Hundreds of conversations with Anthropic's popular artificial intelligence (AI) chatbot Claude were discovered to be publicly accessible through Google and other search engines, raising significant privacy concerns for enterprise users who may have shared work-related information.
According to the BBC, links to Claude chats that users had chosen to "share" were saved by search engines like Google, making them available to anyone using a site-specific search term. The search availability was removed over the weekend, but many logs were saved and shared widely online.
How the Data Leak Occurred
The incident was initially discovered by users on Reddit, who found more than 200 conversations across at least 25 pages of search results. Some of these conversations occurred just weeks ago. The share option within Claude informs users that "anyone with the link" can view the content, but it does not explicitly state that the link may be indexed by search engines.
A spokeswoman for Anthropic said that Claude users maintain control over if and when to share conversations. She added: "When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services."
Types of Exposed Information
The chat logs included a wide range of sensitive data:
- Personal information: Names, contact details, and work history from users seeking resume help.
- Corporate data: One conversation from April showed a user asking Claude to draft an unpublished blog post about cloud security with details of a corporate project.
- Proprietary research: Some users conducted work-related research, including healthcare transcripts of private conversations.
- Unusual queries: One user asked Claude how to "become Nine-tailed fox," and Claude responded with an AI-generated image claiming the user had been given "fully functional fox powers!"
Comparative Context
| Aspect | Claude (Anthropic) | ChatGPT (OpenAI) |
|---|---|---|
| Similar incident | Hundreds of chats indexed | Almost identical issue last year |
| Outcome | Links blocked after discovery | Company changed ease of log accessibility |
The BBC noted that when OpenAI experienced an almost identical issue with ChatGPT chat logs being made publicly accessible, the company ultimately changed how easily such logs could be accessed.
Search Engine Response
A spokesman for Google told the BBC that Google does not control what pages are made public on the web, and that action comes from websites. "We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives." Since the indexing has stopped, it is likely that Anthropic used available tools to quickly block the links from search results. Other search engines like Bing, Brave, and Duck Duck Go also appeared to have indexed the logs; they were approached for comment.
Implications for Enterprise Users
For enterprise technology decision-makers, this incident underscores the risks of using consumer-grade AI chatbots for business purposes. Shared chat logs containing proprietary research, corporate projects, or confidential transcripts can become publicly accessible via search engines if users are not fully aware of how sharing works. The fact that Claude's sharing feature did not explicitly warn about search engine indexing highlights a gap in user education. Organizations should ensure their employees are trained on the privacy implications of AI tools and consider using enterprise-grade versions with more robust data controls.
As AI chatbots like Claude and ChatGPT become integral to workflows, the onus is on both providers and users to safeguard sensitive information. This case also echoes similar past incidents, such as the ChatGPT leak, demonstrating a pattern that the industry must address more systematically.