Incident Report

The One-Way Door: How Samsung Walked Its Source Code Through a Boundary That Only Opens Once

Within roughly three weeks of letting its semiconductor engineers use ChatGPT, Samsung suffered three separate leaks of crown-jewel intellectual property into an external system that learns from what it is given. Source code, defect-detection logic, and a recorded internal meeting. The most technically capable company on earth then did the one thing that revealed how bad the situation was. It did not try to recover the data. It could not. It banned the tool. This is the forensic anatomy of a governance failure whose defining feature is that, by the time anyone noticed, every remedy except prohibition had already expired.

Summary

Within roughly three weeks of letting its semiconductor engineers use ChatGPT, Samsung suffered three separate leaks of crown-jewel intellectual property into an external system that learns from what it is given. Source code, defect-detection logic, and a recorded internal meeting. The most technically capable company on earth then did the one thing that revealed how bad the situation was. It did not try to recover the data. It could not. It banned the tool. This is the forensic anatomy of a governance failure whose defining feature is that, by the time anyone noticed, every remedy except prohibition had already expired.

Why this incident, and why this chapter

Provenance opens its fourth chapter with Samsung, and for good reason. Every other kind of data loss assumes the data is still a thing, an object that sits somewhere and can, in principle, be found and destroyed. Stolen files can be traced and seized. Leaked documents can be enjoined. Breached databases can be rebuilt and their copies hunted down. Samsung’s engineers understood, faster than most legal departments have, that this assumption had just quietly died. The code had not gone somewhere. It had gone into something. It was no longer an object in a place. It was, potentially, a faint adjustment inside a vast web of numbers, present the way an ingredient is present in a finished cake.

That is the Influence dimension, the axis along which data keeps having consequences after its deletion. Read alongside the pattern language of Decision-Centric AI Governance, Samsung is the cleanest case where the six dimensions meet the twelve patterns. A preventable, multi-layer control failure whose downstream property, irreversibility, is exactly what makes the missing governance patterns matter. Analyse it properly and you are reading Chapter Four and a procurement memo at the same time.


Section 1. Executive Brief (The Verdict)

The incident. On 11 March 2023 Samsung’s semiconductor division lifted its internal restriction and allowed staff to use ChatGPT for work. Within about three weeks, three separate disclosures of confidential material occurred. An engineer pasted proprietary semiconductor source code into the chatbot to fix a bug. Another pasted code to optimise it. A third fed in a recording of an internal meeting to generate minutes. Each act was natural, well-intentioned, and exactly what the tool exists for. Samsung responded by restricting upload size and then, in early May 2023, banning generative-AI tools on company devices and internal networks, while committing to build an internal alternative.

What failed, in plain language. Not “employees were careless.” Irreversible authority was handed to individuals to move crown-jewel IP across an organizational boundary into a learning system, with no envelope around that action, no record made at the moment it happened, and no way to drop the privilege the instant it was misused. The control surface a board imagines, a policy and some training, never touched the actual failure point, which was a text box on an external endpoint.

Material impact. No fine, no breach notification, no public dollar figure, and that absence is itself the lesson. The harm is not a countable loss event. It is an unquantifiable, unrecoverable exposure. Process IP from one of the most closely guarded research programmes in global industry may have entered an external model’s training surface, with no mechanism to confirm, contain, or reverse it. The secondary cost was strategic and very real. The company withdrew a major productivity tool from its entire workforce, the blunt remedy you reach for only when no finer one exists.

Core governance failure. Delegated disclosure across an irreversible boundary. In the book’s language, the organisation walked its most valuable data through the one-way door and found, on the far side, that influence cannot be recalled. Prohibition in advance was the only tool left because everything after the paste was already too late.


Section 2. Layered Failure Timeline (Swiss-Cheese Analysis)

The point of this section is that the incident was preventable at three independent layers. Any one of them, designed correctly, stops it.

Design layer, structural. There was no boundary object standing between the corporate network and a consumer-grade external model. In the pattern language this is a missing Decision Envelope. The act of sending classified material into a learning system had no declared conditions it was allowed to run under, so nothing distinguished a reversible copy from an irreversible disclosure. The structural assumption baked in was that a chatbot is a tool like web search, a reversible lookup, when it is in fact a learning system with the manners of a teacher rather than a filing cabinet.

Test layer, operational. “An engineer pastes proprietary code to get a fix” is not an exotic edge case. It is the single most predictable use of the tool by the exact population given access. In the vocabulary of Out of Bounds, this is a normative boundary that any competent whitebox red team would have named on day one, then watched someone cross. It was never modelled. A monitored pilot, a narrow group with full egress logging and inspection in observe mode, would have surfaced the behaviour in days. The real world needed only about twenty. The misuse path was foreseeable, fast, and untested.

Oversight layer, control. Three incidents occurred before the tool was pulled. That number is the indictment of the control layer. Nothing detected the first egress of classified IP and narrowed the channel. No real-time signal drained the privilege. No automatic step-down to a safe state fired. The organisation learned about the failures after the fact and in aggregate, which is the mode the companion books call amnesia by architecture applied to oversight. The system kept no live account of what was leaving it.

Three layers, three slices, every hole aligned. The Swiss cheese did exactly what unmanaged Swiss cheese does.


Section 3. Technical Autopsy (The Missing Patterns)

Name the patterns that were absent and the failure stops looking like bad luck. Four were missing, and only these four need to be named.

A missing Decision Envelope (Pattern One). No envelope declared the conditions under which corporate IP could leave the trusted environment. Without an envelope, the most capable tool in the building was also the least supervised path out of it. Every downstream control treated a paste into a learning model the same as a paste into an internal scratchpad, because the one property that mattered, whether the action was reversible, was never written down as a condition.

A missing Tool-Mediation Gate (Agentic Pattern Five). The book’s agentic set puts one chokepoint between the actor and the world, a single place where authorizing the action and recording it are the same act. Samsung had no such gate on the channel to the external model. The clipboard reached the endpoint directly. So there was no point at which the egress could be blocked, and no point at which it was even witnessed. The hands were free and left no fingerprints.

A missing Intended-Use Preservation (Pattern Three). The approved purpose of the semiconductor network never included feeding a public model, but that purpose lived in a policy document rather than in the architecture. The book’s rule is that intended use must be enforced, not merely documented. Here it was documented at best and enforced nowhere.

No path to Governance Rollback or Authority Recalibration (Patterns Eleven and Agentic Four). Once the first leak happened, nothing returned the channel to a pre-declared safe state, and nothing drained the standing permission to reach the endpoint. The enforceable version of this, continuous authorization that suspends and recalibrates access in seconds on a risk signal, is the subject of the author’s pending provisional filings on continuous decision authorization. Samsung had the opposite, a switch left on.

What the system did instead. With no envelope, no gate, and no rollback, the default behaviour was to trust the user at the point of irreversible action. The path of least resistance, paste into the best available tool, carried the data out. The provider’s own default finished the job. Consumer-grade usage at the time carried the prospect that inputs could be retained and used to improve models. The vacuum was filled by the two least governable forces in any system, human convenience and a vendor default.

Correct governance logic, in concept. Make reversibility a first-class property of the architecture and put an envelope around any action that crosses into a learning system. Default-deny external model endpoints from IP-bearing networks. Route any egress of classified material through a single mediation gate that inspects, blocks, or records. And satisfy the underlying need rather than only forbidding it. Stand up a sanctioned internal or enterprise endpoint with contractual no-training terms, so the engineer who needs a bug fixed has a door that is not one-way. Governance that only says no invites the shadow workarounds that produced this incident in the first place.


Section 4. Assumptions and Signals That Failed

Decision-Centric AI Governance keeps every load-bearing belief in an Assumption Registry, with an owner, so that a belief cannot fail silently. Samsung had no such registry. Three unnamed assumptions were doing all the structural work.

“ChatGPT is essentially smarter search or autocomplete.” Misapplied across contexts. A reversible-tool mental model was transplanted onto an irreversible-disclosure tool. This category mistake is the single most consequential error in the incident.

“Consumer terms are adequate for enterprise use.” Outdated and implicit. The data-handling posture of a free consumer product was silently accepted as the control environment for crown-jewel IP.

“Employees will recognise and withhold sensitive material.” Implicit and unfounded. Discretion at the point of egress was treated as a control. It was the vulnerability.

Signals that existed and did not force a stop. By early 2023 it was widely reported, and stated in the provider’s own terms, that ChatGPT inputs could be used to improve models, and several major institutions, large banks among them, had already restricted or banned the tool. The signal was public and loud. It failed to halt anything because no one owned the question “evaluate irreversible-disclosure risk before enabling this.” In the book’s terms, there was no Assumption Evaluation and Trigger, no rule that says a stressed assumption compels action. Enablement was treated as an IT convenience decision, so the risk signal had no addressee. This is the silent layer where the incident actually began, not in the paste, but in the unexamined decision weeks earlier that the tool was safe to switch on.


Section 5. Governance and Liability Exposure

Why “human in the loop” did not help. There were humans in the loop, the engineers themselves, and that is exactly why it failed. Human-in-Control draws the line the book insists on. Oversight is an architecture, not a person. Human discretion at the moment of irreversible egress is not oversight. It is the attack surface. A person is a control only when they sit above the irreversible action, with the authority and the information to stop it, not when they are the one performing it under deadline. The book’s pattern here is Override Accountability, which presumes a reviewer positioned to override. Samsung had no reviewer in that position at all.

What evidence would be demanded after the incident. Which records left, at what time, through which account. What the provider retained. Whether any of it entered a training run. And proof of deletion if requested. Samsung could obtain satisfying answers to almost none of these, and this is Chapter Four’s hard centre. You cannot subpoena a tilt, you cannot redline a weighting, there is no forensic team that can search a model’s mind. The evidence the situation demands is, by the nature of the dimension, largely unproducible. The enforceable answer, an evidence record written at the boundary at the moment of egress, together with lineage-aware deletion and unlearning that can actually show what was removed, is the subject of the author’s pending provisional filings. Samsung had none of that machinery, so it had nothing to produce.

Where the burden of proof realistically shifts. Onto the discloser, with no way to discharge it. Samsung cannot prove the code was not absorbed. The provider cannot credibly prove erasure from every downstream artefact, because the honest state of the art, which the machine-unlearning literature documents plainly, is that suppression is achievable while guaranteed removal short of full retraining is not. A burden you cannot satisfy is, in effect, strict exposure.

How this reads. Not a defensible one-off error. The pattern, broad enablement with no envelope, no gate, and no halt on the first signal, reads as a governance omission shading toward systemic. The absence of any architecture for AI egress, discovered only because the harm announced itself three times in three weeks.


Section 6. Counterfactual Governance (The Preventable Path)

Credibility here comes from restraint. The fix is not “ban all AI.” It is two patterns, precisely placed.

Envelope plus mediation gate, at the design layer. Put a Decision Envelope around any egress into a learning system, default-deny external endpoints from IP-bearing networks, and route the genuine productivity need through a single Tool-Mediation Gate to a sanctioned internal model with contractual no-training terms. Intervene here and the incident does not happen. The engineer still gets the bug fixed, through a door that closes behind the data instead of swallowing it.

Recalibration on the first signal, at the oversight layer. Inspection on the AI channel that detects classified material leaving and drains access on the first event. This is Authority Recalibration and Governance Rollback working together, the enforceable form of which sits in the continuous-authorization filings. Intervene here and you do not prevent leak one, but you convert three irreversible disclosures into a single contained, learnable incident.

The first pattern is the better investment because, in the Influence dimension, reduce-harm is weak consolation. The only fully effective control is the one applied before the paste. That is the whole argument of the chapter, stated as an architecture decision rather than a philosophical one, and it is why Samsung, lacking the door, was left with the wall.


Section 7. Stakeholder Takeaways

Architect, what should never have been delegated. An external learning endpoint should never have been reachable from a network handling crown-jewel IP without an envelope and a mediation gate. Irreversibility has to be a first-class design property. Actions that cannot be undone need controls that do not depend on the user choosing well under pressure.

Red Team, what scenario should have been tested. “Engineer pastes proprietary source code into the assistant.” It is the most obvious boundary crossing for the most obvious user population, and it should have been run in a monitored pilot before general rollout, not discovered in production three times.

Governance, what evidence was missing. There was no egress record to answer “what left, when, and through whom,” and no provider attestation to answer “what was retained and whether it trained anything.” Build the evidence trail at the boundary, at write time, because in this dimension evidence reconstructed after the dispute begins is exactly the evidence that does not exist.

Executive, what risk should have been challenged earlier. The trade itself. Enabling a consumer-grade learning tool on IP-bearing systems to capture a reversible productivity gain while accepting an irreversible downside. Stated that plainly in a risk-acceptance meeting, the trade fails on sight. The job was to make someone state it plainly before the tool was switched on, not after.


The thread back to Provenance

Samsung is the chapter’s thesis enacted in three weeks. Confronted with a new species of loss, the most capable company on the planet found it owned exactly one tool, the word no, applied in advance, because everything after the paste was already too late. The remedy of last resort became the remedy of only resort, for the same reason regulators reaching for algorithmic disgorgement, destroy the model and not just the data, concede the dimension’s core truth. Influence cannot be located, cannot be extracted, cannot be unlearned with assurance. A governance programme that learns Samsung’s lesson stops treating AI egress as an IT setting and starts treating it as a boundary with a calendar of no return. It puts an envelope on the action, a gate on the channel, and a recalibration trigger on the first signal, and it keeps the evidence at the boundary where the evidence can still be made. The door only opens one way. Govern it before, or not at all.


A note on the pattern vocabulary

The named patterns in this brief, the Decision Envelope, the Tool-Mediation Gate, Intended-Use Preservation, Governance Rollback, Authority Recalibration, the Assumption Registry, and Override Accountability, are drawn from the author’s own books. Provenance, which this brief accompanies, is published and free to read on this site. The other three are completed works by the same author now in production and publishing shortly. Decision-Centric AI Governance defines the pattern language, Out of Bounds defines normative red teaming and the whitebox method, and Human-in-Control defines measurable human oversight. The patterns are used here exactly as those books define them, so this analysis reads on its own today and gains its full depth when read against the pattern language as each book arrives.


This Forensic Brief accompanies Provenance: How the Six Dimensions of Data Will Rewrite Privacy, Power, and Accountability by Dr. Anandkumar Prakasam. Incident facts are drawn from contemporaneous reporting (The Economist Korea, March 2023, with follow-on coverage by TechCrunch, Forbes, and Bloomberg through May 2023) and verified July 2026. Enforcement mechanisms referenced here are described at the level of architecture. Their implementations are the subject of pending provisional patent filings.