Plain-English Briefing
The AI chats that turned up on Google — what actually happened
You may have seen it over the weekend: people’s AI conversations turning up in Google search results. Names, CVs, work in progress, internal project details — findable by anyone who typed the right search.
It sounds like a data breach. It wasn’t one. What it actually is turns out to be more useful to know about, because the same thing can happen to your business with any AI tool you use.
Here’s the plain-English version.
What happened
Claude — the AI assistant made by Anthropic, one of ChatGPT’s main rivals — has a share button. You click it, and it creates a public web page containing a snapshot of your conversation. The idea is that you can send that link to a colleague so they can read what you and the AI discussed.
Over the weekend, someone noticed that those pages could be found through Google. Not just opened if you had the link — found, by searching. A community thread showed page after page of other people’s shared conversations: legal discussions, software work, internal company material, personal topics. Some people claimed to have found login credentials and financial details too, though those particular claims haven’t been independently verified and I’d treat them as unconfirmed.
The pages have since disappeared from Google. It isn’t publicly established whether Google removed them, Anthropic did, or both.
What it wasn’t
This is the part most of the coverage got thin on, and it matters.
Nobody was hacked. No private conversations were taken from anyone’s account. Every one of those pages existed because a human being clicked “share” and created a public web page on purpose. Anthropic’s position is that it blocks search engines from crawling those pages and never submits them to Google, and that the ones which showed up did so because people posted their own links somewhere public — a forum, a social post, a group chat — where a search engine found them.
There’s a nice bit of plumbing here that explains how a page can be “blocked” and listed at the same time. If you tell a search engine “don’t come in”, it doesn’t come in — which means it never reads the note pinned inside the door saying “and don’t list this either”. So it lists the address without ever seeing the contents. Locked door, sign on the wrong side of it.
And this is not a Claude problem. Google’s own chatbot did the same thing in 2023 — over three hundred shared conversations turned up in search results. ChatGPT did it in 2025. Same button, same misunderstanding, three times in three years.
Which tells you it isn’t a bug in one product. It’s a gap between what “anyone with the link” sounds like and what it means.
What it means for a normal business
Most AI advice to small businesses is about what your team types in. Don’t paste the client list. Don’t paste the pricing. Don’t paste the contract. That’s good advice and it’s the risk everyone talks about.
This story is about what comes out — and almost nobody has a rule for it.
Picture it in your business. Someone spends twenty minutes with a free AI tool getting a quote letter right. It’s good. They want a second opinion, so they hit share and drop the link in a WhatsApp group, or a trade forum, or an email that ends up on a public mailing list. That link is now a web page on the internet, containing whatever was in the conversation — your prices, your client’s name, your method for winning the job.
Three things follow from that, and they’re worth knowing whatever tools you use:
- “Anyone with the link” means anyone. Not “the person I sent it to”. A link can be forwarded, screenshotted, pasted or posted, and every one of those is out of your hands the moment it happens.
- Unsharing doesn’t undo it. Turning a share link off stops future visitors. It does nothing about the copies. Once a page has been found, saved or scraped, you’re no longer negotiating with a search engine — you’re negotiating with everyone who saw it.
- Your AI policy probably doesn’t mention this. Most policies — including plenty of good ones — cover what staff may put into AI tools. Very few say a word about share links, published documents or public pages. That’s the gap this weekend just walked through.
Where this fits with the other risk
Regular readers will spot the pattern. The last briefing was about AI systems that can reach further than anyone expected. This one is about your own team, doing something entirely reasonable, with a button that means something other than what it looks like.
Both come down to the same question: where does this actually go?
It’s the question behind Cortex, our AI appliance. It sits in your building and answers questions from your own files. There’s no share button on it that publishes to the internet, because there’s no internet involved — nothing about it creates a public web address, because it has nowhere to put one. That isn’t a clever safety feature we added. It’s what happens when the whole thing lives on your premises instead of someone else’s.
But I’d rather you did the free thing below than bought anything from me this month.
Worth doing this week, whatever you buy (including nothing)
Three jobs, none of which cost anything:
- Check your own shared links. In Claude that’s Settings → Privacy → Shared Chats; ChatGPT and Gemini have equivalents. Look at every one. Anything with a client name, a price, a credential or a person’s details in it — set it back to private today.
- Ask your team the direct question. Not “are you using AI” — you’ll get a shrug. Ask: “has anyone ever sent someone a link to an AI conversation?” That’s the behaviour, and it’s usually invisible until you name it.
- Add one line to your AI rules. Something like: treat any AI share link as a public web page — because that’s what it is.
If you haven’t got written rules yet, our free AI Toolkit builds the whole pack — use policy, staff agreement, tools register, incident plan — personalised to your business in about five minutes. No email, no catch, and nothing you type leaves your browser.
Build your free AI toolkitMore plain-English briefings on the Inferred blog.