Jessica Entwistle
July 28 2026
The BBC reports that hundreds of conversations with Anthropic's Claude AI chatbot were discovered publicly accessible through Google search results. The issue originated from Claude's "share chat" feature, which allows users to create shareable links for conversations and projects. These links, intended for controlled sharing, were being indexed by search engines and made discoverable to anyone searching for related content. Anthropic has since addressed the indexing issue, but the incident highlights how easily shared AI content can become unintentionally public when default privacy settings are not clearly understood by users.
For UK organisations using AI chatbots for internal work, customer support, research or content creation, this incident is a practical reminder that "share" features often mean "publish" in ways users may not expect. Employees may be using AI tools to draft sensitive documents, analyse confidential data, troubleshoot technical issues or discuss business strategy without realising that shared links can be indexed, forwarded or discovered by unintended audiences. The risk is not theoretical—it is about real business information, customer data or intellectual property becoming searchable and accessible outside the organisation's control. The incident also raises questions about how AI platforms handle shared content, what default privacy settings apply, and whether users are given sufficient clarity about the difference between private, shared and publicly discoverable content.
UK businesses should review how AI chatbots are being used across the organisation and what controls are in place around data sharing. Consider whether acceptable use policies clearly address AI tool usage, data handling and sharing practices, and whether employees understand the risks of creating shareable links for sensitive content. Review whether your organisation has visibility into which AI platforms are being used, whether shadow AI usage is occurring outside approved channels, and whether data loss prevention or monitoring controls can detect when sensitive information is being shared externally. Consider whether training and awareness programmes help employees understand the privacy implications of AI chatbot features, and whether governance frameworks clearly define what types of content are appropriate for AI processing. Finally, assess whether incident response plans account for scenarios where sensitive organisational data may have been unintentionally published or indexed by search engines.
Source: BBC Technology