Security and governance at the content layer for Samsung Semiconductor

|
Share

As organizations race to deploy AI agents across their operations, securing and governing unstructured data at the content layer has become the critical foundation for safe enterprise transformation. Samsung Semiconductor is a prime example of how automating compliance and risk management in such a centralized content foundation more effectively protects the enterprise.

Samsung Semiconductor, the industry leader in memory chips and DRAM technology, operates at a scale where a single data leak could disrupt global supply chains. When Evelyn Ngai inherited the company’s GRC operations, she found a system straining under its own complexity: email-based workflows, scattered employee records, manual vendor assessments, and no unified governance framework. 

Inefficiencies were mounting; the risks were real.

By deploying Box AI, Samsung transformed its GRC operations in key ways:

  • Automating the end-to-end vendor security review process with Box Apps, Box AI agents, and metadata extraction
  • Centralizing scattered employee records and automating classification of sensitive PII across file types
  • Leveraging Shield pro to set up data classifications, plus Shield access policies around who can access the data

Governance, risk, and compliance at the content level

Unstructured data, or content, comprises 90% of most companies’ data. This constitutes an enormous amount of sensitive files. In Samsung’s case, some of that content includes things like vendor security assessments, employee-specific files that contain PII, and tax documents — files that require scrupulous security.

Handling security and governance at the content layer ensures that protection is baked directly into the unstructured data itself, rather than relying on fragmented, perimeter-based security to keep everything safe. Governing at the content layer provides complete, contextual awareness of what an AI agent touched, what was inside the file, who classified it, what retention policy applies, and whether that action complied with corporate policy.

That’s why, for Samsung, leaning into Box’s security and governance capabilities better protected content while simultaneously enabling some bold new uses for that content. 

Taking vendor risk assessment from 5 days to 4 hours

One of the most striking examples of Box’s impact at Samsung is in vendor security assessments. Prior to Box, Ngai’s team managed the entire vendor review process over email. Receiving inbound requests, scoring vendors into risk categories, collecting evidence, and conducting manual reviews created a process that took three to five days for each vendor.

Box AI enabled Samsung to automate this workflow end to end. Box’s metadata extraction capabilities and AI agents now analyze vendor documentation automatically, scoring each vendor according to Samsung’s specific risk criteria, even when documents arrive in different formats. “We’re using some of the metadata extractions,” Ngai says, “and looking at the data that the vendors are sending us. Then we have Box Agents behind the scenes to calculate the score.”

Once the first agent completes the risk assessment, it autonomously hands off the task to a second specialized security agent. This agent independently reviews the documentation to flag exceptions against Samsung’s security rubric, demonstrating how agentic workflows enforce compliance without manual intervention and removing the need for manual review of every document. 

The impact has been immediate and measurable. “Originally, it took three to five days to look at each vendor and decide whether or not to use them,” Ngai recalls. “With Box, I’ve been able to save time. Per vendor, it’s only like half a day.”

That’s a 90% reduction in vendor assessment time — a transformation that frees Ngai’s team to focus on higher-value work while maintaining rigorous security standards.

Centralizing employee data and achieving CCPA compliance

Samsung’s governance challenges extended beyond vendor management. With 262,000 employees globally, the company’s employee data was scattered across Workday, network drives, and a variety of other applications, making it nearly impossible to maintain proper retention policies or ensure compliance with regulations like the California Consumer Privacy Act (CCPA).

As Ngai describes it, “Our employee data sat primarily in Workday and network drives — and a variety of other applications.”

By leveraging intelligent AI agents to continuously scan and automatically classify HR documents containing sensitive PII, Samsung establishes an active agentic guardrail that ensures continuous CCPA compliance. Using Box’s metadata and AI search capabilities, Samsung can now automatically apply appropriate retention policies across every file type, everywhere. “Box is able to apply metadata and search different types of files and determine what type of files they are,” says Ngai. “Do they have sensitive data? Do they have PII data?”

For Ngai, the peace of mind that comes with automated, policy-aligned governance is transformative: “The issues are saving time and being in compliance,” he says. “Now I don't worry about the data being leaked, and we're in compliance with the CCPA.”

Building on success: Onboarding, tax document analysis, and beyond

Samsung’s success with Box has inspired plans for broader deployment across the organization. The company is currently beta testing Box Automate for employee onboarding workflows — building a solution that will automatically route documents like W-2 forms to appropriate departments, trigger IT provisioning tasks, and create a seamless onboarding experience at scale.

We're excited about the potential of Box Automate to transform our onboarding process,” Ngai explains. “It will make our onboarding workflow far more scalable by processing documents from Greenhouse and Workday, extracting metadata we choose, and sending it to Box Doc Gen to generate personalized documents for new employees at scale.”

The finance department is also preparing to leverage Box Hubs and Box AI for tax document analysis, enabling the team to analyze five years of tax history and streamline approvals while maintaining proper segregation of duties. And Samsung is testing Box Shield Pro to further strengthen the protection of sensitive and regulated data. Ngai says, “I'm really excited to look at all the other new features Box is going to have, for my team to use across the global organization.”

Security baked into the content layer

Unlike static, bolt-on security tools operating at the network layer, Box provides active agentic security at the content layer. Because Box inherently understands content context, it can dynamically govern what an AI agent is allowed to touch, what actions it can take, and whether those actions comply with corporate policy in real time.

For enterprises like Samsung, that architectural difference means everything. AI-powered automation on a foundation of secure, compliant content is also the basis for scalable AI transformation.

Box’s approach to enterprise security and governance spans the full spectrum of what modern organizations need:

  • Box Shield Pro: An intelligent content security suite with AI-powered classification, threat analysis, and ransomware protection
  • Box Agent’s security and governance: A comprehensive suite of controls purpose-built for the agentic AI era, including prompt injection detection, agent guardrails, external agent activity oversight, audit trails and agent session governance
  • Box Governance: Automated content lifecycle tools that reduce compliance, privacy, and litigation risk through intelligent retention, classification, and defensible deletion
  • Box Zones: Data residency capabilities that ensure content is stored and processed in-region, supporting requirements like GDPR without disrupting collaboration

The result: Enterprises can deploy AI agents with confidence, knowing their content stays protected.

Security at the source

By securing content at its source, organizations can confidently deploy AI agents at scale, knowing their most sensitive data remains protected by MCP guardrails that enforce policy regardless of which AI tools are used.

As organizations race to deploy AI agents across their operations, the risk surface has shifted dramatically. AI agents can read, write, move, delete, and share files at machine speed — and without the right controls in place, that power becomes a liability.

Box has built a comprehensive security and governance platform purpose-built for the enterprise: one that protects content at the content layer, enforces policy regardless of which AI tools your teams use, and gives security and compliance teams the visibility and control they need to say yes to AI adoption — safely.

Learn more about Box's security and governance capabilities at box.com/security.