An engineer is stuck on a bug in code that is part of their employer’s unreleased product. It is 9pm, the personal ChatGPT tab is already open, and pasting the whole function in feels like the fastest way to get an answer. In March 2023, within about three weeks of Samsung’s semiconductor division being permitted to use ChatGPT, the company identified three cases of exactly this: one employee pasted source code from a semiconductor database program to have errors found, a second submitted equipment-related code and requested “code optimization,” and a third uploaded a meeting recording to be turned into minutes. Samsung’s immediate response was an emergency cap of 1,024 bytes per prompt (The Economist Korea’s reporting, summarized in English by Mashable). By 1 May it had gone further, temporarily restricting generative AI tools on company-owned devices entirely (TechCrunch, “Samsung bans use of generative AI tools like ChatGPT after April internal data leak,” 2023).
Nothing in that story required a hacker, a breach, or even bad intent. Three employees trying to work efficiently reversed a company-wide policy that had been in place for less than a month, because pasting a secret into a third party’s system is itself the exposure — it does not need to go public, be misused, or even be read by another human to matter.
What actually counts as a “work secret”
Not everything work-related is a secret in the sense this article means. The category that needs the stop check is narrower and more specific:
- Source code from a proprietary, unreleased, or competitively sensitive system.
- Unreleased financial figures — quarterly results before public disclosure, internal forecasts, pricing strategy.
- Unannounced product or business plans — a feature roadmap, an acquisition target, a pending partnership.
- Security details — vulnerabilities, credentials, architecture diagrams of production systems.
- Contracts and terms under NDA — client contracts, supplier agreements, anything a signature already promised to keep confidential.
- Documented trade secrets your employer has specifically labeled or handled as such (a formula, a process, a customer list built at real cost).
A first draft of a routine internal memo, a public job description, or a generic process question is not in this category — the point is not to be afraid of AI, it is to recognize the narrower set of things that genuinely need a different path.
Why this is more than an IT courtesy
Most workplace AI guidance frames this as a policy-compliance issue, which is true but understates the stakes for genuine trade secrets specifically. Under U.S. law, information only qualifies for trade secret protection if its owner “has taken reasonable measures to keep such information secret” (18 U.S.C. § 1839(3)(A), enacted by the Economic Espionage Act and amended by the Defend Trade Secrets Act) — protection depends on an ongoing pattern of actually keeping the information controlled, not just on the information being valuable or unpublished. EU law sets a comparable bar: a trade secret must have “been subject to reasonable steps under the circumstances, by the person lawfully in control of the information, to keep it secret” (Directive (EU) 2016/943, Article 2(1)(c)).
Pasting a genuine trade secret into a personal AI account, with no contract governing how that provider handles, stores, or trains on the input, is exactly the kind of uncontrolled disclosure that can undermine “reasonable measures” — not because the AI provider necessarily misuses it, but because the information has left the set of people and systems the employer has actual control over. Whether a specific incident actually costs a company its trade secret protection in court depends on the facts and the applicable law in that case; the point for you as an employee is narrower and simpler: this is not a decision you are positioned to make casually at 9pm on your employer’s behalf, and undoing it afterward is often not possible.
Deleting the chat afterward does not undo the disclosure. Most providers let you delete a conversation or request account data deletion, but that does not retract the fact that the content was transmitted to and processed by a third party outside your employer’s control, and you have no way to verify what was retained in logs or already used downstream. Check what your provider’s published data controls actually promise before assuming a delete does what you expect — and treat the paste as effectively irreversible before you make it, not after.
The misconception that causes the damage
The damage usually starts with a measurement error: judging the risk by whether the secret became public. “I only pasted it into a private chat, nobody else saw it, so nothing actually happened.” That measure is wrong for two reasons. First, the exposure to the AI provider itself is the thing that matters for trade secret status, regardless of whether a human other than you ever reads the output. Second, consumer-tier AI accounts often do not carry the same contractual guarantees against training on your input that enterprise tiers do — your employer’s IT or security team, not you, is positioned to know which tier you are actually using and what its data terms say. Privacy and data hygiene at work covers how to check a tool’s actual data-handling terms once you know which tool you are using; this article covers the narrower rule of not pasting the secret in the first place while you are still unsure.
A second misconception treats “everyone on my team does this” as evidence it is fine. The Samsung case involved multiple engineers making the same reasonable-sounding individual choice, independently, before anyone at the company caught it. Peer behavior is not verification.
A third misconception is assuming this rule only applies to engineers and source code. Financial figures, an early draft of an acquisition memo, and a spreadsheet of unreleased pricing tiers are just as exposed the moment they are pasted into a personal account, and the person handling them is often in finance, sales, or operations rather than engineering — the six-category check below applies the same way regardless of your role or department.
The six-category stop check
Before pasting anything into any AI tool that is not your employer’s specifically approved, enterprise-configured account, check whether it falls into any of these:
- Source code from an unreleased or proprietary system.
- Financial figures not yet publicly disclosed.
- An unannounced product, feature, or business plan.
- A security detail — a vulnerability, credential, or production architecture.
- Anything covered by a signed NDA or confidentiality clause.
- Anything your employer has specifically told you is a trade secret or confidential.
If any answer is yes, stop. Finding and reading your employer’s actual AI policy is the first step to finding out whether an approved tool exists for this kind of content at all — some companies have one, some do not yet, and guessing either way is the mistake this article exists to prevent.
What to do instead
- Use your employer’s approved, enterprise-configured AI tool, if one exists — business and enterprise tiers are typically governed by a contract and data-processing terms that a personal account is not. The specifics differ by vendor and by tier, so treat “it is the work account” as a reason to check the actual terms rather than as a guarantee.
- If no approved tool exists for this kind of content, do not use AI on it yet. Ask your manager or IT/security whether an exception process exists, rather than deciding alone that the convenience is worth the risk.
- If you must ask a general question about a pattern rather than the specific secret, strip identifying details first — abstracted function names, rounded figures, a generic description of the business problem — and confirm with yourself honestly whether the abstraction is actually enough to remove the secret, not just enough to feel better about pasting it.
Audit your last AI conversation
Look back at the last AI conversation you had for work. Run it through the six-category stop check above. If anything in it should not have gone into that specific tool, that is worth flagging to your own manager or IT team now — a quiet, early flag is a much smaller conversation than the one that happens after an audit finds it. The work secrets paste-stop card gives you a version of this check to keep next to your keyboard.



