A privacy vulnerability surfaced with Anthropic’s Claude: private conversations and "Artifacts" became searchable on Google. The incident pits user-driven sharing against web indexing in the AI era.
The Mechanism of the Exposure
Reddit users uncovered the breach using Google operators like site:claude.ai/share, which sidestepped the "share chat" feature’s intended privacy. Claude warns that "anyone with the link can view," but the feature is meant for targeted sharing, not global visibility.
Unlike Google Docs, which blocks crawlers by default, Claude’s shared URLs were indexed by Google, letting anyone stumble upon sensitive information via ordinary searches.
Sensitive Data and Content at Risk
Outlets such as Futurism and TechCrunch reported that the indexed results contained:
- Personal Identifiable Information (PII): names and phone numbers of primary-school-aged children.
- Medical Records: detailed clinical-trial results and real patient reports.
- Corporate Intelligence: documents marked "internal use only" and employee performance reviews.
- Technical Assets: code snippets and work notes from Claude’s "Artifacts" feature.
Some exposed chats also slipped past Anthropic’s safety filters, showing sexually explicit content and raising further moderation concerns.
Anthropic and Google Respond
Anthropic defended its architecture, saying it does not share chat directories or sitemaps with search engines. spokeswoman Amie Rotherham explained that share links appear in search results only after users post them on external, crawlable platforms, and that the URLs are "not guessable." Once a link is "out in the wild," it can be archived by third parties.
Google’s spokesperson Ned Adriance echoed that search engines index whatever they can find unless site owners explicitly block crawling. Tests suggest the exposure has been removed from Google’s index, but a similar incident last year also indexed hundreds of Claude chats.
Why This Matters for AI Users
Developers and founders integrating LLMs must treat "shared links" as public, not secure. As AI tools shift from personal assistants to enterprise collaborators, the line between public web content and private data needs technical enforcement, not just a tooltip warning.
Key Takeaways
- Audit Your Settings: Go to Settings → Privacy → Shared Chats in Claude and revoke any active public links.
- Treat Share Links as Public: Assume any AI-generated link can be indexed by search engines.
- Enterprise Caution: Enforce strict policies around "share" features to prevent accidental leaks of proprietary code or sensitive PII.
Anthropic’s Claude AI platform inadvertently exposed private chats and “Artifacts” after Google indexed its share-link URLs, making sensitive conversations searchable. Reddit users spotted the leak with a site-specific Google query, exposing personal, medical, and corporate data.
How the Exposure Happened
Claude’s "share chat" feature generates a URL that the interface warns can be viewed by anyone who possesses it. The intent is to hand the link to a colleague, not broadcast it. Because the URLs sit under the claude.ai/share domain, posting the link on any publicly crawlable site—forums, social media, or a Reddit comment—lets Google’s crawler follow it.
Reddit users discovered the issue by searching site:claude.ai/share on Google, which returned conversations meant to stay private. Unlike Google Docs, whose shared links are protected from indexing by default, Claude’s links lacked that safeguard, allowing the search engine to catalog them.
What Was Exposed
Multiple outlets reported that indexed results contained:
- Personal Identifiable Information (PII): names and phone numbers of primary-school-aged children.
- Medical Records: detailed clinical-trial data and real patient reports.
- Corporate Intelligence: documents marked "internal use only," employee performance reviews, and other proprietary information.
- Technical Assets: code snippets, work notes, and other artifacts generated within Claude’s "Artifacts" feature.
In a few cases, publicly visible chats also included content that slipped past Anthropic’s safety filters, producing sexually explicit material.
Anthropic’s Response
Anthropic утверждает, что не публикует каталоги чатов или карты сайта для поисковых систем. Представитель компании пояснил, что ссылки на общие чаты появляются в результатах поиска только после того, как пользователь разместит URL на внешней, доступной для сканирования платформе, и подчеркнул, что эти URL «невозможно угадать». Как только ссылка намеренно публикуется в сети, компания не может контролировать архивацию сторонними сервисами.
Позиция Google
Google подтвердил, что не решает, какой контент является публичным; поисковик индексирует то, что может найти, если только сайт явно не запрещает сканирование. Компания заявила, что соблюдает такие директивы, как robots.txt или метатеги, запрашивающие исключение из индекса. Предварительные тесты после инцидента показывают, что раскрытые URL были удалены из индекса Google, хотя компания не подтвердила окончательное решение проблемы.
Почему это важно для пользователей ИИ
Этот эпизод высвечивает более широкий риск по мере того, как большие языковые модели переходят из разряда персональных помощников в корпоративные рабочие процессы. «Ссылка для совместного доступа» — это механизм удобства, который может собрать любой поисковый робот. Для организаций, работающих с регулируемыми данными — медицинскими картами, оценками сотрудников, проприетарным кодом — предположение о том, что ссылка безопасна, так как она «просто передана по ссылке», может привести к дорогостоящим утечкам.
Контраргумент: ограничения платформ
Anthropic утверждает, что ответственность лежит на пользователях, публикующих ссылку. Платформа предупреждает, что любой, у кого есть URL, может просмотреть контент, и сама не выставляет URL в публичных каталогах. Google возражает, что не может контролировать каждую частную ссылку, которая всплывает в сети; его роль заключается в том, чтобы соблюдать запросы владельцев сайтов не отображать их в результатах поиска.
Обе позиции технически верны, однако они оставляют пробел: пользовательский интерфейс не делает риск индексации очевидным, а платформа не применяет автоматически директивы «no-index» к общим страницам. Таким образом, бремя предотвращения случайного публичного раскрытия ложится на пользователей, которые могут не осознавать, насколько легко найти ссылку с помощью простого поискового запроса.
За чем следить дальше
Практические шаги для пользователей
- Проведите аудит активных ссылок: Откройте настройки Claude, перейдите в раздел конфиденциальности для общих чатов и отозвите все URL, которые вам больше не нужны.
- Относитесь к каждой ссылке для совместного доступа как к публичной: Исходите из того, что как только ссылка опубликована где-либо в интернете, она может быть проиндексирована, если только это не заблокировано явно.
- Корпоративный контроль: Внедрите инструменты мониторинга, которые помечают создание ссылок, содержащих такие ключевые слова, как "PII", "confidential" или "internal", и внедрите процессы согласования, прежде чем такие ссылки покинут корпоративную сеть.
Инцидент с Claude напоминает нам о том, что удобство мгновенного обмена данными может стать источником рисков, когда веб-среда воспринимает такие ссылки как обычные страницы. Пока платформы не начнут автоматически защищать общие URL, пользователи должны сохранять бдительность.
