Korean Police Leaked Arrest Warrants and Interrogation Records to ChatGPT and Claude
South Korea's National Police Agency confirmed seven security violations where police officers uploaded sensitive investigative documents — arrest warrant.

TL;DR
- —If exposed externally — or ingested into a generative-AI platform's training pipeline — it doesn't just violate the privacy of the people involved; it can compromise the investigations themselves.
- —The guards — air-gapped networks, security clearances, internal-only systems — are designed to protect against external intrusion, not against the authorized insider who pastes the thing into a chatbot to write a summary.
- —And the data doesn't need to be "leaked" in the dramatic sense to be compromised.
The Leaks According to data obtained by Assemblyman Park Sangwoong from the National Police Agency, there were seven confirmed violations of security regulations where internal police documents were uploaded to external AI platforms from last year through the first half of this year. The leaked investigative documents included up to 44 items such as: Arrest warrant requests and applications
Search and seizure warrants
Suspect interrogation statements
Preliminary investigation (pre-indictment) reports
Communications permits and call records The incidents were spread across regional security investigation divisions: Seoul — 11 documents (arrest warrant applications, details of alleged crimes) to ChatGPT over one month starting January last year
Jeonnam Province — 4 documents (search/seizure warrants, investigative reports) to ChatGPT in March
Gyeonggi Northern — 6 documents (preliminary reports, search/seizure warrant applications) to Claude in May
Daejeon — 7 documents (suspect interrogation reports, interview files) in May
Chungnam Province — 9 documents (email seizure warrants) to ChatGPT
Gyeonggi Southern — 3 documents (communications permit, call records) to both Claude and ChatGPT Why This Is Worse Than It Sounds Investigative materials can contain everything from a target's identity and secured evidence to the status and future direction of an active investigation. If exposed externally — or ingested into a generative-AI platform's training pipeline — it doesn't just violate the privacy of the people involved; it can compromise the investigations themselves. The context sharpens the stakes. The police are expanding AI use in investigative work, and the Police Headquarters' AI-Based Policing Division had distributed directives titled "Precautions When Using Generative AI Services such as ChatGPT" that explicitly warned investigative documents and sensitive personal information must not be entered into such platforms. The leaks happened anyway. "A Collapse in the Police's Security System" The most damning detail: six of the seven violations occurred in the security investigation units that recently took over counterintelligence duties from the National Intelligence Service — the units tasked with investigating national security and industrial secrets. These are the most security-conscious corners of the force, operating on an internal network where even personal information is concealed — and they still leaked warrants and interrogation records to external AI chatbots. "The fact that police officers tasked with protecting national security have transferred sensitive documents such as warrants and suspect statements to external AI platforms is not an individual mistake — it is evidence of a collapse in the police's security system." — Assemblyman Park Sangwoong This is the exact failure mode we've documented repeatedly with AI agents leaking secrets and the broader AI security problem: when a powerful, convenient tool meets a human who ignores the policy, no amount of "don't paste this" guidance survives contact with the workflow. What This Means The Korean case is a microcosm of a global dynamic: the people who hold the most sensitive data are the most tempted to outsource it to AI. The guards — air-gapped networks, security clearances, internal-only systems — are designed to protect against external intrusion, not against the authorized insider who pastes the thing into a chatbot to write a summary. And the data doesn't need to be "leaked" in the dramatic sense to be compromised. Anything pasted into ChatGPT or Claude is processed on external servers, and depending on configuration, can be retained or used for training. For a nation's counterintelligence, that's not a minor slip — it's a category error about what "secure" means. What to Do Assume any sensitive document touched by an AI chatbot is compromised. If you or your organization handle warrants, records, or investigative material, a platform paste means the content is now on servers you don't control.
Use air-gapped or self-hosted models for sensitive work. The sovereign AI path — running capable models locally — is the only way to get AI assistance without shipping data to a third party.
Make AI-use policy practical, not aspirational. A directive saying "don't paste secrets" failed. Organizations need technical controls that block sensitive documents from leaving the environment, not just employee warnings.
Audit AI exposure like you audit network intrusion. Treat pastes into external platforms as data-leakage events requiring the same rigor as a breach.