CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem Acting CISA Director Madhu Gottumukkala reportedly uploaded at least four sensitive government documents, including contracting material marked for official use only, to the public version of ChatGPT between mid-July and early August 2025, according to a Senate letter from Sen. Chuck Grassley. DHS cybersecurity systems flagged the activity in early August, prompting an internal review; CISA said Gottumukkala had permission to use ChatGPT with DHS controls in place and described the use as short-term and limited. The incident highlights an AI governance gap: EY's Europe West Tech Risk AI Governance, Risks and Compliance Survey 2025 found only 18% of organizations have clearly defined data governance responsibilities for AI, and IBM's Cost of a Data Breach Report 2026 found 92% of organizations that suffered an AI-related breach lacked proper AI access controls. No attacker needed to break through CISA’s defenses. The reported exposure began with an authorized user, an approved exception, and an ordinary work task. Between mid-July and early August 2025, acting CISA Director Madhu Gottumukkala reportedly uploaded at least four sensitive government documents to the public version of ChatGPT https://www.grassley.senate.gov/imo/media/doc/grassley to cisa - chatgpt.pdf , including contracting material marked for official use only. DHS cybersecurity systems flagged the activity in early August, prompting an internal review. CISA later said Gottumukkala had permission to use ChatGPT with DHS controls in place and described that use as short-term and limited. The episode exposes a harder problem lurking beneath enterprise AI policies: approving a tool is not the same as governing every action performed through it. As AI agents gain access to contracts, customer records, internal systems, and communications, organizations increasingly need to answer a much narrower question: Who is accountable for each agent and the authority it exercises? AI agents are exposing an accountability gap EY’s Europe West Tech Risk AI Governance, Risks and Compliance Survey 2025 https://www.ey.com/content/dam/ey-unified-site/ey-com/pt-pt/services/technology-risk/document/ey ew-tech-risk-ai-grc-survey-2025.pdf found that only 18% of organizations have clearly defined data governance responsibilities for AI, and just 10% have systematic processes for updating the models making decisions with enterprise data. Most companies can point to an AI policy. Few can point to a specific person accountable for what a particular system did with a particular piece of data on a particular day. The accountability question gets harder, not easier, once agents enter the picture. IBM’s Cost of a Data Breach Report 2026 https://www.ibm.com/reports/data-breach found that only 46% of organizations secure non-human identities in their AI workflows, and among organizations that suffered an AI-related breach, 92% lacked proper AI access controls. An AI agent that drafts, retrieves, and sends data on a person’s behalf is a non-human identity. Most enterprises have not decided who owns it. Picture what that looks like on an ordinary Tuesday. An agent summarizes a contract and emails it to the wrong recipient or pulls a customer file it was never authorized to touch. Security teams can usually reconstruct what happened after the fact. Almost none can name, on the spot, the person who was supposed to answer for it before it happened. Part of the reason is that AI governance https://www.techrepublic.com/article/news-sas-agentic-ai-governance-tools/ still gets treated as a periodic exercise, a policy someone writes once and an audit someone runs once a year, rather than a control that must hold for every individual exchange. EY’s Responsible AI Pulse Survey https://www.ey.com/en gl/newsroom/2025/10/ey-survey-companies-advancing-responsible-ai-governance-linked-to-better-business-outcomes , a second-phase poll of 975 C-suite leaders published in October 2025, found that only 12% of respondents could correctly identify the appropriate controls against five common AI risks, and chief risk officers, the people most likely to own this problem on paper, scored slightly below the group average, at 11%. A policy that leadership itself cannot apply correctly is not a control. It is a document. Boards and CISOs need to stop asking whether an AI policy exists and start asking a narrower question. For the last exchange an AI agent made on the organization’s behalf, who authorized it, and can that authorization be reconstructed on demand? Frameworks such as CMMC, HIPAA, and GDPR already push organizations toward demonstrable access controls, accountability, and records that show how sensitive information is handled. AI agents https://www.techrepublic.com/article/news-google-gemini-enterprise-legal-ai-agents/ complicate that requirement because they can take multiple actions between a user’s initial instruction and the eventual outcome. This is a strategy problem before it is a technology problem. Boards already require a named executive sponsor for cybersecurity, privacy, and vendor risk. Almost none have an equivalent requirement for AI agents, even though those agents now touch the same sensitive data those other programs exist to protect. Every AI agent needs a named owner Closing that gap does not require new legislation. It requires boards to ask for something they already ask for everywhere else: a name. That means the practical first step is smaller than most AI governance initiatives make it sound. It is not a new platform or a new committee. It is a name. Every AI agent with access to sensitive data should map to a specific person accountable for its actions, the way an employee badge maps to a specific manager, and that mapping should be something a CISO can produce on request, not something an incident response team must reconstruct after the fact. That shift is starting to show up in how the market is building. Kiteworks’ just-announced acquisition of Bonfy.AI https://www.kiteworks.com/company/press-releases/kiteworks-acquires-bonfy-ai/ , its eighth acquisition in under five years, is one recent example of vendors moving toward evaluating the exchange itself rather than reviewing policy on a schedule, treating an AI agent as a governed identity that inherits the authorization of the person it acts for, never as an independent actor operating on its own account. None of that takes away the hard work. Someone within the organization must be held accountable for how an agent handles sensitive data, just as someone is already held accountable for how a human employee handles it. Until that person is on an org chart, the agent is effectively unsupervised, regardless of what the policy binder says. Gottumukkala’s documents did not need a hacker. They needed an authorized login and thirty seconds. Most enterprises have that same gap sitting within their own AI programs right now, and most have not yet looked for it. Related reading: For more on the security risks created when AI agents inherit excessive access, read TechRepublic’s AI Agents Are Creating a New Enterprise Security Gap https://www.techrepublic.com/article/news-ai-agents-enterprise-security-gap/ .