In April 2023, Samsung Electronics allowed employees in its semiconductor division to use ChatGPT.
Within 20 days, three separate incidents had occurred.
The first engineer pasted proprietary source code into ChatGPT to debug a technical error. The second submitted internal meeting notes to generate a summary. The third uploaded confidential chip manufacturing measurements to get yield calculations.
None of them were trying to steal data. None of them were malicious insiders. They were simply using the most convenient tool available to do their jobs faster. They were doing exactly what you would want a productive employee to do: finding better, quicker ways to solve problems.
What they did not know, or did not think about in that moment, was that pasting Samsung’s semiconductor secrets into a consumer AI platform was the same as handing those secrets to a third party.
Samsung banned ChatGPT within weeks of discovering the incidents. Apple, JPMorgan Chase, Bank of America, Verizon, Amazon, Goldman Sachs, and Deutsche Bank followed with their own restrictions within months.
Every one of those companies arrived at the same conclusion. The productivity gains were real. But so was the risk that employees were turning a consumer AI tool into a data exfiltration channel that nobody had authorised and nobody was watching.
What happened at Samsung in 2023 is happening in Indian companies today. Not as a hypothetical. As a daily operational reality that most CTOs, CISOs, and IT heads have not yet measured, governed, or disclosed to the clients whose data is involved.
The Numbers That Every Company Needs to Read
The Samsung story is not exceptional. It is representative. The research conducted since that incident has produced statistics that should fundamentally change how every company thinks about AI tool usage in its workforce.
According to LayerX Security’s Enterprise AI and SaaS Data Security Report 2025, approximately 18% of enterprise employees paste data into generative AI tools, and more than 50% of those paste events include corporate information.
The scale grows when you include informal usage. 77% of employees paste data into generative AI prompts, and 82% of those paste events come from personal accounts outside company control, averaging approximately 14 pastes per day into non-corporate accounts, at least three of which contain sensitive data.
The sensitivity of what is being shared is increasing faster than the usage itself. Research from Cyberhaven found that 34.8% of the corporate data employees put into AI tools is now sensitive, up from just 10.7% two years earlier.
77% of online AI access goes to ChatGPT specifically. 45% of enterprise employees already use generative AI, and 92% of that usage runs through ChatGPT.
For Indian companies, these numbers carry a specific dimension that the global statistics do not capture fully. India’s IT services sector, its manufacturing exporters, its pharmaceutical companies, and its engineering firms operate under client NDAs that were written in a world where sharing confidential information with a third party meant emailing a document or giving a USB drive to someone outside the company. The NDA language says nothing about AI because the NDA was drafted before this scenario existed. But the legal obligation it creates is unambiguous.
What Employees Are Actually Pasting Into AI Tools
The categories of sensitive corporate information that employees share with AI tools are not exotic. They are the normal outputs of daily work.
- Client and project documentation. A project manager at an Indian IT services company pastes a client’s complete system architecture document into ChatGPT with the prompt “review this architecture and suggest improvements.” The document contains the client’s server configurations, database schemas, API structures, and in some cases system credentials. The client, a financial institution in Singapore, has a 40-page NDA that specifically prohibits sharing architecture documentation with third parties. The project manager used ChatGPT as a tool. Under the NDA, the project manager’s company shared the architecture with a third party.
- Design files and product specifications. An engineer at an automotive component manufacturer in Pune pastes product design specifications into Claude to generate technical documentation faster. The specifications include tolerances, material grades, and process parameters that the client considers proprietary. The client’s contract includes a technology non-disclosure clause. The engineer was meeting a deadline. Under the contract, the company disclosed proprietary technology to an AI vendor.
- Pricing and costing data. A sales executive at a manufacturing company asks ChatGPT to create a proposal from their internal cost sheet. The cost sheet includes supplier names, component costs, margins, and the final price breakdown that the company does not share even with its own sales team broadly. Once in ChatGPT, that information is on OpenAI’s servers. Competitors who obtain the same information through their own AI interactions, which can happen through training data leakage on non-enterprise tiers, now have pricing intelligence.
- Employee details and HR data. An HR manager drafts an employee performance improvement plan using ChatGPT, pasting the employee’s name, role, salary, and specific performance issues. Under the DPDP Act, salary data, performance records, and any other employee information processed digitally is personal data. The employer is the Data Fiduciary. The employee never consented to their personal data being processed by an AI vendor in the United States.
- Standard Operating Procedures and company policies. A quality manager pastes an internal SOP into ChatGPT to “improve the language and structure.” The SOP describes process steps that the company has developed over years and considers a competitive differentiator. It is now on an external server, outside the company’s control.
- Client names and relationship context. A business development professional asks an AI tool to draft a proposal for “our client ABC Fintech who is facing challenges with their regulatory reporting in SEBI submissions.” The client name, the client’s specific business challenge, and the nature of the engagement are now in the AI conversation. The client’s NDA forbids disclosure of the client relationship itself.
In each of these scenarios, the employee was being productive. They were solving a real problem with a powerful tool. They were not aware, or were not thinking in the moment, that productivity and confidentiality had just collided.
Why This Is a Third-Party Disclosure Under Every NDA
This is the legal reality that most employees, and many senior leaders, have not fully absorbed.
Every NDA contains a definition of confidential information and a prohibition on disclosing it to third parties. The definitions typically cover technical data, business information, client information, pricing, product specifications, designs, and anything marked or treated as confidential.
AI tool vendors, including OpenAI, Anthropic, Google, and Microsoft, are third parties. They are companies with their own servers, their own terms of service, and their own data processing practices. When an employee pastes client data into ChatGPT, they are transmitting that data to OpenAI’s infrastructure. That is a third-party disclosure.
The NDA was written before generative AI existed as a tool. But its language was written to cover exactly this scenario. It prohibits sharing confidential information with parties outside the company. AI vendors are parties outside the company.
There is an important distinction between consumer and enterprise AI tiers that companies must understand. Consumer-tier AI products, including free and standard paid versions of ChatGPT, Claude, and Gemini, have historically used conversation data to improve their models. Enterprise tiers, including ChatGPT Enterprise and Claude for Enterprise, have stronger contractual privacy guarantees and do not use customer data for model training. However, both tiers transmit data to the vendor’s servers. The data protection obligation in the NDA applies regardless of whether the data is used for training.
The Amazon incident illustrates this directly. An Amazon attorney told employees not to enter any company secrets into ChatGPT, explicitly stating that its outputs had already been seen to closely match existing confidential information. The concern was not only about future model training. It was about the fact that data had reached a third-party infrastructure that Amazon had not authorised for confidential information.
Even with enterprise AI versions offering improved data handling, the risks remain substantial. A security breach in 2024 exposed over 225,000 OpenAI credentials on dark web markets. If an attacker obtains the credentials for an enterprise ChatGPT account that employees have been using for sensitive work, the data that was protected from model training is still accessible through the compromised account.
The DPDP Act Dimension That Indian Companies Are Missing
Beyond NDA risk, there is a regulatory dimension specific to India that adds legal liability to what might otherwise be treated as a policy violation.
The Digital Personal Data Protection Act, which has been fully operational since the DPDP Rules were notified in November 2025 with enforcement required by May 2027, covers all digital personal data. This includes employee data: names, salaries, performance records, Aadhaar numbers, PAN details, biometric data, and health information.
When an HR manager pastes an employee’s performance details into ChatGPT, that is processing of personal data by a third party. The employer is the Data Fiduciary. The employer has an obligation to have a valid Data Processing Agreement with every entity that processes personal data on their behalf. Consumer ChatGPT usage is not covered by a DPA. The employer has not obtained specific, informed consent from the employee for their data to be processed by an AI vendor.
The same applies to client data. When a project manager pastes client contact details, transaction records, or any information that relates to identifiable individuals into an AI tool, that is personal data under DPDP. The company did not collect that data with consent for AI processing. The purpose of collection was project delivery. AI-assisted documentation drafting is a new purpose that requires separate consent.
The penalty for a data breach under the DPDP Act is up to ₹250 crore per incident. A client who discovers that their confidential data was pasted into a consumer AI tool by the Indian company managing their project has grounds for both contractual action under the NDA and regulatory complaint under DPDP.
The Invisible Nature of the Problem
What makes this risk particularly difficult for Indian CTOs and CISOs to manage is that it leaves almost no trace in standard security monitoring.
Unlike ransomware, which announces itself by encrypting files, or a phishing attack, which generates email security alerts, an employee pasting data into ChatGPT generates no alert in the firewall, no flag in the SIEM, no anomaly in the endpoint protection tool. The data leaves the organisation through a normal HTTPS connection to a legitimate domain. Every security tool in the stack sees a normal browser request.
The bans have softened into policies, and the policies have not eliminated the problem. When companies block ChatGPT on corporate networks, employees switch to personal devices, phone browsers, or smaller AI tools the firewall has not yet classified. Network blocks work as a temporary measure. They do not work as a strategy.
The problem is also growing in a second dimension. AI capabilities are being embedded into tools employees already use. Microsoft Copilot is inside Microsoft 365. GitHub Copilot is inside development environments. Google Workspace has AI features built into Docs, Sheets, and Gmail. These are not shadow AI tools that employees are installing secretly. They are features inside approved, corporate-licensed software that employees are using for work. The data that flows into these embedded AI features is subject to the same disclosure questions as ChatGPT, but is significantly harder to monitor because it occurs within tools the company has already authorised.
What the IT Head, CTO, and CISO Must Do
These are the specific, operational steps that change the situation. Not as a one-time exercise but as an ongoing governance programme.
Classify data before governing AI access.
The first requirement is a data classification framework that employees can actually apply. Confidential data, which includes client information, pricing, designs, employee records, and anything covered by an NDA, cannot go into consumer AI tools. Internal data can go into approved, enterprise-tier AI tools. Public data can go anywhere. This classification needs to be simple enough that an employee deciding in the middle of a busy workday can apply it without consulting a policy document.
Step 2: Publish a specific AI acceptable use policy.
Most Indian companies have an IT acceptable use policy. Very few have one that specifically addresses AI tools. The AI AUP must define which tools are approved and for what categories of data, explicitly prohibit pasting client data, pricing, designs, employee information, and NDA-covered material into any non-approved AI platform, and clarify that consumer-tier AI tools are third parties under company NDAs regardless of how employees think of them. The policy must be acknowledged, not just distributed.
Step 3: Move approved AI usage to enterprise-tier tools with DPA coverage.
If employees are going to use AI tools for work, and they are, regardless of what the policy says, the company should provide enterprise-tier access with contractual data protection guarantees. ChatGPT Enterprise and Claude for Enterprise both offer agreements under which the vendor does not use customer data for model training and provides a Data Processing Agreement. This does not eliminate all risk, but it significantly reduces the training data leakage channel and creates a contractual basis for the vendor’s data handling obligations.
Step 4: Monitor AI tool access at the network level.
EasyNAC and network monitoring tools can identify which AI services are being accessed from the corporate network, which devices are accessing them, and whether access patterns suggest systematic use of non-approved AI tools. This does not prevent an employee from using a personal device on a personal connection, but it provides visibility into AI tool usage within the corporate network environment that most companies currently have no way to see. Visibility is the prerequisite for governance.
Step 5: Run specific AI data security training.
Standard security awareness training covers phishing and password hygiene. Almost none of it addresses AI tool data sharing. Employees need a specific training module that makes the NDA and DPDP implications of AI usage visible in a way that connects to their daily work. The most effective approach is scenario-based: “You have a client architecture document. You want to ask ChatGPT to suggest improvements. Here is what that means under your client’s NDA. Here is what you should do instead.” Real scenarios from the employee’s actual work context land differently than generic policy statements.
Step 6: Include AI tool governance in vendor and client contract reviews.
When renewing or signing client NDAs, include language that specifically addresses AI tool usage. Define whether approved enterprise-tier AI tools with DPA coverage are permitted for processing client data and under what conditions. Get clarity from the client on their position before an incident forces the conversation. Some Indian IT services companies are discovering mid-project that their client’s updated NDA explicitly prohibits any AI tool processing of client data. Being surprised by this position during an audit is significantly more damaging than having negotiated it at contract signing.
Step 7: Audit what data is currently in AI tools.
If your company has not had an AI usage policy until now, there is a meaningful probability that sensitive data has already been shared with AI platforms. A retrospective audit, asking department heads to assess what types of information their teams may have used AI tools to process, gives a starting picture of exposure. This is not a comfortable exercise. It is a necessary one before a client audit or regulatory enquiry makes the question unavoidable.
The “Banning Doesn’t Work” Reality
One of the clearest findings from two years of corporate experience with AI data leakage is that outright bans are not a sustainable strategy.
When Samsung banned ChatGPT after the incident, employees did not stop wanting to use AI tools. They found alternatives. When JPMorgan Chase restricted AI access, employees used personal devices. When Apple restricted GitHub Copilot, developers found other code assistance tools.
The productivity benefit of AI tools is real and significant. Employees who are denied access to these tools while their counterparts at other companies use them freely will find workarounds. Network-level blocks buy time. They are not a governance framework.
The effective approach is not prohibition. It is structure. Clear classification of what data can go where. Approved tools with enterprise-tier protections for work data. Regular training that makes the stakes personal and specific. Monitoring that creates accountability without treating employees as suspects.
The companies that have navigated this well are not the ones that banned AI fastest. They are the ones that built a framework that gives employees a safe, approved path to use AI for their work while making the unsanctioned path visible and consequential.
The IT Services Sector Is Most Exposed
This final point deserves direct statement because it applies to a large and specific segment of the Skeletos blog audience.
IT services sector employs millions of knowledge workers whose primary output is intellectual work product for international clients. Those clients have signed NDAs. Those NDAs have third-party disclosure restrictions. And those same employees are among the most enthusiastic and technically capable users of AI productivity tools in the global workforce.
A developer at a Pune IT services firm using GitHub Copilot to write code for a US banking client is potentially putting that client’s codebase architecture into Microsoft’s AI infrastructure. A business analyst at a Bengaluru consulting firm using ChatGPT to summarise client meeting notes is potentially putting those notes onto OpenAI’s servers.
The client discovery scenarios vary. Some clients are running their own AI security audits and finding evidence of their data in AI training sets. Some are including AI usage restrictions in updated NDAs and asking suppliers to attest compliance. Some have already encountered situations where an AI-generated output they did not author appeared to contain information from their own confidential documents.
IT services companies that get ahead of this, that build an AI governance framework before a client audit surfaces the question, are in a fundamentally better commercial position than those that discover it the hard way.
The Samsung engineers were not reckless. They were trying to do their jobs faster using the best tool available. The governance that would have protected Samsung was not a character improvement programme. It was a policy, a classification framework, and a monitoring capability that made the boundary visible before three people crossed it in 20 days.
That governance needs to exist in your company before the 20 days start.
Final Thought
There is a sentence in the Samsung incident report that stays with me.
None of them were malicious insiders. They were simply using the most convenient tool available to do their jobs faster.
That sentence describes most AI data governance failures. Not bad actors. Not careless individuals. People doing their jobs, using the most powerful tool available, in the absence of a framework that told them where the line was.
The CTO who reads this and thinks “my team would not do that” is the CTO who has not yet had the conversation with their team about what an NDA actually says about third-party tools, and has not yet looked at their network logs to see which AI services are being accessed daily.
The CTO who reads this and builds a framework is the one who has that conversation before the client’s legal team does.
At Skeletos IT Services, we help Indian companies build the AI governance frameworks, acceptable use policies, data classification standards, and network monitoring capabilities that make AI tools productive without creating confidentiality exposure. From policy design to EasyNAC-based network visibility to employee training, we build the structure that makes the safe path the easy path. If you want to understand what AI tools your employees are currently accessing and what data may already have reached external AI platforms, we can help you find out.
Note: This blog references publicly reported incidents at Samsung Electronics, JPMorgan Chase, Amazon, and others, sourced from verified news reporting. Samsung’s ChatGPT ban was confirmed in May 2023. Statistics are sourced from the LayerX Security Enterprise AI and SaaS Data Security Report 2025 and Cyberhaven 2025 research. This blog is for awareness and educational purposes.

