An art director is behind on a deadline. The client's unreleased packaging mockup needs a quick tweak, a color shift, a tagline swap, and the fastest path is pasting it into an AI tool for a few iterations. No one downloads anything sketchy. No one clicks a phishing link. The brief just leaves the building, quietly, on a Tuesday afternoon, headed for a server no one in the room actually controls.
This is the new shape of IP leakage in creative work. It doesn't look like a hack. It looks like a workflow habit.
Samsung's 2023 incident is the reference point everyone in enterprise security already knows. Engineers pasted proprietary semiconductor source code into ChatGPT to debug errors and optimize performance; the material was tied to confidential chip projects.
Creative agencies have the same exposure, except a single design brief usually leaks more at once than a code snippet does. One file can carry the client's name, an unreleased product, the positioning strategy behind it, and the visual identity itself — four categories of confidential material, pasted into a chat window in one motion. A line of source code rarely tells a stranger who the client is.
The paste-and-forget habit. This is the Samsung pattern, relocated to a design studio. A brief, a brand guideline, a packaging comp goes into a public AI tool for feedback or a quick revision, and nobody tracks where it lands or how long it's retained.
The unsecured backend. The leak isn't always the AI "telling" anyone anything. Sometimes the vendor's storage was simply never locked down. Security researchers have repeatedly found AI image-generation platforms with publicly exposed cloud storage buckets containing millions of user-uploaded files — no password, no encryption. The AI didn't do anything wrong in those cases. The infrastructure underneath it just wasn't built to keep contents contained.
The cross-user bug. This is the closest real-world parallel to "Agency A's concept gets shown to Agency B." In 2025, a researcher discovered that
Samsung could ban ChatGPT outright because writing code doesn't require it. Creative work is different, iteration speed is now built into how agencies pitch, revise, and deliver, and clients increasingly expect AI-assisted turnaround. Banning the tools doesn't solve the underlying problem; it just removes the productivity gain while leaving every other vendor's infrastructure exactly as exposed as it was.
The real gap isn't between agencies that use AI and agencies that don't. It's between AI infrastructure that's structurally capable of leaking, because it centralizes raw client data on servers the agency doesn't control, and infrastructure that isn't built that way in the first place.
This is where architecture, not policy, starts doing the work. Infrastructures like
The question every creative director should be asking before the next late-night revision isn't whether a given AI tool is good. It's what happens to the brief after they hit send — and whether the infrastructure on the other end was built to keep it contained.
About Aphanarc