oneenergy
news
Market Intel

Tech Compass #1

Por Rafael Bortoloti11 de março de 2026 às 11:304 min de leitura
Compartilhar
ChatGPT

Corporate AI: The fine line between productivity and exposure

By Romulo Bacchiega

Romulo Bacchiega
Romulo Bacchiega (Source: WSB Team)

It was just another ordinary day at Samsung’s semiconductor division in March 2023. An engineer, struggling with a stubborn bug, decided to ask ChatGPT for help. He pasted chunks of the company’s proprietary source code into the tool and, within seconds, received debugging suggestions. Problem solved, work expedited. What he didn’t know was that he had just handed over strategic information from the South Korean giant to OpenAI’s servers. Within 20 days, two similar incidents occurred: one developer optimizing code for sensitive equipment and another transcribing a confidential meeting to automatically generate minutes. Samsung reacted quickly, banning ChatGPT from its network. But the damage was already done.

Samsung’s story isn’t the exception, it’s the rule. The same artificial intelligence tools that promise to revolutionize productivity are becoming silent vehicles for information leakage. And what’s most concerning is that this happens without malice, without hackers, without sophisticated attacks. It happens because an employee, pressed by deadlines, found a quick and convenient solution.

The numbers reveal the scale of the problem. According to a LayerX Security report, approximately 77% of employees have already leaked some type of corporate data while using tools like ChatGPT, Gemini, or Claude. Research conducted by IBM shows that nearly one in five employees regularly pastes company information into generative AI platforms, and more than half of these insertions contain confidential data. This isn’t occasional carelessness. It’s widespread behavior that has become routine.

To understand how this turns into leakage, we need to grasp the nature of these tools. Language models are trained in billions of texts, and that training never really ends. When you input information into public versions of these platforms, your data can be incorporated into the models’ refinement processes. What you typed today might appear as a suggestion to another user tomorrow.

But the risk goes further. There are reverse engineering attacks, where malicious actors use sophisticated techniques to extract information from previous conversations. There’s also legal risk: conversations with AIs can be subpoenaed in lawsuits. Sam Altman, OpenAI’s CEO, has already confirmed that data can be turned over under court order. An American judge ordered the delivery of 20 million ChatGPT conversations in a legal proceeding. Lawyers who used the tool to draft contracts discovered too late that attorney-client privilege may not apply when there’s a digital third party in the conversation.

The impacts on companies are multiple and severe. Operationally, leaking technical specifications or strategies means handing over competitive advantage. Legally, there’s risk of lawsuits for breach of confidentiality, intellectual property violation, and non-compliance with regulations like GDPR and various data protection laws. And perhaps the hardest to quantify: reputational damage. The trust of clients and partners, built over years, can evaporate when leaks become public.

The major challenge isn’t just what employees do with authorized tools, but what they do in the shadows. The phenomenon called “Shadow AI” – unauthorized use of artificial intelligence tools – is spreading. Well-intentioned employees, seeking efficiency, bypass IT policies using their personal accounts on public platforms. Research indicates that 97% of organizations that suffered AI-related leaks didn’t have adequate access controls.

So how do we navigate this dilemma? The solution is not to abandon AI—that would be throwing away one of today’s most powerful tools. The answer lies in intelligent governance.

First, clear usage policies are fundamental. Employees need to understand exactly what can and cannot be shared. This can’t remain buried in a compliance manual. It needs to be part of organizational culture, discussed in onboarding, reinforced in training.

Second, investing in enterprise solutions makes a difference. Platforms like Azure OpenAI, AWS Bedrock, or Google Vertex AI offer contractual guarantees that data won’t be used for training and remain isolated in the company’s environment. For highly sensitive information, local models eliminate external exposure risk. Yes, they cost more, but for certain data, the cost of a leak is infinitely higher.

Third, continuous education. Technology evolves too fast for annual training to suffice. Employees need to understand not just the rules, but the reasons behind them. When people comprehend the real risks, adherence increases naturally.

Finally, DLP (Data Loss Prevention) tools need to evolve for the AI world. Systems that identify when classified information is about to leave the network, that block suspicious uploads, that alert about risky patterns. Technology exists, but few companies have implemented it with generative AI in mind.

Artificial intelligence isn’t the villain in this story. It’s an extraordinary tool that’s redefining productivity, creativity, and innovation. But like any transformative technology, it comes with responsibilities proportional to its power. Companies that treat AI like they treated email in the ’90s”figure it out yourselves” pay the price. Those that invest in governance from the start will reap the benefits without nightmares.

Samsung’s case had an interesting outcome. After the initial scare, the company didn’t simply ban AI. It developed its own internal solution, with character limits per prompt, no internet connection and fully controlled. It transformed error into learning. That might be the most important lesson: in the AI era, the question isn’t whether we should use it, but how to use it intelligently. And intelligence, in this case, means security, governance, and responsibility. Because at the end of the day, no productivity is worth a leak.

Esta matéria foi produzida pela equipe editorial da Westhon Media para o One Energy News.

Reportagem e curadoria por Westhon Media

Leia também