Top U.S. Cyber Defense Official Uploads Sensitive Documents to ChatGPT, DHS Investigation

By Sam Massey

By: Sam Massey

South Dakota has made tremendous investments to improve our IT  infrastructure. Our new BIT Commissioner Dr. Madhu Gottumukkala is the  right person to carry that momentum forward. He will focus on putting

Madhu Gottumukkala, a technocrat appointed in 2025 to lead the United States’ top cyber defense agency, has come under scrutiny after uploading internal government files into a public version of ChatGPT. The incident triggered automated security alerts within the Department of Homeland Security and prompted an internal review of his actions.

Gottumukkala is the acting director of the Cybersecurity and Infrastructure Security Agency, the federal body responsible for protecting government networks and critical infrastructure from cyber threats. According to reporting, the documents uploaded were marked “for official use only,” a designation applied to sensitive but unclassified material. The files reportedly related to internal contracting and operational matters and were not intended for external dissemination.

The uploads were detected after CISA’s own monitoring systems flagged anomalous activity. While Gottumukkala reportedly had limited authorization to experiment with generative AI tools, most DHS employees are prohibited from using public AI systems like ChatGPT for work purposes. Officials have stated that no classified information was shared and that there is no evidence of malicious intent.

Join Gambit’s Newsletter Here

The episode has raised questions about internal safeguards and judgment at the highest levels of federal cybersecurity leadership. CISA has been among the agencies most vocal about warning public and private institutions against improper data handling and uncontrolled AI use. That the agency’s top official would personally trigger internal alerts by feeding sensitive material into a public AI system undercuts those warnings and exposes a gap between policy and practice.

Public reaction has focused on two related issues. One is institutional readiness for generative AI, particularly whether federal agencies have coherent, enforceable rules governing its use by senior officials. The other is accountability, specifically how mistakes are handled when they originate from leadership rather than rank-and-file employees. What stands out most is not the use of artificial intelligence itself, but the apparent lack of judgment surrounding it. In an administration that has prioritized loyalty and technocratic experimentation over institutional discipline, incidents like this invite scrutiny over whether those placed in charge are actually qualified for the responsibilities they hold.

This article was written by Sam Massey.

Discover more from Gambit Forecaster

Subscribe now to keep reading and get access to the full archive.

Continue reading