4.3 AI for Defence · Module 4 · Shadow AI & Case Studies

The Samsung Leak & Detecting Shadow AI

A second cautionary tale, and the graduated tactics for finding shadow AI.

DetectionExercise~15 min

The big idea

Within 20 days of allowing ChatGPT internally in 2023, Samsung had three separate leaks — engineers pasting proprietary source code and an internal meeting transcript. It restricted use and capped prompt sizes. The lesson for contractors is the same as NSW RA: people will paste sensitive material to get help. Detecting it runs from network-layer logging (who's visiting AI sites) up to endpoint DLP and SaaS-discovery tools (what's being sent).

Key insight: You can't manage what you can't see. Detection is graduated: network logs show who and how often; endpoint DLP and SaaS-discovery tools can show what is being sent — and block it.

What you'll see

The Samsung incidents and the three layers of shadow-AI detection.

The lesson and the tactics

From cautionary tale to detection. Tap to expand.

Key points to remember

Samsung: three source-code/transcript leaks within 20 days of allowing ChatGPT.
Detection is graduated — network → endpoint DLP → SaaS discovery.
Network logs show who; DLP shows (and can block) what.
Exercise: a 5-question team self-audit on which tools, devices and accounts are in use.