En Australia, un socio de KPMG Australia y auditor registrado de sociedades habría subido un documento de referencia de un curso interno de formación sobre IA a una herramienta de IA para responder una pregunta de examen, en violación de la política de la firma. KPMG habría detectado la actividad en agosto de 2025 e impuesto una penalización de más de 10.000 dólares australianos de ingresos futuros tras una investigación interna. El socio también habría autoinformado el asunto a Chartered Accountants ANZ, que está investigando el caso.
Gestión práctica de riesgos corporativos y regulaciones
The operational impact of this incident—where a senior partner at KPMG Australia was fined $10,000 by the firm's compliance board for copying proprietary training test questions into the public ChatGPT to cheat on an internal assessment—resulted in a severe breach of confidentiality, audit investigations, and loss of leadership credibility. Copying proprietary corporate materials into public AI models leaks intellectual property and violates client confidentiality, exposing the firm to potential contract breaches and legal claims. Regulatory Impact Alignment: Financial audits, transaction tracking, and internal reporting algorithms must comply with Sarbanes-Oxley (SOX) Section 404 and AICPA SOC 2 Type II regulations. Accounting teams must prevent data leakage by isolating sensitive financial logs from public generative AI models.
Employees—even at the executive level—frequently bypass internal confidentiality agreements out of convenience, leading to massive Shadow AI leakage. Corporate training materials and intellectual property must be protected from leakage via third-party AI models. Standard NDAs and IT policies must explicitly address the use of public generative AI. Compliance Audit Standards: For detailed verification audits, this case maps directly under Sarbanes-Oxley Act (SOX) Section 404 & AICPA SOC 2 Type II Safeguards. Systems deploying similar AI features must maintain dynamic security logs and hold systematic compliance records.
Professional compliance incident analysis
Cheating on an internal AI test by leaking that test's proprietary questions to public ChatGPT is an absolute compliance failure. Organizations must realize that employees will take shortcuts. Securing your enterprise data requires blocking public chatbot portals and providing secure, sandboxed alternatives.
Critical answers regarding AI compliance, auditing, and organizational risks
The senior partner copied proprietary corporate exam questions and confidential training materials directly into the public consumer ChatGPT interface to cheat on an internal assessment, leaking protected firm IP.
Public generative models save prompt history to retrain neural networks, meaning any pasted data (like trade secrets, internal questions, or patient records) becomes part of OpenAI's global database, breaching NDAs.
By deploying DNS firewall blocks on corporate devices to restrict public AI domains, whitelisting secure enterprise models that guarantee data opt-outs, and running regular compliance audits.
A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.
An Israeli farmer, Moshe Har Shemesh, reportedly received a fine generated by a Tax Authority software system whose calculation officials were allegedly unable to explain. When the farmer reportedly sought access to the program or its source code to understand the basis for the amount, the authority allegedly refused, citing security concerns and the difficulty of extracting the embedded guidelines. The dispute reportedly later moved into legal proceedings focused on whether code and automated decision rules constitute information subject to public disclosure.
Charlie the Chatbot, an AI-powered system deployed by the Canada Revenue Agency (CRA), has reportedly been providing inaccurate or incomplete tax-related information to members of the public. An audit by the Auditor General of Canada reportedly found the chatbot produced correct responses in fewer than half of tested cases. The system has been publicly available across multiple CRA webpages since March 2020 and reportedly used by millions of users.