MODULE 1 / 6🔊LEAK RISK  50
A developer pasting code into a public chatbot late at night
AI Safety Course

The Leak

Three Samsung engineers pasted secret source code into ChatGPT. They weren't spies. They were trying to ship faster.

25 minutes. Branching decisions, a redaction lab, and a classification sprint. A leak-risk score that follows you.

How this works: you play Sam, an analyst under deadline. Every choice about what goes into a prompt changes your score. Sound on for the full effect.

The real incident - Samsung, 2023

Three paste jobs. One company-wide ban.

0
Teams leaked code
0 wks
From rollout to ban

Spring 2023. Samsung lets engineers use ChatGPT. Within weeks, three separate teams paste proprietary source code and internal meeting content into it - one debugging, one optimizing, one turning meeting notes into a presentation.

Nobody was trying to leak anything. They were trying to ship faster. Samsung's response: ban generative AI on internal devices and start building its own internal chatbot.

The most dangerous prompt is a productive one. Chatbot inputs may be stored, reviewed by humans, or used for training. They leave your control the moment you hit enter.

Sources: TechCrunch, Bloomberg, The Register (Apr-May 2023) - see Case Library.
Dramatized scenario

9:41 PM.
Clearwater Health Systems.

You are Sam, a data analyst. A claims report is due at 8 AM and your script keeps throwing an error you can't crack.

YOUR SCREEN

The script pulls from the production database - connection string, credentials, and a sample of real patient records are sitting right there in the code. A public chatbot would spot the bug in seconds.

Decision point 1

What goes into the prompt?

Decision point 2

The next morning, your manager asks for a summary of a confidential vendor contract.

The chatbot writes great summaries. You have the PDF.

Decision point 3

A coworker shrugs: "Everyone uses it. IT knows. It's fine."

Redaction lab - prompt 1 of 4

Redact before you send.

Tap every segment that must come out before this prompt goes to a public chatbot. Then check your work.

PUBLIC CHATBOT - DRAFT PROMPT
Classification sprint

Classify before it moves.

1 / 12
Knowledge check - 5 of 6 to pass
Module complete
0

Decision points-
Redaction lab-
Classification sprint-
Knowledge check-
AI Safety 101 - Official Certificate
AI
SAFETY
101

This certifies that

has completed Module 1 - The Leak: confidential data and public chatbots on with a final score of /100.

Evidence on record: decision history, lab accuracy, sprint calls, knowledge check. This certificate ID verifies in your firm's admin report. A team certificate issues when every enrolled employee completes all 12 modules.

Your one rule to keep: before anything goes into a prompt - classify it, strip it, or route it to the approved tool. If you'd shout it in the lobby, it's fine. Otherwise, it doesn't go in.