Noesa
← The Casebook

South Korea · 2023

They pasted the chip code in to get it debugged. That was the disclosure.

Three Samsung engineers used ChatGPT the way anyone would. Within weeks the company banned it outright.

Published 15 August 2026

What happened

In April 2023, three Samsung employees put sensitive internal material into ChatGPT — in one case source code, submitted for the entirely ordinary purpose of getting help with it. The story was first reported by Bloomberg [1][2].

Nobody was attacking anything. Each was doing what the tool is for: pasting in a problem and asking for help with it. The disclosure was the use [1][2].

On 1 May 2023 Samsung restricted generative AI tools — ChatGPT, Bing and Bard among them — on company-owned computers, tablets and phones, and on personal devices connected to internal networks. The memo said the restriction would hold "until it builds security measures to create a secure environment for safely using generative AI" [1].

The company's stated reasoning was not that the models were untrustworthy. It was that data sent to an outside service is hard to "retrieve and delete", and could be "disclosed to other users" [1].

Samsung also said it was building its own internal tools for software development and translation — the actual resolution, and the one most organisations eventually reach [1].

Where the same use helps

Pasting code into a model to have it explained, reviewed or debugged is genuinely one of the most useful things the technology does, and the engineers here were not wrong about that. Samsung's own response says as much: it did not decide the tool was worthless, it decided the tool needed somewhere safe to run, and set about building one. The lesson is not "do not use it" — it is that where the text goes is a separate question from whether the answer is good, and the two get conflated because both feel like using a website [1].

Where it burned

A chat box does not look like a transmission. It looks like a document — a private scratchpad that happens to answer back. There is no send button, no recipient, no attachment warning, none of the friction that has trained everyone to think twice about email. So material that would never have been emailed outside the company gets typed into a text field, because the interface gives no signal that it is leaving [1][2].

The tell

Before you paste, ask the question you would ask about an email: who is the recipient, and would I send this to them? If you would not email it to a vendor, do not paste it into one.

The useful shift is to stop thinking of a prompt as writing and start thinking of it as sending. Everything in the box goes to a company you have a contract with — or, more often, one you do not. That reframing settles most cases in a second without needing a policy document: customer records, unreleased figures, someone else's confidential information, code you are not free to share. And where the answer is genuinely worth the disclosure, the fix is a tool with the right contract behind it, not a braver guess.

Share this case

The image has the link printed on it, so it still leads back here.

The check is a habit, and habits are trained. Data safety with AI is about precisely this line — what is safe to put in, what is not, and how to get the help without making the disclosure.

Sources

Every source below was opened and read. Last verified 15 August 2026.

  1. [1] Samsung bans use of generative AI tools like ChatGPT after April internal data leakKate Park, TechCrunch, 2 May 2023
  2. [2] Samsung Bans ChatGPT Among Employees After Sensitive Code LeakSiladitya Ray, Forbes, 2 May 2023