The acting director of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) uploaded sensitive government contracting to a public version of ChatGPT last summer, prompting security alerts and raising questions about the governance of artificial intelligence at the agency responsible for defending federal networks and critical infrastructure.

According to Politico, Madhu Gottumukkala, who has led CISA since May 2025, uploaded at least four documents marked “for official use only” to OpenAI’s ChatGPT platform. This happened between July and early August. The documents contained contract information that was not intended for publication. “Cybersecurity sensors” detected the activity in early August, generating several alerts in the first week.
The incident occurred despite Gottumukkala having personally requested special permission to use ChatGPT shortly after joining CISA. At the time, the artificial intelligence tool was blocked from most DHS employees due to concerns that sensitive information could be kept outside of federal systems.
See also: PwC and Google Cloud: Investments to strengthen defense with AI
CISA Data on ChatGPT: What are the risks?
Data fed into the public version of ChatGPT can be incorporated into training data the model’s and exposed to hundreds of millions of users. Unlike DHS-approved AI tools, which have controls that prevent fed data from leaving federal networks, the public ChatGPT keeps uploaded information on OpenAI’s servers.
The incident highlights systemic failures in the way government agencies, and by extension businesses, manage AI tool exceptions for senior executives, security analysts said.
“FOUO is not classified, but it is still sensitive government information,” said Arjun Chauhan, an executive at Everest Group. “Posting it to a public AI tool creates real exposure: loss of data control, expanded exposure surface, risk of secondary abuse, and breakdown of political boundaries.”
According to Chauhan, this pattern mirrors early incidents at enterprises where employees pasted confidential material into ChatGPT. The critical difference is that there were allegedly controls in place at CISA and the breach occurred via an exception pathway. “This highlights a fundamental governance failure. Exceptions and senior-level access are often where AI controls break down.”
See also: EU: Significant increase in reports of GDPR violations

Federal agencies now have AI policies and AI management teams, but the gap appears to be in execution rather than intent, according to Chauhan. Safe, approved AI tools are not always the default or most usable option, and enforcement varies by role and hierarchy.
Sunil Varkey, a consultant at Beagle Security, said the incident reflects a broader organizational challenge. “Leadership teams may view these tools as positive for learning, productivity, and improved communication, which inadvertently normalizes their use,” he said. “As a result, such platforms have quickly become de facto productivity apps without being treated with the governance typically applied to enterprise systems that handle sensitive information.” The tension between convenience and security often leads to such incidents, Varkey added.
Because “official use only” data is not officially classified, users often underestimate the operational impact or reputational damage. Jaishiv Prakash, principal analyst at Gartner, said the biggest risk when officials upload documents marked FOUO to public AI platforms is the loss of control over the data. “You have no visibility into how long it’s kept, whether it can ever be deleted, or whether it’s exposed during legal proceedings or discovery.”
Prakash stressed that organizations should provide employees with licensed, controlled AI platforms with agreed-upon data residency from the vendor, strict guarantees of no-training of AI models, and minimal data retention.
“Without this, people will continue to turn to public AI tools out of convenience, putting sensitive information at risk“.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Questioning leadership credibility
The uploads prompted an internal DHS review that included the department's then-acting general counsel Joseph Mazzara and chief intelligence officer Antoine McCord, along with CISA chief intelligence officer Robert Costello and chief counsel Spencer Fisher.
See also: Chrome extensions have stolen conversations from ChatGPT and DeepSeek
The outcome has not been disclosed. According to the report, CISA spokeswoman Marci McCarthy confirmed that Gottumukkala received approval to use ChatGPT under DHS safeguards and described the use as “short-term and limited.” She said that he last used the tool in mid-July 2025 under an approved temporary exemption and that CISA’s default policy blocks access to ChatGPT unless an exemption is granted.
The fact that automated alerts appeared shows that controls can detect abuse, but the incident occurring at a leadership level raises questions of accountability.
“Because this is about the head of the cybersecurity organization, the impact is primarily reputational,” Chauhan said. “Leaders set the code of conduct. Deviations undermine the culture of compliance and weaken credibility when advising other organizations and critical infrastructure operators.”
Noem, now DHS secretary. CISA did not immediately respond to a request for comment.
