The acting head of the United States’ top cyber-defence body is facing scrutiny after sensitive government documents were reportedly uploaded to a public version of ChatGPT, triggering internal security alerts and a damage assessment by the Department of Homeland Security (DHS).
According to a Politico investigation, Madhu Gottumukkala, interim director of the Cybersecurity and Infrastructure Security Agency (CISA), used special permission to access the AI platform last summer, despite its general prohibition for DHS staff. He is said to have entered contracting documents labelled “For Official Use Only” — material that is not classified but is considered sensitive and restricted from public disclosure.
Officials familiar with the matter said CISA’s cybersecurity monitoring systems detected the uploads in early August, prompting DHS to launch an internal review to evaluate any potential exposure or harm. The outcome of that assessment has not been publicly disclosed.
The episode has drawn attention because information entered into public versions of ChatGPT can be retained by developer OpenAI, unlike DHS-approved AI systems that are configured to keep data within federal networks. CISA, however, said Gottumukkala’s access was granted with controls in place and described his use of the tool as limited and temporary.
Gottumukkala has served in an acting role since May, pending Senate confirmation of nominee Sean Plankey. The ChatGPT incident adds to a series of controversies during his tenure, including reports that he failed a counterintelligence polygraph test last year, a characterisation he rejected during recent congressional testimony.
The disclosure comes as the Trump administration pushes rapid AI adoption across federal agencies, loosening regulatory constraints and advancing an “AI-first” strategy within the Pentagon, even as concerns grow over data security and oversight.
NEW – Head of the U.S. cyber defense agency CISA, Madhu Gottumukkala, uploaded sensitive contracting documents into a public version of ChatGPT, triggering a DHS security review — Politico pic.twitter.com/sBFegSiiPT
— Disclose.tv (@disclosetv) January 28, 2026