Indian-origin US cyber agency chief accused of sharing sensitive documents on ChatGPT
A new report has revealed that Madhu Gottumukkala, the Indian-origin acting director of the US Cybersecurity and Infrastructure Security Agency (CISA), allegedly shared sensitive contracting...

A new report has revealed that Madhu Gottumukkala, the Indian-origin acting director of the US Cybersecurity and Infrastructure Security Agency (CISA), allegedly shared sensitive contracting and cybersecurity documents with ChatGPT during routine work last summer.
The disclosure has triggered internal reviews and raised concerns about potential exposure of government information to external AI systems.
CISA, America’s lead civilian cyber defence agency, is responsible for protecting federal systems, critical infrastructure and election security — making the reported lapse especially serious.
⭐ What happened?
According to the report, Gottumukkala uploaded:
contracting documents
cybersecurity-related materials
internal work notes
…to ChatGPT while seeking assistance for drafting or improving official text.
Although the documents were not classified, they were reportedly government-sensitive, containing operational details that should not be shared with external platforms that store data on cloud servers.
Officials stressed that no classified national security information was involved, but the incident still violates standard federal data-handling policies.
⭐ Why this matters
CISA is the frontline agency responsible for:
protecting US federal networks
safeguarding elections
responding to cyberattacks
issuing national cyber advisories
Any breach — even accidental — raises questions about:
data hygiene
AI governance inside federal agencies
internal training on emerging technologies
vulnerability of government workflows
The report suggests that the incident was not malicious, but a policy violation triggered by convenience, reflecting the wider challenge governments face as AI tools enter everyday workspaces.
⭐ CISA’s internal response
Sources say the agency has:
initiated internal reviews
reminded staff of AI usage protocols
tightened data-sharing rules
begun updating cyber workforce guidance
A CISA spokesperson said the agency remains committed to safeguarding federal information and is reviewing how AI tools should or should not be used in official capacities.
Gottumukkala has not issued a public statement yet.
⭐ Why using ChatGPT poses risk for government agencies
AI platforms like ChatGPT:
store user inputs on external servers
may use data for model training (depending on settings)
cannot guarantee long-term encryption for sensitive information
introduce third-party exposure risks
US federal agencies are required to handle even unclassified materials with discretion, especially when they relate to critical infrastructure or cybersecurity systems.
The Biden administration has already issued memos restricting AI usage across federal departments due to similar concerns.
⭐ The growing dilemma: AI convenience vs security standards
This incident highlights a broader global issue — government employees increasingly rely on AI tools for:
drafting documents
summarising reports
generating technical notes
improving clarity and speed
But the risks are serious:
✔ data leaks
✔ metadata exposure
✔ internal document misclassification
✔ lack of control once information is uploaded
Governments worldwide are struggling to set clear boundaries, particularly as AI becomes embedded in professional workflows.
