CISA Acting Director Sparks Security Alert by Uploading Sensitive Documents to ChatGPT, Raising AI Governance Concerns

January 28, 2026
CISA Acting Director Sparks Security Alert by Uploading Sensitive Documents to ChatGPT, Raising AI Governance Concerns
  • The acting director of the Cybersecurity and Infrastructure Security Agency uploaded sensitive government documents marked for official use only to OpenAI’s public ChatGPT last summer, triggering automated security alerts detected by DHS sensors in August.

  • The incident highlights tensions over federal staff using AI chat tools and safeguarding sensitive information, prompting policy considerations and cautions for public sector use.

  • DHS and Politico report that the uploads involved non-classified but sensitive contracting documents, raising concerns about data exposure when using consumer AI services within federal operations.

  • Industry responses call for a multi-layered AI governance approach, including data loss prevention, network monitoring, zero-trust principles, and robust data classification to curb unauthorized AI use.

  • The broader political context includes stalled confirmation of Sean Plankey as CISA director and ongoing controversy surrounding Gottumukkala’s leadership.

  • The story, reported by Politico citing DHS officials, notes that permanent leadership at CISA remains pending confirmation.

  • Disciplinary actions could range from retraining to suspension or loss of security clearance, depending on investigation findings.

  • Internal DHS reviews are examining potential harm to government security, with possible actions from warnings to revocation of clearances.

  • Access to the public ChatGPT app was blocked for other DHS employees at the time, with details kept limited due to the incident’s sensitivity.

  • Regulatory gaps in federal AI governance are highlighted, including incomplete enforcement of OMB guidance and limited applicability of FISMA to AI, with legislative action proceeding slowly.

  • The incident is situated within ongoing debates about AI safety, data privacy, and policy implications for government use of AI tools.

  • The piece, framed around a security incident involving a government official and AI data practices, is presented in a tech-focused, sponsor-influenced layout but centers on the core story.

Summary based on 9 sources


Get a daily email with more AI stories

More Stories