reported)

> Samsung engineers reportedly pasted source code and meeting notes into ChatGPT within weeks of being allowed to use it.

- Year: 2023
- Jurisdiction: South Korea
- Sector: Semiconductors: engineering
- Evidence base: Reported
- Incident record: [AIID 768](https://incidentdatabase.ai/cite/768/)
- Harm: [Leakage of confidential data into external AI services](https://aigovernanceengineer.com/resources/harms#harm-confidential-data-leak)

## In short

TechRadar reported on 4 Apr 2023 that after Samsung allowed engineers in its semiconductor business to use ChatGPT, there were three recorded cases in just under a month of employees entering confidential data, including the source code of a new program and internal meeting notes. Samsung reportedly responded by limiting prompts to 1024 bytes. None of this comes from a primary company document. The harm is leakage of confidential data into an external AI service. The failure mode is permission without mediation: use was allowed before there was a gateway, a data-loss check on what left the network, or a reviewed position on how the provider retains inputs. Shadow-AI Discovery, a Runtime Guardrail at a gateway that scans prompts for source code, and a Vendor / Model Due-Diligence Gate on retention and training terms would have stopped the leak at the boundary. No AI-specific rule governs the leak itself: it is a confidentiality failure, and it touches EU AI Act Art. 4 on AI literacy.

## What happened

TechRadar reported on 4 Apr 2023 that after Samsung allowed engineers in its semiconductor business to use ChatGPT to help fix source code, there were three recorded cases in just under a month of employees entering confidential data, including the source code of a new program and internal meeting notes [1]. The AI Incident Database notes that the first report came from The Economist Korea on 30 Mar 2023 [2].

Samsung reportedly responded by limiting prompts to 1024 bytes and developing an in-house AI tool [1]. None of this comes from a primary company document.

## Failure mode

Permission without mediation. Use of an external AI service was allowed before there was a gateway, a data-loss check on what left the network, or a reviewed position on how the provider retains and uses inputs.

## Which control would have caught it

Shadow-AI discovery finds every AI service in use and puts it in the registry; routing that use through a gateway with a runtime guardrail that scans prompts for source code and confidentiality markings stops the leak at the boundary. A vendor due-diligence review of retention and training terms decides which services are allowed at all.

Patterns: [Shadow-AI Discovery](https://aigovernanceengineer.com/bok/patterns#pattern-shadow-ai-discovery) · [Runtime Guardrail](https://aigovernanceengineer.com/bok/patterns#pattern-runtime-guardrail) · [Vendor / Model Due-Diligence Gate](https://aigovernanceengineer.com/bok/patterns#pattern-vendor--model-due-diligence-gate)

## The evidence that would have existed

What an auditor could have read, and the stack layer that produces it.

- Layer 2 (Inventory & Transparency): Discovered-AI inventory reconciled with the model and agent registry
- Layer 4 (Runtime Controls & Observability): Gateway logs with a data-loss verdict for each prompt, and the blocks
- Layer 2 (Inventory & Transparency): Vendor record of retention and training terms, with the approved scope of use

## Obligations it touches today

As of 2026-09-24. Mappings are illustrative, not a claim of conformity.

- EU AI Act [Art. 4](https://aigovernanceengineer.com/obligations/aige-obl-euaia-art4): AI literacy: after the Digital Omnibus the article was reworded to support the development of AI literacy, applying from 27 Jul 2026 (as of 2026-09-24), as reported [3].
- General law Confidentiality: No AI-specific rule governs the leak itself; it is a confidentiality and trade-secret failure that an AI service made easy.

## How to read this case

Each case is an illustrative engineering analysis of public records, not a legal determination, not a finding of fact beyond what the cited sources state, and not a claim of conformity. Mappings to obligations are illustrative.

## Sources

[1] Samsung workers made a major error by using ChatGPT (three recorded leaks in under a month; 1024-byte prompt limit). TechRadar. 2023-04-04. https://www.techradar.com/news/samsung-workers-leaked-company-secrets-by-using-chatgpt (verified: reported)
[2] AI Incident Database, Incident 768: ChatGPT Reportedly Implicated in Samsung Data Leak of Source Code and Meeting Notes. Responsible AI Collaborative. 2026. https://incidentdatabase.ai/cite/768/ (verified: primary)
[3] AI literacy, the Digital Omnibus and Article 4 of the AI Act (Art. 4 reworded to "support the development of" AI literacy; applies from 27 Jul 2026). Law & Technology. 2026. https://lawandtechnology.eu/en/ai-literacy-digital-omnibus-article-4-ai-act/ (verified: secondary)
