The acting director of the Cybersecurity and Infrastructure Security Agency has prompted an internal security review after sensitive federal contracting documents labelled "for official use only" were uploaded into the public version of ChatGPT, multiple news outlets report. According to Politico and subsequent coverage, the transfers took place in mid-July through early August 2025, weeks after Madhu Gottumukkala became acting director in May. Automated monitoring within the Department of Homeland Security detected the activity and generated alerts that escalated to senior DHS cybersecurity teams. (Sources: Times of India, Cybernews)

CISA has acknowledged the event but sought to frame it as performed under constrained authorisation. A CISA spokesperson, Marci McCarthy, told reporters the use of ChatGPT occurred "with DHS controls in place" and under a "short-term and limited" exception, and CISA's logs show Gottumukkala's last recorded access to the public platform in mid-July 2025. Nevertheless, agency sensors repeatedly flagged the uploads as potential data exfiltration incidents, prompting an ordered damage assessment consistent with DHS policy when sensitive information is moved outside secure networks. (Sources: Times of India, Cybernews, Financial Express)

Government officials interviewed by press outlets described a rapid internal response that included meetings between Gottumukkala and senior agency advisers, and the opening of a formal review to determine whether the FOUO material had been compromised or required personnel action. Insiders speaking on condition of anonymity told The Independent that CISA's chief information officer and chief counsel were present in mid-summer discussions about proper handling of FOUO-designated records. The findings of that review have not been released publicly. (Sources: Lead LinkedIn item, Times of India)

Critics inside the agency have voiced stronger condemnations, with at least one current official quoted by multiple outlets alleging that the acting director "forced CISA's hand" to secure the exemption and then "abused it." That account contrasts with CISA's public description of the access as controlled, underscoring internal divisions over leadership decisions at a time when the agency is confronting both budgetary pressures and morale challenges. (Sources: Lead LinkedIn item, NDTV)

The episode highlights broader risks as federal bodies experiment with generative AI. Academic research and reporting have repeatedly warned that public AI platforms can retain user inputs and use them to refine models, potentially exposing sensitive operational details unless inputs are routed through enterprise or government-controlled instances with strict data governance. For agencies responsible for defending against state-sponsored cyber threats, even unclassified but operationally sensitive contracting and architecture information can yield actionable insights for adversaries. (Sources: Lead LinkedIn item, Cybernews)

Gottumukkala's ascent to the acting directorship and his résumé were widely reported in profiles that note a background in state government and private-sector IT leadership. He assumed deputy director duties in April 2025 and became acting director later that month; biographical summaries state he previously served in senior technology posts in South Dakota and holds advanced degrees in engineering, computer science and information systems. Recent reporting also recounts separate internal controversies during his tenure, including a disputed polygraph process and personnel actions that have already prompted additional inquiries. (Sources: Times of India profile, Wikipedia, Financial Express)

The incident is likely to attract attention from Congressional committees overseeing homeland security and federal cybersecurity practices, where bipartisan concern about AI adoption and data controls has grown. Lawmakers have signalled an appetite for tighter rules governing when and how public generative AI tools may be used with government information, and this case could be cited as an example reinforcing calls for stricter protocols, real-time monitoring and clearer accountability. (Sources: Lead LinkedIn item, Times of India, Financial Express)

Source Reference Map

Inspired by headline at: [1]

Sources by paragraph:

Source: Noah Wire Services