Caesar AI Atlas
Бухгалтерия
2026-02-15Кейс #49

Партнёр KPMG Australia, как сообщалось, использовал ИИ для списывания на внутреннем тесте по обучению ИИ и был оштрафован на 10 000 австралийских долларов

Описание инцидента

В Австралии партнёр KPMG Australia и зарегистрированный аудитор компаний, как сообщалось, загрузил справочный документ из внутреннего курса обучения ИИ в ИИ-инструмент, чтобы ответить на экзаменационный вопрос, нарушив политику фирмы. KPMG, как сообщалось, выявила эту активность в августе 2025 года и после внутреннего расследования наложила штраф в размере более 10 000 австралийских долларов будущего дохода. Партнёр также, как сообщалось, самостоятельно сообщил о деле в Chartered Accountants ANZ, которая расследует этот случай.

Комплайенс-досье

Практическое управление корпоративными рисками и регламенты

Влияние на бизнес и риски МСБ

The operational impact of this incident—where a senior partner at KPMG Australia was fined $10,000 by the firm's compliance board for copying proprietary training test questions into the public ChatGPT to cheat on an internal assessment—resulted in a severe breach of confidentiality, audit investigations, and loss of leadership credibility. Copying proprietary corporate materials into public AI models leaks intellectual property and violates client confidentiality, exposing the firm to potential contract breaches and legal claims. Regulatory Impact Alignment: Financial audits, transaction tracking, and internal reporting algorithms must comply with Sarbanes-Oxley (SOX) Section 404 and AICPA SOC 2 Type II regulations. Accounting teams must prevent data leakage by isolating sensitive financial logs from public generative AI models.

Главный комплайенс-урок

Employees—even at the executive level—frequently bypass internal confidentiality agreements out of convenience, leading to massive Shadow AI leakage. Corporate training materials and intellectual property must be protected from leakage via third-party AI models. Standard NDAs and IT policies must explicitly address the use of public generative AI. Compliance Audit Standards: For detailed verification audits, this case maps directly under Sarbanes-Oxley Act (SOX) Section 404 & AICPA SOC 2 Type II Safeguards. Systems deploying similar AI features must maintain dynamic security logs and hold systematic compliance records.

Пошаговый план внедрения регламентов

  • 1Strict AI NDA policies: Enforce a strict, legally binding policy prohibiting the input of any proprietary corporate materials or client data into public generative AI interfaces.
  • 2Deploy secure enterprise AI: Provide secure, internally hosted enterprise AI platforms (white-listed environments) that guarantee prompt data is not used for model training.
  • 3Automated network logs audits: Deploy automated network logs auditing to detect and flag unauthorized transfers of corporate documents and files to public AI domains.
  • 4Regular Partner ethics training: Conduct regular compliance training and mandatory security testing for all partners and staff on the secure, ethical use of generative AI.
  • 5Deterministic Audit Trail: Generate complete, cryptographically signed, and chronological audit trails for every automated transaction analysis.
  • 6Vpc Network Isolation: Restrict all corporate ledger evaluations to network-isolated Private Virtual Clouds (VPCs) without public internet hooks.
  • 7Leakage Monitoring: Configure active data loss prevention (DLP) alerts to immediately block the paste or upload of proprietary files to external LLM APIs.

Комментарий эксперта по комплайенсу

Профессиональный комплаенс-анализ инцидента

Cheating on an internal AI test by leaking that test's proprietary questions to public ChatGPT is an absolute compliance failure. Organizations must realize that employees will take shortcuts. Securing your enterprise data requires blocking public chatbot portals and providing secure, sandboxed alternatives.

Терминология и нюансы глоссария ИИ

AI Compliance FAQ

Critical answers regarding AI compliance, auditing, and organizational risks

QWhy was the KPMG partner fined A$10,000?

The senior partner copied proprietary corporate exam questions and confidential training materials directly into the public consumer ChatGPT interface to cheat on an internal assessment, leaking protected firm IP.

QWhat is the compliance risk of copy-pasting text to ChatGPT?

Public generative models save prompt history to retrain neural networks, meaning any pasted data (like trade secrets, internal questions, or patient records) becomes part of OpenAI's global database, breaching NDAs.

QHow can consulting firms block Shadow AI data leaks?

By deploying DNS firewall blocks on corporate devices to restrict public AI domains, whitelisting secure enterprise models that guarantee data opt-outs, and running regular compliance audits.

Участники инцидента

Кто развернул систему

неназванный партнёр KPMG Australia

Кто разработал систему

неизвестные разработчики генеративного ИИ

Кто пострадал

KPMG Australia

Проверяемые источники (3)

Рекомендуемые похожие кейсы

AccountancyCase #50

Microsoft 365 Copilot vulnerability exposes local system files without audit trail logs

A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.

Изучить досье
AccountancyCase #51

Tax Authority uses opaque automated pricing algorithm to issue heavy fines without recourse

An Israeli farmer, Moshe Har Shemesh, reportedly received a fine generated by a Tax Authority software system whose calculation officials were allegedly unable to explain. When the farmer reportedly sought access to the program or its source code to understand the basis for the amount, the authority allegedly refused, citing security concerns and the difficulty of extracting the embedded guidelines. The dispute reportedly later moved into legal proceedings focused on whether code and automated decision rules constitute information subject to public disclosure.

Изучить досье
AccountancyCase #53

Canada Revenue Agency tax chatbot 'Charlie' gives incorrect tax filing guidelines to citizens

Charlie the Chatbot, an AI-powered system deployed by the Canada Revenue Agency (CRA), has reportedly been providing inaccurate or incomplete tax-related information to members of the public. An audit by the Auditor General of Canada reportedly found the chatbot produced correct responses in fewer than half of tested cases. The system has been publicly available across multiple CRA webpages since March 2020 and reportedly used by millions of users.

Изучить досье