Disclosure of confidential data by an employee pasting it into an external AI service, an incident with no intrusion and no technical flaw.
An employee pasting a fragment of source code, a contract or a client file into a consumer conversational assistant transmits that data to a third party, under terms of use that sometimes permit its retention and use for improving the service. The incident is defined by what it is not: there is no intrusion, no exploited vulnerability and no malicious act, and no perimeter security device detects it since the traffic is outbound to a legitimate service. Its legal characterization is nonetheless that of a personal data breach once the information falls within scope, with the corresponding notification duty, and of trade secret disclosure in other cases. The broader phenomenon, teams using unapproved services on their own initiative, is not addressed by prohibition, which pushes usage onto personal devices where it becomes invisible, but by providing an acceptable alternative and by logging outbound traffic.
In May 2023, Samsung Electronics restricted the use of external conversational assistants on its internal systems after employees had transmitted internal source code and meeting notes to a consumer service.
prompt leakage, fuite par invite, shadow AI, IA de l'ombre