Phone us
Generative AI tools are becoming part of everyday working life, but sharing features can expose information more widely than users realise. This article looks at what the recent Claude chat exposure teaches businesses about AI privacy, governance and the safe use of generative AI.

Employees use generative AI tools to draft documents, summarise information, analyse data and generate ideas. However, a recent privacy incident involving Anthropic’s Claude chatbot has highlighted a risk that organisations cannot afford to overlook: information entered into or shared through an AI platform may become more public than the user expects.

According to BBC News, hundreds of conversations with Claude were found to be publicly accessible online. The conversations affected were not ordinary private chats, and there is no indication that Claude itself was hacked. Instead, they were chats that users had chosen to make accessible through Claude’s sharing feature.

That distinction matters, but it does not remove the risk. A person may create a public link believing that only the colleague, client or friend receiving it will see the content. Yet a public URL can be forwarded, posted elsewhere, archived by third parties or discovered by a search engine. Once that happens, information intended for a limited audience can become visible far beyond it.

How Did the Conversations Become Searchable?

Claude allows users to create a public link to a snapshot of a conversation. Reports indicated that some of these shared pages were subsequently indexed by search engines, allowing people to find them without first receiving the link directly.

Anthropic said it did not provide search engines with directories or sitemaps of shared conversations and that the links were not guessable. It explained that a shared page could become discoverable if its link had been posted somewhere publicly accessible, such as a website, forum or social media platform.

The case also highlighted an important technical lesson. Anthropic reportedly used a robots.txt file to tell search-engine crawlers not to access shared chats. However, several shared pages examined by WIRED did not contain a separate “noindex” instruction. Search-engine guidance recommends using this additional control to prevent an individual page from appearing in results. Relying on one safeguard alone therefore left room for public links to become searchable.

Why Does This Matter to Organisations?

The most significant risk is not limited to one chatbot or one sharing feature. It concerns the way employees understand privacy when using cloud-based AI tools.

A link described as “shareable” or available to “anyone with the link” can feel private because it is not advertised through a normal public profile. In reality, it should be treated as public. If a conversation contains personal data, internal business information, client details, source code, financial information or security procedures, accidental exposure could lead to regulatory, commercial and reputational consequences.

The incident also demonstrates how human error and unclear product design can combine with technical weaknesses. A user may make the initial decision to share a conversation, but platforms must also communicate the consequences clearly and apply privacy-protective controls by design.

For businesses, relying solely on individual judgement is not enough. Governance, training and technical safeguards must work together.

What Should Businesses Do Now?

Organisations should review how generative AI is being used across the business and take the following steps:

  • Establish a clear AI acceptable-use policy defining which tools are approved and what information employees must never enter, upload or share.
  • Treat public and link-sharing features as a potential form of external disclosure, requiring the same care as publishing information on a website.
  • Train employees to remove personal, confidential and commercially sensitive data before using public AI services.
  • Review existing shared chats, links and AI-generated artefacts, revoking access where sharing is no longer required.
  • Apply data minimisation so that only the information genuinely needed for a task is provided to an AI system.
  • Assess suppliers’ privacy settings, retention arrangements, access controls, incident processes and contractual protections before approving a tool.
  • Include AI platforms in data protection impact assessments, third-party risk reviews and incident response plans where appropriate.
  • Use enterprise or privately hosted solutions for higher-risk work, supported by suitable security configurations and contractual controls.

The UK National Cyber Security Centre advises users not to place sensitive information into public large language models or submit anything that would cause problems if it later became public.

The Information Commissioner’s Office also advises organisations to define clearly what AI may be used for, select privacy-enhancing settings and ensure employees understand that information shared with an AI tool may be accessible outside the organisation.

A Governance Issue, Not Simply a User Mistake

The Claude incident is a useful reminder that “private by default” does not mean every action taken within a platform remains private. Sharing changes the security boundary.

Organisations therefore need to understand not only what an AI system does with prompts, but also how conversations can be exported, published, retained and discovered.

Generative AI can deliver real benefits, but adoption must be supported by proportionate governance. Clear policies, staff awareness, supplier assurance and secure configuration can help businesses use AI productively without allowing convenience to undermine confidentiality.

At A Jolly Consulting, we help organisations understand emerging cyber and data protection risks, strengthen governance and build practical security measures around new technologies. As AI becomes embedded in routine business activity, organisations that address these risks early will be better placed to innovate with confidence.

Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Sources:

BBC News. (2026). Some people’s chats with Claude AI found to be publicly available online. Available at: https://www.bbc.co.uk/news/articles/cly5qgjk5ywo

TechCrunch. (2026). PSA: Your Claude shared chats and Artifacts may have ended up on Google. Available at: https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/

WIRED. (2026). Private Claude Chats Exposed in Google and Bing Search Results. Available at: https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/

National Cyber Security Centre. ChatGPT and large language models: What’s the risk? Available at: https://www.ncsc.gov.uk/blog-post/chatgpt-and-large-language-models-whats-the-risk

Information Commissioner’s Office. Guidance on AI and data protection. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

Image accreditation: Philip Oroni (September 2024) from Unsplash.com+. Last accessed on 5 August 2026. Available at:
https://unsplash.com/photos/a-computer-keyboard-sitting-on-top-of-a-computer-mouse-AMAYQqzQYaI

In case you missed it...

Data Protection at the Airport
Data Protection at the Airport: The...

Busy airports, unfamiliar networks and frequent travel updates can create opportunities for cybercriminals and put personal data at risk. This...

Read More
krysta collin
Meet Krysta Collin, General Manager at...

In this series, we introduce the people behind AJC and the experience they bring to the business. In this profile,...

Read More
AI Cyber Resilience
OpenAI Security Incident Highlights the Growing...

As AI becomes more capable, organisations need to understand both the opportunities and the risks it can create. This article...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.