Samsung AI governance was a case study in my Oxford course. I did not expect it to become a live experiment by the time I finished.
I completed an AI Governance course from Oxford’s Saïd Business School a few months ago, the kind of thing I do partly for the certificate and partly because I genuinely want to keep up with how the adults in the room are thinking about this kind of stuff. One of the case studies in the risk module was on Samsung AI governance, specifically the 2023 ChatGPT leak.
Engineers in the semiconductor division pasted proprietary source code into ChatGPT looking for a bug fix, another uploaded code for detecting equipment defects, a third ran an internal meeting through a transcription tool and fed the notes to ChatGPT to generate minutes. Three incidents, twenty days, and Samsung banned generative AI company-wide within the month.
The course filed this under security risk and operational risk, and that’s a fair read. What the case study couldn’t tell me, because it was written before it happened, is what Samsung did next. With that curious mind, I went looking, and the answer is more interesting than the leak itself.
The ban wasn’t the end of the story, it was the start of one
Samsung didn’t just block ChatGPT and move on. The company committed to building its own internal AI system rather than depending on public tools it couldn’t control, and that became Samsung Gauss, unveiled later in 2023 and followed by Gauss2 in 2024. The ban held for three years. It wasn’t universally popular inside the company either. In October 2024 the Samsung Group United Union wrote directly to Chairman Lee Jae-yong asking him to lift it, arguing that a company aiming to be world-class needs to use the best tools available.
The reversal came this June. Samsung’s DX Division officially reopened access to ChatGPT, Gemini, and Claude, framing it not as a one-off rollout but as a deliberate decision to let employees use whichever tool fits the task rather than treating AI adoption as a single initiative. The scale of it became clear weeks later when OpenAI confirmed it’s providing ChatGPT Enterprise and Codex to every Samsung Electronics employee in Korea and every DX division worker globally, described as the largest single enterprise adoption case OpenAI has on the books.
That’s a genuinely large swing, from a total ban to the biggest rollout of its kind. The thing I want to argue is that the swing isn’t reckless. It’s what governance done properly looks like when you walk it through the framework I just spent a course learning.

Running Samsung through the Trustworthy AI Cycle
To understand how Samsung AI governance actually matured over three years, it helps to map the arc against a framework I studied in the AI Governance course. The course centres on a five-stage model called the Trustworthy AI Cycle: consequences and oversight, data quality and conformance, principles and metrics, testing and documentation, and monitoring and review. The course teaches it as a forward-looking tool, something you apply before a system goes live. But I will be honest, I did not expect it to map this cleanly onto something that already happened.
Consequences and oversight is the 2023 leak itself. Before Samsung had defined any oversight mechanism for generative AI, three well-meaning engineers exposed exactly what could go wrong. That’s the failure mode the rest of the cycle exists to prevent, and Samsung found it the hard way.
Data quality and conformance is Gauss. Rather than keep sending Samsung’s proprietary information through someone else’s servers, the company built a model trained on its own data, code, and processes, alongside a dedicated AI Red Team (an internal group tasked with actively trying to break or misuse the system to find vulnerabilities before attackers do) to test for security and privacy gaps before anything shipped internally.
Principles and metrics shows up in the verification process Samsung ran before this year’s reversal. The DX Division tested external tools with around 2,500 employees first, rather than deciding from the boardroom that ChatGPT, Gemini, and Claude were fit for purpose. That’s the difference between a principle stated on a slide and a principle actually measured against real use.
Testing and documentation is that same pilot, formalised. New AI usage guidelines went in alongside the access, as opposed to an afterthought once problems started showing up. Roh Tae-moon, the DX Division president, was explicit that this was framed as a transformation in how the company works, not simply a tool being switched on.
Monitoring and review is happening now, in the form of dedicated AI divisions being stood up across Samsung’s affiliated companies, tasked with managing data, models, and security as adoption scales. This is the stage my own course material flags as the one organisations skip most often, the bit where you keep watching after launch instead of declaring victory and moving to the next project. Samsung built it in before the rollout went wide, not after something went wrong a second time.

The real Samsung AI governance lesson is sequencing
The easy headline version of this story is “company bans AI, company later un-bans AI,” which makes it sound like Samsung either overreacted in 2023 or is being careless now. However, I don’t think either is true. What actually happened is a textbook example of Samsung AI governance maturing rather than oscillating. Samsung used the closed period to build the internal capability and the security posture that made the open period defensible. The governance came first, the access came second, and that ordering is the entire point.
Most organisations do this backwards. They adopt a tool because it’s useful, discover the risk after the fact, and then bolt on a policy in a hurry. Samsung had that experience once, in 2023, and didn’t repeat the mistake when the pendulum swung back. That’s a more useful story for anyone building an AI policy than “ban bad tools, ship good ones,” because it shows the actual work that has to happen in between.
Where this leaves me
I came out of the course with a decent grip on the frameworks, but frameworks only mean something once you’ve tested them against a real case rather than a fictional one in a textbook. Samsung happens to have run a three-year, real-world version of the Trustworthy AI Cycle without knowing it was being graded on it. The mark I’d give them isn’t perfect, no organisation gets a clean pass on something this fast-moving, but it’s a long way ahead of most companies still pretending the choice is simply on or off.
If you’re sitting on the same decision in your own organisation, the question worth asking isn’t whether to allow generative AI tools. It’s whether you’ve done the unglamorous work in between the ban and the rollout that makes the rollout safe to do at all. The Samsung AI governance arc, more than the leak that started it, is the part worth studying.
Thinking about how AI systems discover and cite content? I wrote about that separately in the context of GEO and what it means for marketers.