Phone us
Generative AI tools are becoming part of everyday working life, but sharing features can expose information more widely than users realise. This article looks at what the recent Claude chat exposure teaches businesses about AI privacy, governance and the safe use of generative AI.

Employees use generative AI tools to draft documents, summarise information, analyse data and generate ideas. However, a recent privacy incident involving Anthropic’s Claude chatbot has highlighted a risk that organisations cannot afford to overlook: information entered into or shared through an AI platform may become more public than the user expects.

According to BBC News, hundreds of conversations with Claude were found to be publicly accessible online. The conversations affected were not ordinary private chats, and there is no indication that Claude itself was hacked. Instead, they were chats that users had chosen to make accessible through Claude’s sharing feature.

That distinction matters, but it does not remove the risk. A person may create a public link believing that only the colleague, client or friend receiving it will see the content. Yet a public URL can be forwarded, posted elsewhere, archived by third parties or discovered by a search engine. Once that happens, information intended for a limited audience can become visible far beyond it.

How Did the Conversations Become Searchable?

Claude allows users to create a public link to a snapshot of a conversation. Reports indicated that some of these shared pages were subsequently indexed by search engines, allowing people to find them without first receiving the link directly.

Anthropic said it did not provide search engines with directories or sitemaps of shared conversations and that the links were not guessable. It explained that a shared page could become discoverable if its link had been posted somewhere publicly accessible, such as a website, forum or social media platform.

The case also highlighted an important technical lesson. Anthropic reportedly used a robots.txt file to tell search-engine crawlers not to access shared chats. However, several shared pages examined by WIRED did not contain a separate “noindex” instruction. Search-engine guidance recommends using this additional control to prevent an individual page from appearing in results. Relying on one safeguard alone therefore left room for public links to become searchable.

Why Does This Matter to Organisations?

The most significant risk is not limited to one chatbot or one sharing feature. It concerns the way employees understand privacy when using cloud-based AI tools.

A link described as “shareable” or available to “anyone with the link” can feel private because it is not advertised through a normal public profile. In reality, it should be treated as public. If a conversation contains personal data, internal business information, client details, source code, financial information or security procedures, accidental exposure could lead to regulatory, commercial and reputational consequences.

The incident also demonstrates how human error and unclear product design can combine with technical weaknesses. A user may make the initial decision to share a conversation, but platforms must also communicate the consequences clearly and apply privacy-protective controls by design.

For businesses, relying solely on individual judgement is not enough. Governance, training and technical safeguards must work together.

What Should Businesses Do Now?

Organisations should review how generative AI is being used across the business and take the following steps:

  • Establish a clear AI acceptable-use policy defining which tools are approved and what information employees must never enter, upload or share.
  • Treat public and link-sharing features as a potential form of external disclosure, requiring the same care as publishing information on a website.
  • Train employees to remove personal, confidential and commercially sensitive data before using public AI services.
  • Review existing shared chats, links and AI-generated artefacts, revoking access where sharing is no longer required.
  • Apply data minimisation so that only the information genuinely needed for a task is provided to an AI system.
  • Assess suppliers’ privacy settings, retention arrangements, access controls, incident processes and contractual protections before approving a tool.
  • Include AI platforms in data protection impact assessments, third-party risk reviews and incident response plans where appropriate.
  • Use enterprise or privately hosted solutions for higher-risk work, supported by suitable security configurations and contractual controls.

The UK National Cyber Security Centre advises users not to place sensitive information into public large language models or submit anything that would cause problems if it later became public.

The Information Commissioner’s Office also advises organisations to define clearly what AI may be used for, select privacy-enhancing settings and ensure employees understand that information shared with an AI tool may be accessible outside the organisation.

A Governance Issue, Not Simply a User Mistake

The Claude incident is a useful reminder that “private by default” does not mean every action taken within a platform remains private. Sharing changes the security boundary.

Organisations therefore need to understand not only what an AI system does with prompts, but also how conversations can be exported, published, retained and discovered.

Generative AI can deliver real benefits, but adoption must be supported by proportionate governance. Clear policies, staff awareness, supplier assurance and secure configuration can help businesses use AI productively without allowing convenience to undermine confidentiality.

At A Jolly Consulting, we help organisations understand emerging cyber and data protection risks, strengthen governance and build practical security measures around new technologies. As AI becomes embedded in routine business activity, organisations that address these risks early will be better placed to innovate with confidence.

Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.

Sources:

BBC News. (2026). Some people’s chats with Claude AI found to be publicly available online. Available at: https://www.bbc.co.uk/news/articles/cly5qgjk5ywo

TechCrunch. (2026). PSA: Your Claude shared chats and Artifacts may have ended up on Google. Available at: https://techcrunch.com/2026/07/27/psa-your-claude-shared-chats-and-artifacts-may-have-ended-up-on-google/

WIRED. (2026). Private Claude Chats Exposed in Google and Bing Search Results. Available at: https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/

National Cyber Security Centre. ChatGPT and large language models: What’s the risk? Available at: https://www.ncsc.gov.uk/blog-post/chatgpt-and-large-language-models-whats-the-risk

Information Commissioner’s Office. Guidance on AI and data protection. Available at: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

Image accreditation: Philip Oroni (September 2024) from Unsplash.com+. Last accessed on 5 August 2026. Available at:
https://unsplash.com/photos/a-computer-keyboard-sitting-on-top-of-a-computer-mouse-AMAYQqzQYaI

In case you missed it...

cookie compliance gambling websites
Cookie Compliance Lessons from UK Gambling...

Cookie compliance is about more than having a banner in place. This article looks at new research into UK gambling...

Read More
UK Air Traffic Control Disruption
UK Air Traffic Control Disruption: Why...

Recent disruption across UK airports has shown how quickly the failure of a critical system can have far-reaching consequences. While...

Read More
cyber security healthCARE
Patient Data Breaches: Why Cyber Security...

Protecting patient data is not just about securing systems and technology. This article looks at how human behaviour, organisational processes...

Read More

Get in touch

    By submitting this form you are consenting that your data be handled in accordance with our Privacy Notice and we will be in touch regarding your enquiry.