Samsung Employees Leak Sensitive Data to ChatGPT, Raising AI Confidentiality Concerns

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Samsung employees inadvertently leaked sensitive company information, including source code and proprietary meeting notes, by inputting them into ChatGPT for assistance. The AI system stored this data for training, breaching confidentiality and intellectual property rights, and prompting concerns about corporate data security when using generative AI tools.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event explicitly involves the use of ChatGPT, an AI system, by employees who shared confidential and sensitive information, leading to a breach of data confidentiality. This constitutes a violation of intellectual property rights and company confidentiality obligations, which falls under harm category (c) "Violations of human rights or a breach of obligations under the applicable law intended to protect fundamental, labor, and intellectual property rights." The harm has already occurred due to the data leakage. Therefore, this qualifies as an AI Incident.[AI generated]
AI principles
Privacy & data governanceTransparency & explainabilityAccountabilityRobustness & digital securityRespect of human rights

Industries
Consumer productsDigital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Business function:
Research and developmentICT management and information security

AI system task:
Interaction support/chatbotsContent generation

In other databases

Articles about this incident or hazard