The Samsung Leak & Detecting Shadow AI
A second cautionary tale, and the graduated tactics for finding shadow AI.
The big idea
Within 20 days of allowing ChatGPT internally in 2023, Samsung had three separate leaks — engineers pasting proprietary source code and an internal meeting transcript. It restricted use and capped prompt sizes. The lesson for contractors is the same as NSW RA: people will paste sensitive material to get help. Detecting it runs from network-layer logging (who's visiting AI sites) up to endpoint DLP and SaaS-discovery tools (what's being sent).
Key insight: You can't manage what you can't see. Detection is graduated: network logs show who and how often; endpoint DLP and SaaS-discovery tools can show what is being sent — and block it.
What you'll see
The Samsung incidents and the three layers of shadow-AI detection.
The lesson and the tactics
From cautionary tale to detection. Tap to expand.