Policy & Regulation
CISA acting director uploaded sensitive documents to ChatGPT
Madhu Gottumukkala, the acting head of the U.S. cybersecurity agency CISA, reportedly uploaded sensitive government contracting documents to ChatGPT, triggering an internal review.
On Tuesday, Politico, citing officials, reported that Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA)—the U.S. cybersecurity agency—uploaded sensitive contracting documents marked “for official use only” to ChatGPT. The upload of these sensitive government docs to a public version of a large language model has been characterized as problematic. Because public models train themselves on the information they receive, uploading unclassified but internal government documents potentially allows their contents to be shared with other users of the platform.
Gottumukkala was reportedly granted an exception to use ChatGPT earlier in his tenure as CISA director, a privilege given at a time when other agency employees were prohibited from using the tool. Despite this authorized exception, his document uploads triggered multiple automated security warnings on federal networks. These automated warnings are specifically designed to prevent the theft or inadvertent disclosure of government files. Following these alerts, officials at the Department of Homeland Security, the department housing CISA, initiated an internal review to determine if there was any harm to government security as a result of the uploads.
The document disclosure has occurred alongside broader internal turmoil and scrutiny at the agency. Prior to his appointment at CISA, Gottumukkala served as the chief information officer of South Dakota under then-governor Kristi Noem. Following his appointment to CISA, Gottumukkala reportedly failed a counterintelligence polygraph. The Department of Homeland Security later claimed that this specific polygraph was unsanctioned. Following these events, Gottumukkala suspended six career staff from accessing classified information.
In response to the reports, a CISA spokesperson defended the acting director’s actions to Politico, stating that Gottumukkala’s use of ChatGPT was “short-term and limited.” The Department of Homeland Security continues to review the security implications of the uploads.
Why it matters
This incident highlights the tension between adopting generative AI tools and maintaining strict security protocols for sensitive government data, especially within critical infrastructure agencies. It underscores the operational and security risks that arise when senior leadership bypasses established agency guardrails to utilize public commercial models.