Drooid Logo
Back to story perspectives

Full Breakdown

Sensitive Information Uploaded to ChatGPT by CISA Acting Director

1/29/2026, 2:25:53 AM

Incident Overview

Madhu Gottumukkala, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), inadvertently uploaded sensitive government documents to a public version of ChatGPT last summer. This incident, reported by Politico, involved the uploading of CISA contracting documents marked “for official use only,” which triggered multiple internal cybersecurity alerts aimed at preventing unauthorized disclosures of government material. The uploads occurred shortly after Gottumukkala's appointment, during which he sought special permission to access OpenAI's chatbot, a privilege not granted to most Department of Homeland Security (DHS) staff.

Background and Context

Gottumukkala's access to ChatGPT was an exception within the DHS, which typically restricts its employees to approved AI tools designed to safeguard sensitive information. The documents he uploaded, while not classified, were deemed sensitive enough that their unauthorized sharing could adversely affect individuals' privacy or the operation of essential federal programs. The incident raised concerns about the potential for the information to be accessed by ChatGPT's extensive user base, estimated at 700 million.

Official Statements & Responses

A CISA spokesperson characterized Gottumukkala's use of ChatGPT as “short-term and limited.” Following the incident, DHS initiated an investigation to assess any potential security risks, which could lead to administrative or disciplinary actions against Gottumukkala. Possible repercussions include formal warnings, mandatory retraining, or even suspension or revocation of security clearances.

Criticism & Opposition

Critics have expressed alarm over Gottumukkala's actions, suggesting that his decision to use ChatGPT reflects a disregard for established cybersecurity protocols. Some officials within DHS indicated that it appeared he "forced CISA’s hand" to allow his use of the chatbot, which they viewed as an abuse of privilege. Experts have also warned about the risks associated with using public AI tools, highlighting that uploaded data can be retained or misused.

Conflicting Reports & Gaps

While the documents uploaded by Gottumukkala were marked “for official use only,” there is some ambiguity regarding the exact nature of the information and the potential implications of its exposure. The investigation by DHS is ongoing, and it remains uncertain whether any significant harm to government security has occurred as a result of the incident.

Verbatim Quotes

  • “that using public AI tools poses real risks because uploaded data can be retained, breached, or used to inform responses to other users.” — Cybersecurity Expert

This incident underscores the ongoing challenges faced by government agencies in balancing innovation with the need for stringent cybersecurity measures. As investigations continue, the implications of this breach may prompt a reevaluation of access protocols for AI tools within federal agencies.