Severity

high

Exposure

4/5

Date of incident

April 1, 2023
Samsung ChatGPT Secret Paste

confirmed

Tier -

A

Secrets crossed into model provider — no tokenization at agent ingress boundary.
What Happened

Employees treated chat agent as scratchpad; proprietary logic entered model provider retention boundary — governance gap at human–agent ingress.

Sumarry

Samsung restricted ChatGPT after staff pasted sensitive source code and meeting notes into consumer chat agent.

Detect

DLP + mask at ingress

What Happened

Trust Vault before any model API call

Blekline //

Mask PII/secrets at ingress before model API

Without agent boundary //

Ban consumer ChatGPT policy — shadow AI bypasses via personal accounts

Financial services AI security use case

Looking to integrate AI company-wide?