How a Top US Cybersecurity Official Accidentally Shared Sensitive Files with ChatGPT

The head of America’s top cybersecurity agency is facing uncomfortable questions after an internal incident involving the public version of ChatGPT. Madhu Gottumukkala, Acting Director of the Cybersecurity and Infrastructure Security Agency (CISA), reportedly uploaded sensitive government documents to the widely available AI chatbot—an action that triggered multiple automated security alerts inside federal systems.

According to details shared by several Department of Homeland Security officials, the uploads set off monitoring tools designed to detect potential data loss and stop government materials from being exposed or removed from secure networks. The alerts reportedly fired repeatedly, with activity concentrated around the first week of August.

While the documents involved were not classified, they were described as contract materials labeled “For Official Use Only.” That marking matters: it typically signals information that isn’t meant for public release and may include operational details, vendor data, internal processes, or other sensitive content that could create risk if shared outside approved channels.

The situation stands out because of how public AI tools handle user inputs. When someone uploads text or documents into a consumer-facing chatbot, the data is transmitted outside government networks to the service provider. Depending on the platform’s policies and configurations, that information can potentially be retained, reviewed for safety, or used to improve system performance. Even if the likelihood of broad exposure is low, the act of moving sensitive government content into a public AI service is exactly the kind of behavior federal cybersecurity controls are designed to prevent.

That contrasts sharply with government-approved AI systems built to keep information inside protected environments. Department-sanctioned tools are typically configured so employee prompts and uploaded content do not leave federal networks, reducing the chance of accidental disclosure and helping agencies comply with security and records policies.

Reports also indicate Gottumukkala obtained a special exemption to access ChatGPT, requesting permission from CISA’s Chief Information Officer shortly after taking office in May. At that point, access to the app was restricted for regular DHS employees, reflecting broader government caution about using public generative AI tools with sensitive work.

CISA has attempted to calm concerns. Agency spokesperson Marci McCarthy said the usage was approved, limited in duration, and conducted with security precautions in place. She also disputed part of the timeline, saying the last use occurred in mid-July—though officials have suggested the automated sensors were still logging uploads in early August. That discrepancy is now one of the key issues investigators will likely try to resolve.

An internal review is underway to determine whether any real harm occurred, including whether information was exposed beyond authorized systems or whether the alerts indicate a broader breakdown in policy compliance. The episode is also drawing attention because it comes amid other reported controversies involving Gottumukkala, adding fuel to concerns about leadership judgment at an agency whose mission is to protect critical infrastructure and strengthen national cyber defenses.

More broadly, the incident highlights a growing challenge across government and industry: generative AI tools are powerful and convenient, but they can become a serious data security risk when workers paste, upload, or summarize sensitive material in systems not designed for confidential use. As agencies race to adopt AI, this case is likely to intensify calls for clearer rules, stronger enforcement, and safer internal alternatives that let employees benefit from AI without putting protected information at risk.