AI Business

CISA's ChatGPT Breach Reveals the Real Problem: Nobody Owns What AI Does

A senior government official's unauthorized document uploads exposed a critical flaw in enterprise AI governance—organizations approve tools but fail to assign accountability for each action an AI agent takes.

·5 min read
CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem
CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem

Breaching CISA's systems required no sophisticated attack. Instead, the vulnerability stemmed from a straightforward combination: an employee with legitimate access, a sanctioned tool exception, and a routine administrative function.

From mid-July through early August 2025, acting CISA Director Madhu Gottumukkala allegedly transferred at least four classified government records into the public ChatGPT interface, including procurement documents restricted to official use. The DHS cybersecurity infrastructure detected this activity in early August, triggering an examination. CISA subsequently confirmed that Gottumukkala possessed authorization to access ChatGPT under DHS safeguards and characterized the activity as temporary and restricted in scope.

This incident illuminates a deeper structural challenge embedded in how enterprises manage AI: permitting a technology does not equate to controlling each transaction executed through it. With AI systems now handling agreements, personal information, internal platforms, and correspondence, organizations face an increasingly specific challenge: determining who bears responsibility for each agent and the decisions it makes.

AI agents are exposing an accountability gap

According to EY's Europe West Tech Risk AI Governance, Risks and Compliance Survey 2025, merely 18% of enterprises have established transparent accountability structures for data management involving AI, and only 10% maintain regular procedures for modifying systems that process organizational information. While most organizations maintain documented AI guidelines, very few designate a particular individual responsible for a specific system's handling of a specific dataset on a specific date.

The accountability challenge intensifies substantially when autonomous agents become involved. IBM's Cost of a Data Breach Report 2026 revealed that just 46% of enterprises implement security measures for non-human identities within their AI operations, and among firms experiencing AI-related incidents, 92% operated without adequate AI permission frameworks. An autonomous agent that generates, accesses, and distributes information on someone's behalf represents a non-human identity. The majority of organizations have not determined who maintains control over it.

Consider a typical business scenario. An agent incorrectly forwards a summarized agreement or retrieves a client record beyond its permitted scope. Incident response personnel can typically determine what transpired after the breach occurs. Virtually none can immediately identify the individual who should have prevented it beforehand.

A significant factor contributing to this situation is that AI governance continues to function as an infrequent undertaking—a policy authored once and an assessment executed annually—rather than an ongoing mechanism enforced during each transaction.

EY's Responsible AI Pulse Survey, a follow-up examination of 975 senior executives released in October 2025, demonstrated that merely 12% of participants could properly recognize the suitable safeguards for five typical AI dangers, and senior risk management officers, who theoretically shoulder this accountability, performed marginally beneath the broader sample at 11%. A governance framework that senior management cannot accurately implement functions as mere paperwork rather than a genuine control mechanism.

Leadership and security executives must transition from verifying that an AI governance framework exists to posing a more targeted inquiry. Regarding the most recent action an AI agent performed for the business, who granted that permission, and is that authorization verifiable immediately? Established standards including CMMC, HIPAA, and GDPR already mandate that organizations maintain verifiable permission controls, clear responsibility chains, and documentation demonstrating the handling of restricted materials.

AI agents create complications because they frequently execute numerous operations between the moment a user issues an initial directive and the ultimate conclusion.

This represents a strategic challenge before it becomes a technical one. Boards currently mandate an identified executive champion for cybersecurity, information protection, and third-party administration. Virtually none establish a parallel requirement for AI agents, despite the fact that these agents now interact with the identical restricted materials that these other initiatives are designed to safeguard.

Every AI agent needs a named owner

Resolving this disparity does not necessitate regulatory changes. It demands that boards request what they consistently demand in other domains: identification.

This means the initial action is more straightforward than the majority of AI governance programs suggest. It is not a new infrastructure or a new organizational unit. It is identification. Each AI agent interacting with restricted materials must correspond to a particular individual answerable for its operations, comparable to how an employee identification badge corresponds to a particular supervisor, and this correspondence must be retrievable by a CISO upon request, not reconstructed by an incident response unit following a breach.

This evolution is becoming apparent in market developments. Kiteworks' recently completed acquisition of Bonfy.AI, representing its ninth acquisition within five years, exemplifies how technology providers are shifting toward scrutinizing the transaction itself rather than conducting periodic policy assessments, managing an AI agent as an administered identity that assumes the permission of the individual it represents, rather than treating it as an autonomous operator managing its own credentials.

This does not diminish the substantial effort required. An organization must designate someone answerable for how an agent manages restricted materials, precisely as someone is already answerable for how a human worker manages them. Until that individual appears on the organizational hierarchy, the agent operates without genuine supervision, irrespective of what the policy documentation contains.

Gottumukkala's documents did not require a criminal. They required a legitimate credential and thirty seconds. The majority of organizations harbor this identical vulnerability within their own AI deployments at this moment, and most have not yet investigated whether it exists.