Sensitive job docs in a public AI tool: the problem nobody's talking about
CISA's director uploaded sensitive government contracts to the public version of ChatGPT. If a federal cybersecurity chief made that mistake, your team will too.
Between July and August of last year, the acting director of CISA, the US federal agency responsible for cybersecurity, uploaded at least four sensitive government documents to the public version of ChatGPT. DHS systems flagged it. There was an internal review. The documents included contracting material marked for official use only.
If that can happen at a federal cybersecurity agency, it will happen at your company. Probably already has.
What happened
The CISA incident is the clearest recent example of a problem that's mostly invisible in construction: people are pasting job-sensitive material into public AI tools without thinking about where it goes.
What counts as sensitive? Subcontractor agreements with rate schedules. Owner contracts with penalty clauses. RFIs that reference site conditions or access restrictions. Bid breakdowns. Anything with a client's name, address, and dollar figures attached.
Public versions of ChatGPT, Claude, and Gemini use your inputs to improve their models unless you've specifically opted out or you're on a paid business tier with data controls turned on. The free tools that feel private are not private.
Why it matters for your shop
This is less about hackers and more about habit. Someone on your team, an estimator, a PM, an admin, is almost certainly using a free AI tool to draft emails, summarise RFIs, or rewrite contract language. That's not a problem in itself. The problem is doing it by pasting raw documents in without knowing what the tool does with that text.
For a $10M contractor, the exposure isn't usually a data breach. It's more mundane: a client finds out you ran their contract through a public model, you've violated an NDA you signed on page four, and now you're having an awkward conversation you didn't need to have.
The fix doesn't require a new tool. OpenAI, Anthropic, and Google all have paid tiers, Teams or Business, with data controls that turn off training on your inputs. OpenAI's Team plan is $30 per user per month. If you have two or three people using AI regularly for anything touching client documents, that's worth paying for. Alternatively, build a standing rule: no client names, no dollar figures, no addresses in a public tool. Summarise the situation in plain language instead of pasting the document.
Neither of those things is complicated. They just need to be decided and communicated before someone makes the same mistake the head of federal cybersecurity did.
One thing to try this week
Ask whoever on your team uses AI tools the most, even casually, one question: "When you use ChatGPT or Claude, are you on the free version or a paid account?" If they don't know, find out. If it's the free version and they're touching anything client-facing, either upgrade the account or set a clear rule about what goes in and what doesn't. Write it down. Send it in a text or email so there's a record. That's the whole task.
, Austin
Source: https://www.techrepublic.com/article/news-cisa-chatgpt-ai-agent-governance-accountability
We help growing businesses build systems that last.
If this resonates with your current situation, a 30-minute conversation is the fastest way to know if we can help.