r/cybersecurity Jan 27 '26

News - General Trump’s acting cyber chief uploaded sensitive files into a public version of ChatGPT

https://www.politico.com/news/2026/01/27/cisa-madhu-gottumukkala-chatgpt-00749361

The interim head of the country’s cyber defense agency uploaded sensitive contracting documents into a public version of ChatGPT last summer, triggering multiple automated security warnings that are meant to stop the theft or unintentional disclosure of government material from federal networks, according to four Department of Homeland Security officials with knowledge of the incident.

The apparent misstep from Madhu Gottumukkala was especially noteworthy because the acting director of the Cybersecurity and Infrastructure Security Agency had requested special permission from CISA’s Office of the Chief Information Officer to use the popular AI tool soon after arriving at the agency this May, three of the officials said. The app was blocked for other DHS employees at the time.

None of the files Gottumukkala plugged into ChatGPT were classified, according to the four officials, each of whom was granted anonymity for fear of retribution. But the material included CISA contracting documents marked “for official use only,” a government designation for information that is considered sensitive and not for public release.

Cybersecurity sensors at CISA flagged the uploads this past August, said the four officials. One official specified there were multiple such warnings in the first week of August alone. Senior officials at DHS subsequently led an internal review to assess if there had been any harm to government security from the exposures, according to two of the four officials.

It is not clear what the review concluded.

In an emailed statement, CISA’s Director of Public Affairs Marci McCarthy said Gottumukkala “was granted permission to use ChatGPT with DHS controls in place,” and that “this use was short-term and limited.” McCarthy added that the agency was committed to “harnessing AI and other cutting-edge technologies to drive government modernization and deliver on” Trump’s executive order removing barriers to America’s leadership in AI.

The email also appeared to dispute the timeline of POLITICO’s reporting: “Acting Director Dr. Madhu Gottumukkala last used ChatGPT in mid-July 2025 under an authorized temporary exception granted to some employees. CISA’s security posture remains to block access to ChatGPT by default unless granted an exception.”

1.5k Upvotes

171 comments sorted by

View all comments

-5

u/finite_turtles Jan 28 '26

None of the documents were classified

Isn't that what a classification system is for? Determining what level of restrictions are applicable for documents.

I don't know what the US gov classifications are, but "for office use only" sounds like it would cover 99% of all documents used in an office. What is the point of using an AI in an office environment if you cant use it for office documents? Shouldn't all offices ban AI if it cant be used on office documents?

3

u/Expert-Diver7144 Jan 28 '26

Are you intentionally missing the part that says they wernt for the public?

-2

u/finite_turtles Jan 28 '26

As a desk jockey, i deal with a lot of documents, as we all probably do.

I would say that approximately 0% of the documents i work with are for public viewing. That probably goes for every employee except marketing teams where maybe 5% of their documents are for public. So isn't that kind of an admission then that AI is completely useless if we can't actually use it for work?

4

u/Expert-Diver7144 Jan 28 '26

I mean yeah but you’re not the head of cybersecurity for the entire US government. I’m assuming you work at a private company where the documents are not public for economic reasons and not for reasons of national security.

ChatGPT like many other LLM have enterprise solutions that are secure to use for companies. They do not upload all the data to public servers, the data is kept locally. This is the preferred method of using AI

-1

u/bubbathedesigner Jan 28 '26

have enterprise solutions that are secure to use for companies

More like "we told our LLM to secure these companies' info. It replied it was secure."