Samsung's semiconductor division was permitted to use ChatGPT. Within under twenty days, Korean media reported three separate disclosures.
An engineer pasted proprietary source code for chip manufacturing equipment, to find an error. Another submitted internal test program code, with hardware specifications, hoping for optimisation. A third uploaded a transcript of a confidential internal meeting to generate minutes.
Samsung then prohibited generative AI on company devices and moved to build internal systems it controlled.
Notice what did not happen. Nobody was social-engineered. Nobody clicked a link. Nobody broke a rule, because there was no rule.
The decision point is the missing document. Three capable employees independently reached for a useful tool to do their jobs faster, in a company that had said yes to the tool and never said what was allowed to go into it. The failure was the absence of one page.
This is not a warning to avoid AI tools. They are useful, and pretending otherwise helps nobody and gets ignored anyway, which is how you end up with the autopsy above.
It is about using them the way you would use any powerful tool that touches sensitive material: with a clear idea of where your data goes, a short list of what never goes in, and a rule you wrote down before you needed it.
Most of the risk here is quiet. Nothing dramatic happens. You paste something, get a good result, and never see the cost, because the cost arrives later and somewhere else.
What you paste can leave
When you type into an online tool, that text goes to a company's servers. What happens next depends entirely on that service and the plan you are on. Depending on the terms, your input may be stored, may be reviewed by humans for quality, and on some consumer tiers may be used to train future models.
That is fine for "rewrite this paragraph to be friendlier". It is a real problem for a client's confidential documents, unreleased work you intend to own and sell, customer lists or personal data you are legally responsible for, or anything covered by an agreement that says you will keep it confidential.
The danger is not that the company is malicious. It is that you moved someone else's sensitive information onto a third party's systems, often without their knowledge, under terms you did not read.
One question, before the paste rather than after: would I be comfortable emailing this exact text to a vendor I have not vetted?
If the answer is no, it does not go in the box. That test is fast enough to survive contact with a deadline, which is the only property that matters, because the Samsung engineers were not reckless people. They were busy ones.
Sort your material into three tiers
Blanket rules fail because they are either so strict that people route around them or so vague that they decide nothing. Three tiers works.
Tier 1, free flow. Public marketing copy, general questions, published material, anything already on your own website, drafting that contains no specifics. This is the large majority of daily work and it should move without friction, because a policy that slows down safe work loses to a deadline every time.
Tier 2, controlled. Internal documents, unpublished drafts, client work under NDA, anything with names, numbers or strategy in it. Allowed only on a plan with written data protection, and only if you have read what that plan actually commits to.
Tier 3, never. No plan, no tier, no exception.
- Seed phrases, private keys and recovery phrases. A meaningful number of people now paste recovery phrases into chatbots asking for help. This is the same mistake as handing them to fake support in F111-03, with the same ending. No tool needs your keys, and pasting them exposes them through logging, storage or review.
- Passwords and two-factor backup codes. A credential typed into a third-party tool is a credential you no longer control.
- Customer or patient data you are legally obliged to protect. This can be a breach of law or contract with real consequences beyond the leak itself.
Tier 3 items are not "be careful" items. The convenience is never worth it.
If you are ever tempted to paste a recovery phrase or private key into an assistant to troubleshoot a problem, stop. There is no legitimate fix that requires it, exactly as there is no legitimate support agent who needs it. Solve wallet problems through the wallet's own official documentation and recovery flow, never by reciting your secrets to a chatbot.
And note the compounding risk from F111-05: an assistant that has read your secrets is now an assistant an injected instruction can be told to repeat them.
Is the paid tier worth it?
Most people answer this by instinct. Answer it with arithmetic instead, because the arithmetic is easy and it usually points somewhere instinct does not.
Invented figures, to demonstrate the method rather than to describe your situation.
A ten-person studio. A business tier with written data-protection terms costs $30 per user per month.
Annual cost = 10 x $30 x 12 = $3,600
Now the other side. The studio's largest client contract is worth $80,000 a year and carries a confidentiality clause. Estimate the probability that, over a year of unmanaged pasting, something covered by that clause reaches a consumer tier in a way that costs you the relationship. Call it 5 percent.
Expected annual loss = 0.05 x $80,000 = $4,000
$4,000 > $3,600, so the plan pays for itself on this one contract alone, before you count reputation, other clients, or legal cost.
Then run the sensitivity, because that is where the real answer lives. The decision flips at:
$3,600 / $80,000 = 4.5 percent
So the whole question reduces to one thing: do you believe the annual chance of a confidentiality slip is above or below about one in twenty, in a team of ten with no written rule?
The Samsung autopsy is your base rate. Three disclosures in under twenty days, in one division, from people who were not careless. Whatever number you were about to write down, that should push it up.
Notice the structure, because it generalises past this decision. You are not asked to predict the future. You are asked whether a probability sits above or below a threshold you can compute, and thresholds are much easier to reason about than forecasts.
The one page
Most accidental leaks happen because nobody ever said the rule out loud. So say it, on one page, and keep it short enough that people read it.
- The three tiers, with two or three examples of each drawn from your actual work rather than generic categories.
- Which tools are approved, and on which plan. "Approved" means someone read the terms, not that someone liked the product.
- Where to ask. A named person who answers "can I paste this?" within the hour. Without this, the rule loses to the deadline and you get Samsung.
- What to do after a mistake. Explicitly no-blame, because the alternative is that mistakes go unreported and you find out from a client. The Samsung incidents surfaced. Most do not.
For creators specifically
If you make things for a living, there is a second question underneath the privacy one: ownership and provenance.
Keep originals and a dated record. Maintain your own original files and working history. Being able to show where a piece came from and how it evolved is the strongest position you have if ownership is ever disputed, and it is exactly the kind of record an on-chain ownership claim, a DOT, is designed to anchor.
Read the terms on rights and training. Tools differ enormously on who owns output and whether inputs train the model. For anything you intend to sell or license, choose terms that clearly leave the rights with you.
Keep unreleased work out of consumer tiers. If a piece is going to be a paid release, it stays out of any tool that might store or learn from it until it is public.
Keep a human between output and anything that ships. Check claims, names, numbers and links before they reach a customer. A polished mistake is still a mistake and it goes out under your name.
Closing the course
Every lesson here has resolved to the same move, which is worth saying plainly now that you have all six.
You never had to detect anything. Not a generated voice, not a generated face, not a generated article, not an injected instruction, not a leaked paste. In each case the defence was a decision made in advance, when you were calm, that removed the need to be right in the moment: a code word, a callback, a sourcing rule, a traced origin, a spending cap, a written tier.
That is the whole discipline. The fakes will keep improving and none of those defences get weaker as they do.
The lab, F111-L, is the smallest possible version of it: one protocol, with one real person, tested once.
Sort before you paste. Public work flows freely, controlled work goes only to plans whose terms you have read, and keys, credentials and protected personal data go nowhere at all. Put the split on one page with a named person to ask and a no-blame path after a mistake, because Samsung leaked three times in twenty days with no rule and no careless employees. Decide the paid tier with expected value rather than instinct, keep dated originals of your own work, and keep a human between any model output and anything that ships under your name.