Samsung Data Leak Caused by Employee Use of Generative AI Tools

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

In 2023, Samsung engineers uploaded confidential company documents and source code to ChatGPT, resulting in a data leak. The data was stored on external servers beyond the company's control, raising significant security and GDPR compliance issues. This incident highlights the risks of unregulated employee use of generative AI in corporate environments.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use and misuse of AI systems (generative AI tools like ChatGPT) within corporate environments, leading directly to harms such as data leakage, loss of control over sensitive information, and regulatory compliance violations. These harms fall under violations of legal obligations and harm to property/business interests. The article reports actual incidents (e.g., Samsung's data leak) and ongoing risks, not just potential hazards. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to harm.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital securityIT infrastructure and hosting

Affected stakeholders
Business

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Severity
AI incident

Business function:
Research and development

AI system task:
Content generation


Articles about this incident or hazard

Thumbnail Image

Láthatatlan kockázat a cégeknek az ellenőrizetlen mesterséges intelligencia

2026-06-27
Magyar Nemzet
Why's our monitor labelling this an incident or hazard?
The article highlights plausible future harms arising from the use and misuse of AI systems (chatbots and AI content generators) in organizations, including data breaches and regulatory violations. Although no specific harm event is described as having already occurred, the described risks clearly indicate credible potential for AI-related incidents. Therefore, this qualifies as an AI Hazard rather than an AI Incident or Complementary Information.
Thumbnail Image

Láthatatlan kockázat a cégeknek az árnyék-AI használata

2026-06-28
Kuruc.info h�rport�l
Why's our monitor labelling this an incident or hazard?
The event involves the use and misuse of AI systems (generative AI tools like ChatGPT) within corporate environments, leading directly to harms such as data leakage, loss of control over sensitive information, and regulatory compliance violations. These harms fall under violations of legal obligations and harm to property/business interests. The article reports actual incidents (e.g., Samsung's data leak) and ongoing risks, not just potential hazards. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to harm.
Thumbnail Image

Túl könnyen osztunk meg érzékeny adatokat a mesterséges intelligenciával

2026-06-27
alon.hu
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the use of AI systems (generative AI like ChatGPT) leading to actual data leaks and confidentiality breaches in companies such as Samsung and Amazon. These breaches constitute harm to property and violation of data protection laws, fulfilling the criteria for an AI Incident. The involvement of AI systems in these harms is direct, as the AI tools were used by employees and led to data being exposed externally. The article also discusses the broader risks and the need for governance but the core event is the realized harm from AI misuse.
Thumbnail Image

A magyar vállalatoknak gyakran láthatatlan kockázatot jelent az, ha az alkalmazottak árnyék-MI-t használnak

2026-06-27
raketa.hu
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions AI systems (generative AI like ChatGPT) being used by employees without authorization, leading to direct harms such as data leakage of confidential corporate information and GDPR compliance issues. The Samsung example confirms actual harm caused by AI misuse. The risks described are not hypothetical but have materialized, fulfilling the criteria for an AI Incident. The involvement of AI systems in causing harm through their use and misuse is clear and direct, and the harms include violation of data protection laws and business risks, which fall under harm categories (c) violations of rights and (d) harm to communities/businesses. Hence, the classification as AI Incident is appropriate.
Thumbnail Image

Az ESET közleménye: a shadow AI adatszivárgási és GDPR-kockázatot jelent

2026-06-28
Bumm.sk
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions the use of generative AI systems (ChatGPT, Gemini, Claude) by employees leading to actual data leakage incidents, such as Samsung's confidential documents being uploaded and leaked. This is a direct harm to property (confidential corporate data) and a violation of legal obligations (GDPR). The involvement of AI systems in causing these harms is clear and direct. The article also discusses the broader risks and the need for governance, but the presence of actual data breaches caused by AI use makes this an AI Incident rather than a hazard or complementary information.