Samsung bans use of A.I. like ChatGPT for employees
cnbc.com
cnbc.com
What is it about an AI chat bots that makes the risk of a data leak so much higher? Is something about OpenAI's ToS? Or it's relative infancy?
“(c) Use of Content to Improve Services. We do not use Content that you provide to or receive from our API (“API Content”) to develop or improve our Services. We may use Content from Services other than our API (“Non-API Content”) to help develop and improve our Services. You can read more here about how Non-API Content may be used to improve model performance.”
https://web.archive.org/web/20190224031626/https://blog.open...
> Chat History & Training Save new chats to your history and allow them to be used to improve ChatGPT via model training. Unsaved chats will be deleted from our systems within 30 days.
Most people do not change most default options. And companies know this.
If you dig into the Settings you can disable sharing chats with OpenAI, but you lose access to just about every feature including saving chats. You can only have one chat at a time, and if the window is closed or refreshed your chat is wiped. it's kind of like if opening a "Private Browsing" window prevented you from having a regular browsing window open and also had no tabs.
For some reason, they still retain your chat for "up to 30 days" despite not letting you save or access it after the page is refreshed.
They need to use an asynchronous system to be tracking when your chat becomes "finished" and then likely queue it up to a system looking to propagate deletes. They have to choose some kind of SLA on that and probably went with a common data privacy user data deletion window of 30 days.
That sentence does not claim OpenAI does not use such Content for other purposes besides "developing and improving the Services". For example, using the Content in a manner that potentially harms Samsung's business.
What does "develop or improve our Services" even mean? There is no definition.
Third, how would anyone outside of OpenAI know how OpenAI uses the Content. For example, what if OpenAI was using Content from Services other than the API for purposes other than "to develop and improve our Services" (assuming anyone could prove what thet even means). How would anyone outside of OpenAI discover this was happening?
If we search these "ToS" for phrases like "You will" or "You will not", we see that users make promises to OpenAI. However if we search for phrases like "We will" or "We wil not", we see that there are no instances where OpenAI promises anything. IMHO, these "ToS" are better characterised as "ToU". Not to mention being found at "/policies/".
As a ChatGPT user, OpenAI does not owe you anything, unless perhaps you are Microsoft. For you, the "terms" can change at any time, for any reason, without any prior notice.
Let's imagine some far-fetched scenario where someone inside the company leaks information that suggests OpenAI is using Content from Services other than the API for purposes other than "improving or developing the Services". Then what?
OpenAI has not promised to refrain from using Content for certain purposes. There is no breach of these ToS if OpenAI uses the Content for whatever purposes it desires.
Maybe Samsung could claim something like (a) OpenAI misrepesented facts in their ToS, (b) that induced Samsung into using OpenAI, and (c) as a result Samsung suffered harm. Needless to say, claims like that are difficult to prove and any recovery is limited. Whatever creative legal claims Samsung could could up with, none of them would fix damage already done to Samsung from its employees having used OpenAI.
Though, they don't define "developing and improving".
> Save new chats to your history and allow them to be used to improve ChatGPT via model training
How will that private/proprietary information be used by OpenAI? Does it include NDA information from another company that they don't have the right to share? How secure is the information stored (think industrial espionage)? There is a lot that needs to be taken into account that even goes beyond this.
From what I personally have seen, this sort of guidance remains. When companies do use things like Google Docs or Microsoft Office365, they likely have some specific contract in place with Google / Microsoft / etc., that the company's legal team has decided they are happy with.
I anticipate that the same will eventually be true of ChatGPT and such, that there will be some paid corporate offering with contract terms that make the company lawyers happy.
Most of my career has been with larger companies, often with high data sensitivity; I can easily imagine that some smaller and/or less data-sensitive companies might not care about any of this.
The cloud is a terrible bet for many large companies. The benefits are minimal while the risks are huge, however what’s in the best interest for the company is only tangentially related to what happens.
It’s really difficult to ensure companies actually take low probability risks seriously. A 1% chance to lose 10 billion dollars is an easy bet for upper management to make when their personal risks and rewards don’t line up with the company’s risks and rewards.
As to the risks, many companies live and die by their internal secrets. These range from a private keys, customer lists, trading strategies, and similar trade secrets to actual serious R&D efforts.
Sometimes the damage is obvious such as crypto exchanges suddenly finding themselves broke, but corporate espionage can also be kept quite. Losing major government bids because a competitor read some internal memo’s is a serious risk and you may never know.
It’s much harder to reconstruct actionable intelligence from a huge stream of people using Google search even if they’re using it to preform sensitive calculations.
There’s plenty of high profile fuckups from people falling to AWS specific gotcha’s.
So prior to that, they were willing to use your data for model training. Every service may have leaks/security issues, but few say they'll purposely use your data. OpenAI probably should've promised not to use your data from the beginning; it'll be a hard perception to change now.
https://techcrunch.com/2023/03/01/addressing-criticism-opena...
A dark pattern that tends to provoke an unintentional behavior does not seem to be likely to hold up as "agreement"
Yes they do. Where I work the whole google office suite is blocked from inside the network (you have to use MS Office). ChatGPT is blocked. Most web apps that you can copy text or data into are either blocked, or we have an agreement with the provider, or (for open source) we have an internal on-prem fork.
This is the same thing.
I see a distinction between several kinds of companies:
Competent companies are asking employees to be more productive and are training them with AI.
Less competent companies are restricting use of AI.
Companies generally tend to be wary of cloud services due to data leak concerns. At the very least, they like to be in control of the decision about which services are approved and which are not.
I would have concerns about Google using my data but I wouldn't be concerned that the data I enter could easily appear in someone else's spreadsheet.
E.G. you’ll probably be able to use the corporate account to sign into the corporate Google Docs or O365 instance but if you try to sign into your own it would be blocked and likely also reported on so you might get a call from SecOps down the line.
OpenAI currently offers none of it and more importantly it openly uses the data that users submit to it as well as the responses for additional training and any other purpose they might come up with.
As for browsers these are also often also configured not to send data outside of the company and yes it’s possible. Windows 11 web search and other features would also likely be disabled on your corporate device.
With ChatGPT, you get researchers paid over $1m per year [1] to use you as a training data source and ship stuff with basic bugs and then "feel sorry" when stuff breaks: https://www.theregister.com/2023/03/23/openai_ceo_leak/
Another position for those like Samsung: preventing ChatGPT use encourages incubation of internal competing solutions.
[1] https://davidgoudet.medium.com/how-did-this-ai-scientist-end....
We are not to use any third party cloud hosted software that is not approved to store proprietary information.
There are only three external SaaS companies that I am aware of that we use that stores anything proprietary.
We are not even allowed to take pictures of the whiteboard because the pictures can be synced to external cloud storage providers.
Of course there is a duty on employees to be professional - the latter will be the ones taking up opportunities at non-legacy/dinosaur corporations that think they can command the waves.
The answer is to sort your processes, security and training out - new AI is here to stay, and managers cannot stop employees using game-changing tools without looking very foolish and incompetent.
At the size of Samsung that's just an impossible move, and it's easier to blanket ban a problematic service and have employee request exceptions justifying their use case.
BTW I've been in companies that blanket ban posting stuff online, and got posts security reviewed when asking help on vendor community forums. That's totally a thing.
Personally I haven't used GPT much so I wouldn't mind, but banning copilot would make me reconsider.
Basically the challenge is fairly straightforward, if one side is machine-generated, and the other side is human-validated, the human loses 100% of the time. Either the machine has to be 100% accurate or very close to it, or the human needs tools to help him. As it stands, neither of those conditions is here yet
IMO the only people crapping on AI either don’t know how to prompt it correctly, aren’t very creative, or frankly weren’t doing that much work in the first place and feel threatened by it. I understand the need to protect intellectual property but 10 years from now there will be two types of companies: Those that embrace AI, and those that crashed and burned.
> I write a lot of code with it and it’s extraordinarily, obviously clear that when prompted right, it increases productivity 2-5x. My company recently banned it and it has been excruciating. Like going back to coding before StackOverflow and Google existed.
I would still appreciate any tips in this regards
The big area of concern were people using 'doctor google' instead of going to a doctor. Finding a sore throat and jumping down the most negative path.
You could use google to mine certain types of data in that era. Passwords.. now much of that is filtered.
In 10 years those intellectual property rights might give them ownership over AI. The court battles haven't begun yet
You are neither arguing in good faith, nor even engaging in my argument at all. Please try not to do that. Your two paragraphs amount to nothing more than "if you are criticizing GPT-like tool, you are an idiot", that's not even an argument.
That's strange to me. I'm employed in order to receive a paycheck. If receiving my paycheck is contingent on me not using ChatGPT, then so be it, what do I care?
I am hugely fascinated and impressed by AI, and the fact that my work is paying me to spend time using this awesome tool in a real world context is suuuuuuuper good for my job satisfaction.
Some people want their work to be high quality and/or done quicker. If there are tools to facilitate that, some people will be interested.
If you get fired/quit and any other job you're looking at is going to have you interacting with new languages or AI workflows or something like that you have to assess what value you're losing by working for that company and the risks associated with it.
I can be employed to receive a paycheck by employers that give me freedom or employers that take away useful tools.
Why do I stick with the employer that gives me less freedom? Not to mention, getting a new job almost always drastically increases the size of said paycheck.
Why? Companies typically have many rules that they expect employees to follow. Why would employees disregard these particular rules, or even quit because of them?
i.e basically you can do a lot of work in just a matter of hours. Once you taste the productivity increase by integrating AI into your workflow you will miss it if it is taken out.
not mention you can build all the handy little tools in a matter of seconds that will make your daily life way easier.
I still fail to see why employees will now choose to disregard this particular rule, and either disobey or quit.
I'm not sure how you mean trivial here, but not being able to use emacs isn't a trivial matter to emacs users :)
> I still fail to see why employees will now choose to disregard this particular rule, and either disobey or quit.
I fail to see why employees follow rules that make no sense rather than disobeying or quitting.
I find your explanation sound and reasonable. There are many rules that, even if not necessarily liked, are not sufficient grounds to do anything about. But sometimes rules may impede your workflow so much that you find it preferable to either quietly work around the rule, or even to quit.
I'll give you a real-life anecdotal example to expand a little on my point. My buddy is a front-end developer for a company which produce pretty basic "stuff" (sorry, I don't know anything about front-end) according to him. He says that he's gotten lazy and unmotivated to do anything about it. This leaves him unchallenged and he doesn't really like his job. Once GPT arrived, he's been able to (according to himself) reduce 70 % of the boring boiler-plate code type work he has been doing for years, by making GPT write it for him, and him just verifying it works. This has ultimately allowed him not only to focus on taking on more interesting projects where he can challenge himself, but also spending a lot of the time he previously spent writing "bullshit boiler-plate code" in learning new and more challenging front-end things.
I can easily imagine people in other jobs, in IT or perhaps in other fields already using GPT to reduce the boring parts of their jobs. I can genuinly not recall having heard anyone say a new IDE or any other tool since the arrival of the computer itself reduce their "boring work" load this signifcantly. So I think at this point it is reasonable to assume that access to GPT will become considered as commonplace as having access to a computer or email (given you work in a field where those are considered basic/primary tools of course), and that employers will have to adapt. If not, people will disregard rules / go "shadow IT" or even consider quitting.
Just yesterday, I needed to mock up a quick prototype for a new feature we're developing. I just paste in my existing React component (and it's all front-end code with no sensitive/proprietary information), tell GPT-4 what I want it to do, and it does it.
Is it perfect? No. Does it sometimes get things wrong? Yes. But it's still easier and faster to help guide GPT-4 and tweak its final output than to have done it all myself.
I'll never go back. Never.
and generating boilerplate is the road to madness
Companies can have reasonable cause to block things, or require processes for installing software, etc., but when those burdens become too much time or effort employees will find a way around it.
Almost a decade ago, the company I worked for didn't have good wiki software OR a good request system. My team had a linux server for the purpose of some primitive monitoring and automation of our systems. Apache was already installed...
Within a few weeks we operationalized a new dokuwiki installation, and not long after that we built an internal request system based on Bottle.py (since it didn't require any installation, only a single file).
Seeing that GPT-4 is so incredibly useful to the people I've heard talk about it, there will be employees trying to use it to increase their code quality, communications, planning, etc.
My current employer put out guidance specifically stating not to put any proprietary code into it, no matter how small, nor any confidential information of any kind (don't format your internal earnings email with it, for example).
That seems reasonable, and recognizes how hard it will be for employees to go zero-tolerance, especially if they don't have total network control over work endpoints.
Companies banning the use of ChatGPT level tools going forward will find the rules either flouted, subverted or the employees going elsewhere.
If my employees are leaking company information through ChatGPT, I'm happy to have them go work for my competitors and leak their information, instead.
If you think people are just hyping ChatGPT because its new without further reflection, you have stunningly missed the moment and have a rude awakening coming.
I agree that when it becomes an option, hosted or securely tunable solutions will be preferred in some cost/risk calculations.
What would impact the world economy more? OpenAI disappearing (no one would notice) or Samsung disappearing?
My advice is follow best practice and wait for an official company policy detailing the use of these new services. Otherwise you may find yourself in legal trouble years from now when the traces you left can easily be uncovered by technology that does not forget.
The only use for AI is for writing code and the company created a policy around that.
Samsung may attempt to ban use of the tool for their employees because they're worried about loss of internal data, but when the tool hugely reduces the workload of those employees, they'll find a way to use it anyways.
1. https://learn.microsoft.com/en-us/azure/cognitive-services/o...
1. https://learn.microsoft.com/en-us/azure/cognitive-services/o...
Super helpful for boilerplate code. Right now, we have a limit of 500 tokens though, so it somewhat limits asking more complex questions.
Interestingly, our internal team supporting it has added a ton of initial prompts depending on what vertical of our business you want to ask about. Kind of neat, as I haven’t tried to get the AI to pretend to be something else as of yet.
(Because I mostly just ask it to write various things to the tune of the “Fresh Prince of Bel Air”)
When you say use it a lot do you mean typing in queries yourself or programatically and/or recursively generating prompts like autogpt?
Because I thought one day I had used it a lot by typing in lots of messages. The next day my usage was less than a few dollars.
You can hardly see from the pictures AI if your picture is part of the model.
Also in the news: https://www.cnbc.com/2023/05/02/chegg-drops-more-than-40perc...
>but the real value comes from replace internal “tribal knowledge” with an AI who knows your org in and out
I bet Microsoft is already working on that.
We currently use GPT-4 combined with an internal knowledge base we had earlier since the beginning, and we practically have to fire our chief of staff and the admin team. Just kidding, but it's made her team's work a ton easier that she can devote more time to the nitty-gritty hard stuff.
The interesting part is that I had a bit of a personality touch added as part of its context, so the AI's character is quite.... villainous.
Enterprise self-hosted ChatGPT is going to be huge.
Currently we use an initial semantic search for context injection, which is then passed to GPT for completions. If any LLAMA company were to make that second pretrained bit self-hostable for some license fee, I know a bunch of companies in finance of all sizes which would readily pounce on that tool. But I'm fairly certain that's not what Open AI wants to do.
They are now trying to build a search index and feeding it in-context results.
Honestly not seeing much value over a search index, but hey if it makes the internal data easily searchable under the banner of AI hype it's a win.
(it makes it easier for some junior to replace you some day)
And the junior could leave the company, an AI won't.
Sure its not everyone, but the people who arent using them are signaling a major red flag IMO.
They are resistant to change, even if they don't understand the technology, what else are they resisting from their managers/leadership team? Further, I think of the people in my life who have refused to even try it, they all seem to have a screw or two loose, even if they are making 200k/yr successful.
All IMO of course, but in tech, I imagine something needs to be 'off' to never try it.
EDIT: Seems I'm getting criticism from people who are using it for inappropriate use cases. I don't use a screwdriver to hammer nails.
maybe it is easier to go through actual verified information than to double check everything an AI says.
I only use LLMs to restate information that I can half piece together so I can remember the missing bits (like a math proof or derivation), or to point me to recommendations of actual resources. And even those two things i am very wary off.
Wrong tool for the job. You don't ask it information questions. Ask it brainstorming questions.
Consistent conditional logic makes more sense than a risk-laden hallucinating LLM for a lot of workflows.
"Everyone" doesn't need to hammer nails because there's more than just one career and industry. The acceptable quality of the job output varies drastically too.
"It kind of boggles my mind" that people can't see beyond their own life.
It's great for generating sample code snippets or refactoring code, but I can't paste my company's intellectual property into it
If I could train a customized version of it on all my company's Slack messages, Jira tickets, e-mails, etc it'd be insanely useful . . . . but I don't think any big company would actually want that, since it wouldn't be able to keep secrets from anyone with access to it
But it's definitely good at some other things. Writing boiler plate texts of various sorts and giving instructions on how to do certain things notably.
It seems to mostly synthesize common knowledge rather than learning anything. But that can be very useful, a lot of people's job involves doing things like that today.
To test reading comprehension, the source should be in the prompt, not the training set.
It's wise to ban them until they improve or naive users get more instruction how to use them properly. And from experience with some Samsung products, they could do with tightening up their code QA standards a bit.
Sometimes it's a dick and will test the assertion that 1==1 though.
(Just as I would if it was something I found on Stack Overflow.)
When I look at a PR, there are two things I try to validate:
1. Do I understand what the code is supposed to do, and why the author chose to do those things that way. If not, then either the code need rewriting (because it does things in a way that shouldn't be done,) or more commenting (because it ain't obvious), or both.
2. Catch anything that is obvious to me, but not the author, or to the linter. Maybe there's a different function that does a thing the author didn't know about? And while doing that, it's important to keep context in mind. You could write the kind of code that would be very smart, but can't be understood by most, and that's code is just as bad as a very dumb code (see (1)).
If I have to catch obvious errors, than the author didn't do their job. If I have to catch spelling mistakes or formatting issues, than the linter didn't do their job.
My job is to catch anything that neither the author nor the tools can.
It is always better to educate people. ChatGPT needs to be treated as Wikipedia.
The way basic privacy and secrecy is ignored in this space is staggering.
What remains to be seen is whether we come back to our senses soon enough.
A lot of “experts” working in ai are warning about dangers but what they omit telling is that it’s the humans who own ai that are dangerous.
However, Samukawa offered assurances that Yokosuka intends to use the tool in line with OpenAI’s typical security policy.
Ha
CIA/NSA would be failing at its core real mission if they didnt help US interests when they see an opportunity. And with us-based cloud they dont need to hack anything remote, just fill another form and go again in.
Makes me think, having strong privacy laws like ie in Swtzerland is a massive win for given country and its citizens in long term.
I'm not sure if this claim was ever validated but it seems wild those fairly boring companies would come out with it over nothing, whereas it is related to of the US services stated mission.
US government access to thier companies customers files has been a compliance issue in Europe for a while because it is hard to claim GDPR compliance if your vendor might be required to leak user data outside the judicial system. This is why privacy shield treaty was needed.
[1] https://www.bbc.com/news/world-europe-32542140
[2] https://www.theguardian.com/world/2013/sep/09/nsa-spying-bra...
[3] https://www.theguardian.com/business/2010/dec/08/wikileaks-c...
Microsoft so far hasn't been hacked.
How do you know?
Nation states wouldn't, but it's safe to assume powerful nation states are already in every cloud provider, at least the US glowy boys anyway according to Snowden.
And you are sure no hacker group has boasted, anywhere on the darknet, about hacking Microsoft? And even if that were true, you take that as strong evidence that Microsoft has not been hacked?
> When you use our non-API consumer services ChatGPT or DALL-E, we may use the data you provide us to improve our models. You can switch off training in ChatGPT settings (under Data Controls) to turn off training for any conversations created while training is disabled or you can submit this form. Once you opt out, new conversations will not be used to train our models.
https://www.pcmag.com/news/samsung-software-engineers-busted...
Basically sensitive code got spat out later.
I'm not really familiar exactly on how ChatGPT works but does it get trained on input data(search queries)? People are also "leaking" their personal information to Google when they search for something personal like health issues, financial issues, family issues etc.
What is the privacy policy of these chatbots afer-all?
The OpenAI API has a policy to not use input as training data.
Azure also offers the API with an agreement not to use it for training.
We're investigating standing up our own internal model for internal use to control any risk of our IP leaking out and to be able to vet the training data.
I see lots of casual mention of using it for assistance in writing code.. we view that as fairly dangerous in terms of the risk of accidentally including snippets of open source code.
There are many risks to this. Personally my own experimentation (for coding) was pretty ambivalent as to what it can/could actually speed up. Chat GPT is not that fast and it takes time to keep refining what it sends back to you. The window of what it actually helps with seems small right now.
Seems very questionable to not make a single claim about how GPT was “misused”. Without a claim, it seems like narrative.
Which, honestly, is a better article and states the issue outright: https://www.bloomberg.com/news/articles/2023-05-02/samsung-b...
I'd also say that one needs a moat in order to succeed; you can't just provide the LLM, since anyone can do that, you need to provide something more that works even without any AI at all.
1. given the following string [...], build me a regex that extracts the [abc] before [`], until the 2nd [xyz], used for extracting a bunch of info from an array
2. give me a list of common beneficiaries, then give me 5 more
Took an hour or so of Googling, then about 10 mins to find an online/open ChatGPT prompt, and about 2 mins to implement the answer in my code. But that's where I draw the line, I'll never use an editor that uses AI in my actual IDE, or expose my code openly to train modelsIt's 2 sentences repeated 3 time.
What exactly is "misuse"?
News for the ADHD...
Using AI in a way that doesn't share your company secrets and private code with the entire world is around the corner or already partially possible.
Very obviously Samsung will not ban AI as a whole forever.
Havent found something that works in 1 click.
The lazy use of viral when talking about computer tech here annoys me slightly.
People have tasted the fruit of the tree of (machine) knowledge.
They're not going to let a simple webfilter stop them.
It doesn't matter if they have a checkbox saying 'we totally won't save your information we promise', no one should be shoveling confidential data into ChatGPT and if people keep doing so then they're a security risk.
I do wonder if there will one day be communications formatters like what Prettier does for code, where no matter the style of writing going in, it will come out consistent. But until there are 'communications rewriters' to match a predefined company tone and style guide it seems like anyone's use of a tool like this would by ad-hoc.
What do you think the most sensible policy is to have right now, and why?
[1]: https://www.reuters.com/legal/us-supreme-court-rejects-compu...
Can they enforce code injections to create backdoors, like they tried with cryptography?
What "misuse"?
This is more of a sound bite than news, there's no information content...