CISA Uploads Sensitive Government Docs to Public ChatGPT, Exposing AI Governance Gaps
What Happened — Between mid‑July and early August 2025, the acting director of CISA uploaded at least four classified or “official‑use‑only” documents to the public version of ChatGPT. The activity was flagged by DHS security tools, prompting an internal review that confirmed the data had been exposed to the public AI service.
Why It Matters for Trust & Control Assurance
- The incident shows how an approved tool can become a vector for data leakage when AI agents are not governed by clear accountability controls.
- Continuous control‑assurance programs need to capture who authorizes AI actions, what data the agent can access, and how that access is logged and reviewed.
- Verisq’s Control‑Mapping capability helps map AI‑specific governance controls to multiple frameworks and provides evidence that those controls are operating as intended.
Who Is Affected – Federal agencies, any organization that permits AI agents to process sensitive data, and AI service providers that host public models.
Recommended Actions
- Define and document AI‑agent accountability roles (owner, steward, reviewer) in your AI governance policy.
- Implement continuous monitoring of AI‑agent activity, including data access logs and automated policy enforcement.
- Map your AI governance controls to the NIST AI RMF and ISO 42001 using a control‑mapping platform to generate audit‑ready evidence.
Source: TechRepublic article
Technical Notes
- No external exploit; the exposure resulted from an insider using an authorized exception to interact with a public AI model.
- Data types included contracting material and other documents marked “official use only.”
Source: same as above