The acting head of America’s top civilian cybersecurity agency uploaded sensitive government contracting documents into a public version of ChatGPT, setting off internal alerts and a formal damage assessment, according to accounts from multiple officials. Madhu Gottumukkala, the interim director of the Cybersecurity and Infrastructure Security Agency, entered materials marked “for official use only” into the AI system, despite clear restrictions barring their public disclosure.
The documents were not classified, but officials said the markings explicitly limited their circulation to authorized government use. CISA’s own cybersecurity monitoring tools detected the uploads several times, prompting warnings inside the agency and escalating the matter to the Department of Homeland Security for review. The episode has unsettled career staff within an agency charged with protecting federal networks from foreign espionage and cyber intrusion.
According to one DHS official familiar with the situation, Gottumukkala pushed aggressively for access to ChatGPT and then used it in ways that violated internal norms. The official described the episode as forcing the agency’s hand on approving the tool and then misusing it, a characterization that reflects broader unease among staff about leadership practices and accountability at the top of the organization.
CISA leadership later defended the incident by saying the use of ChatGPT had been authorized, limited in scope, and temporary. The agency cited broader policy direction from the Trump administration aimed at accelerating US leadership in artificial intelligence by reducing bureaucratic barriers. Critics inside and outside government, however, say the incident underscores a widening gap between ambitious AI adoption and the basic security discipline expected from those overseeing the nation’s cyber defenses.
The controversy arrives at a sensitive moment, as federal agencies rush to integrate generative AI tools while struggling to define clear boundaries for their use. For an agency tasked with guarding against sophisticated threats from adversarial states, the episode has become an uncomfortable illustration of how internal missteps, rather than external hackers, can sometimes pose the most immediate risk.

