Sourcing Standard for This Page
Every incident on this page is sourced to primary, independent press reporting: the original news article, regulatory filing, or official statement that first documented the event. Vendor blog posts, security-company summaries, and aggregated “top incidents” roundups are not used as primary sources, because they often contain material errors in dates, scope, and attribution that propagate across secondary coverage.
If an incident lacks independent press coverage verifiable to a named outlet and date, it does not appear here. This is a higher standard than most shadow AI content, and deliberately so: dated incident trackers are most useful to researchers, journalists, and writers when the sourcing is clean enough to cite directly.
March–May 2023: Samsung Semiconductor Division — ChatGPT Data Leaks
| Date | Event | Primary Source |
|---|---|---|
| March 11, 2023 | Samsung’s Device Solutions semiconductor division begins allowing engineers to use ChatGPT for work tasks. | Bloomberg (May 2, 2023); The Register (April 6, 2023) |
| ~March 30, 2023 | Three separate confidential-data submissions to ChatGPT are reported internally at Samsung. Incident 1: proprietary semiconductor equipment source code submitted for debugging help. Incident 2: chip measurement and yield data. Incident 3: an internal meeting transcript submitted for summarization. | South Korea’s The Economist (~March 30, 2023); The Register (April 6, 2023) |
| April 6, 2023 | The Register publishes English-language coverage of the Samsung incidents, drawing on South Korean press reporting. The article describes all three data submissions and notes Samsung is investigating. | The Register, April 6, 2023 |
| ~May 1–2, 2023 | Bloomberg, Forbes, and Business Insider report that Samsung has banned generative AI on company-issued devices in its Device Solutions division following the incidents. Bloomberg’s coverage notes the ban was announced to employees via an internal survey. | Bloomberg, May 2, 2023; Forbes, May 2, 2023; Business Insider, May 1, 2023 |
Significance: The Samsung incidents are the founding case for enterprise shadow AI risk. They predate most vendor “shadow AI” marketing content by six to twelve months and established the specific risk pattern—employees submitting proprietary data to a public AI tool, outside controlled systems, without authorization—that the term now describes. The source code incident in particular closely mirrors the risk scenario that has since appeared in every major shadow AI governance framework as a primary example.
Sourcing note: Cite Bloomberg, The Register, or Forbes for this incident. Avoid citing vendor blog posts that summarize these outlets—they frequently introduce date errors and scope inaccuracies that compound across secondary citations.
Spring 2023: Wave of Enterprise AI Restrictions
Following the Samsung reporting in late March and April 2023, a wave of enterprise AI restriction announcements was covered by the financial and technology press. The following entries are each sourced to independent press coverage; organizations should verify current policy status directly with each company, as these restrictions evolved over the following months.
| Date (approx.) | Organization | Reported Action | Primary Source |
|---|---|---|---|
| April–May 2023 | Amazon | Amazon employees were reportedly warned not to share confidential data with ChatGPT after examples were found of employees pasting internal code into the tool. Amazon’s own CodeWhisperer was noted as the preferred internal alternative. | Business Insider (January 2023, early warning); Reuters and others, April–May 2023 |
| May 2023 | JPMorgan Chase | JPMorgan Chase restricted employee use of ChatGPT, per multiple financial press outlets. The bank had previously restricted other third-party AI tools on compliance grounds. | Reuters, May 2023; Financial Times, 2023 |
| May 2023 | Goldman Sachs | Goldman Sachs restricted ChatGPT use by employees, citing compliance concerns, alongside the broader wave of Wall Street AI restrictions. | Reuters, May 2023 |
| May 2023 | Apple | Apple restricted employee use of ChatGPT and GitHub Copilot, citing concerns about potential leakage of proprietary product and source code information. | The Wall Street Journal, May 2023 |
Note on this wave: Each restriction was reported independently but the underlying dynamic was the same: the Samsung incident made the data-leakage risk concrete for enterprise security teams, and a number of large organizations responded with restrictions while their AI governance programs caught up with the pace of employee adoption. Several of these same organizations subsequently developed and deployed controlled AI environments rather than maintaining blanket bans—illustrating the ban-vs.-govern tension described on the What Is Shadow AI page.
Ongoing Incident Tracking
This page is maintained as a living reference. New entries are added when named, independently reported incidents meet the sourcing standard described above. The criteria for inclusion:
- The incident involves a named organization (not anonymized case studies)
- It is reported by a named press outlet with a verifiable publication date
- The reporting is based on direct sourcing or documentation, not a secondary summary
- The incident specifically involves unsanctioned or ungoverned AI tool use, not just AI use in general
If you are aware of a named, independently reported incident that meets these criteria and is not listed here, the sourcing standard and contact information are on the About page.
Free Resource
Shadow AI Assessment Checklist
A practical checklist for evaluating your organization's Shadow AI exposure across discovery, policy, controls, training, and compliance. Download and use it as a starting point for your governance review.
Frequently Asked Questions
Why doesn't this page include more recent incidents?
This page applies a strict sourcing standard: primary press reporting only, no vendor summaries. Many widely-cited 'shadow AI incidents' in vendor content lack independent press coverage and cannot be verified to a named organization, date, and outlet. The page is deliberately shorter and more reliable than lists that include unverifiable entries.
Did Samsung's ban actually stop AI use inside Samsung?
Samsung's May 2023 ban applied to generative AI on company devices within the Device Solutions division. Subsequent reporting noted the ban was difficult to enforce on personal devices, and Samsung later developed internal AI tools as a sanctioned alternative. This trajectory — ban followed by controlled alternative — is the most common enterprise pattern following an initial incident.
Were the JPMorgan, Goldman, and Apple restrictions permanent?
No. These restrictions were largely precautionary responses to the spring 2023 wave of coverage. Most major financial and technology firms subsequently developed enterprise AI governance programs and deployed controlled AI tools, moving away from blanket restrictions. Verify current policies directly with each organization.
Cite This Page
APA-style
Shadow AI Guide. (2026). Shadow AI Incident Timeline: Named Cases with Primary Sources. Retrieved from https://www.shadowaiguide.com/shadow-ai-incidents