TL;DR
More than 200 conversations with Anthropic’s Claude were found sitting in public search results, surfaced by Reddit users running site-specific searches. The chats included CVs with names and contact details, an unpublished blog post about a corporate cloud security project, and healthcare research containing transcripts of private conversations. Search indexing was removed over the weekend, but copies had already been saved and circulated.
Every affected conversation came from someone using Claude’s share feature. That link, Anthropic told the BBC, is “not guessable or discoverable unless people choose to share them themselves” — accurate as far as it goes. The gap is what happens next: the share dialogue warns that “anyone with the link” can view the contents, but does not say the link may be crawled and listed by Google.
This is now a recurring pattern rather than a one-off. OpenAI hit an almost identical problem with ChatGPT logs last year and subsequently made shared conversations harder to reach. Grok, X’s chatbot, exposed hundreds of thousands of logs through search over the same period. Three major assistants, the same failure, the same fix applied afterwards.
Google’s position is that it does not decide what goes public: site owners control crawling and indexing, and Google respects those directives. Removal therefore had to be initiated by Anthropic, which is consistent with how quickly the links vanished.
The UK relevance is direct. Where an employee shares a conversation containing customer names, patient information or commercial data, the sharing organisation is the controller — not the chatbot vendor. Any resulting exposure is a personal data breach on the organisation’s side, with the ICO reporting duties that follow. The Resultsense corpus carried a survey yesterday finding half of UK founders had fed sensitive data into public AI tools inside a single month; this incident shows what one careless share button does to that data.
Looking Forward
Practical mitigation is unglamorous: treat share links as publication, not as sending a file to a colleague. Businesses running staff assistants should check whether shared-conversation URLs are reachable without authentication, and set an internal rule that anything containing client or personal data is never shared by link. Vendors, for their part, have now had three chances to make that warning explicit at the point of sharing.