When employees put company information into a generative AI tool, they may be sending it to servers outside their organization’s control. Samsung’s decision to restrict staff use of tools such as ChatGPT and Google Bard followed the discovery that an engineer had uploaded sensitive internal source code to ChatGPT. The episode underscores a practical question for businesses: what information should employees be allowed to share with AI services?
How an AI experiment exposed company information
Samsung’s internal memo, obtained by Bloomberg, said the restriction followed a leak of sensitive source code. Earlier reports described one employee asking ChatGPT to check database code for errors and another submitting a recorded meeting to generate minutes. The company warned that employees caught using the tools could be fired.
Samsung was not alone in setting limits. JPMorgan restricted employee use over compliance concerns, while Amazon reportedly told staff not to share code with the chatbot. Verizon and Accenture also took similar steps. The examples show how quickly an everyday productivity tool can raise questions about confidentiality and oversight inside a workplace.
These restrictions do not mean companies see no value in generative AI. Samsung’s memo also pledged to develop its own tools for translation and document summaries. The tension is between the potential to save time and the need to control where sensitive information goes.
What happens to information entered into a chatbot
Generative AI can make sophisticated capabilities accessible to people who do not have technical backgrounds. But the service still depends on computing infrastructure operated by someone else. Like a cloud storage service, ChatGPT stores information shared with it on OpenAI’s servers.
That information can include prompts and conversations, as well as account details, approximate location, IP address, payment details and device information. OpenAI says it uses data to train and improve the model so it can better understand and respond to natural language queries. OpenAI also says conversations are encrypted and data is held on secure servers that are regularly monitored for vulnerabilities.
Those protections do not remove the possibility of a breach. OpenAI acknowledged that ChatGPT had experienced a significant data breach in March, exposing personal and partial payment data belonging to ChatGPT Plus subscribers. The incident illustrates that storing information with a service provider carries risks even when safeguards are in place.
Why workplace rules matter
Employees may turn to AI tools to rewrite documents, research a question or speed up routine tasks. A prompt can seem harmless in the moment, yet include material that an organization would not want shared beyond its own systems. For example, Cyberhaven described an executive entering points from a company strategy document and asking ChatGPT to format them as presentation slides. The company warned that information submitted this way could inform a later response about the organization’s priorities.
Cyberhaven’s analysis found that about 10% of surveyed employees had used ChatGPT at work, and 7.5% had pasted company data into it since its launch. It found that 4% had entered sensitive information at least once, including source code and client data. These findings point to a gap between the availability of AI tools and employees’ understanding of the data risks.
Clear boundaries can help close that gap. Organizations need to tell staff which information they may share and which information must stay out of public AI services. Source code and confidential data are examples of material that should be addressed explicitly in those rules.
Pair boundaries with employee training
A policy alone may not be enough if people do not understand how a tool handles their input. Cybersecurity training can explain the risks in terms employees can apply to everyday tasks: before entering text, consider whether the organization would be comfortable with that information becoming accessible outside its control.
The source article compares generative AI risks with phishing, another area where a convincing message can lead someone to make a costly mistake. Its broader point is that companies should prepare and train employees rather than assume every worker already knows how to judge the risks. When organizations adopt AI without proper guidance, they may expose company or client information without realizing it.
Generative AI may help businesses automate tasks, conduct research and streamline workflows. Capturing those benefits requires making data handling part of the decision to use a tool. Employees need practical instructions about what they can enter, and companies need boundaries that match the sensitivity of the information they hold.