
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
In 2023, Samsung engineers uploaded confidential company documents and source code to ChatGPT, resulting in a data leak. The data was stored on external servers beyond the company's control, raising significant security and GDPR compliance issues. This incident highlights the risks of unregulated employee use of generative AI in corporate environments.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves the use and misuse of AI systems (generative AI tools like ChatGPT) within corporate environments, leading directly to harms such as data leakage, loss of control over sensitive information, and regulatory compliance violations. These harms fall under violations of legal obligations and harm to property/business interests. The article reports actual incidents (e.g., Samsung's data leak) and ongoing risks, not just potential hazards. Therefore, this qualifies as an AI Incident because the AI system's use has directly led to harm.[AI generated]