Skip to main content
Live
Main content

Claude shared chats and Artifacts surfaced in Google search results

Anthropic's share-link feature exposed conversations containing medical records, children's contact details, and internal company documents.

Jaeden Schafer
Editor in Chief · · 4 min read
Anthropic logo

An untold number of Claude shared chats and Artifacts were surfaced in Google search results over the weekend, after Reddit users found that typing the operator 'site:claude.ai/share' into Google returned a long list of user conversations. The exposed material included a detailed medical report of a real patient, clinical trial results with patient names, documents containing names and phone numbers of primary school-aged children, internal company documents, and employee reviews with personal information. The issue was first flagged on Reddit on Saturday and first reported Monday morning; by Monday afternoon, test searches no longer returned results.

The leak stems from Claude's 'share chat' feature, which generates a URL that lets anyone with the link view a conversation or Artifact. Claude's interface warns 'Anyone with the link can view,' language that reads more like a Google Docs-style permission — where documents are not indexed by search engines — than a full public post. That mismatch between user expectation and search-engine behavior is what turned private-feeling links into public web pages.

Anthropic's position is that the shared URLs are not themselves indexed by design. The company said it does not submit chat directories or sitemaps to search engines, and that a link only appears in Google when a user has posted it somewhere crawlable, such as a forum or social media. In other words, Anthropic frames the exposure as downstream of user behavior rather than a platform-level leak.

Key facts

  • 01Claude shared chats and Artifacts became discoverable on Google via the 'site:claude.ai/share' search operator, first flagged on Reddit Saturday.
  • 02Exposed content included medical reports with patient names, clinical trial results, phone numbers of primary-school-aged children, and internal company documents.
  • 03A similar 2025 incident saw Google index just under 600 Claude conversations before the pages disappeared from results.
  • 04By Monday afternoon, test searches returned no results, suggesting the exposure had been remediated.
  • 05Last year a researcher scraped roughly 100,000 publicly shared ChatGPT conversations, indicating the problem is not unique to Anthropic.

Anthropic spokeswoman Amie Rotherham detailed the company's stance in an explainer provided to reporters.

We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves.
Amie Rotherham, Anthropic spokeswoman

Google offered a parallel argument, pointing out that search engines index what site owners allow to be crawled. The company said site owners have controls to block crawling and indexing, and that Google honors those directives. The pages in question, Google noted, were indexed across multiple search engines, not just its own.

Google spokesperson Ned Adriance made the point directly.

Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.
Ned Adriance, Google spokesperson

This is not the first time Claude shares have leaked into search. Last year, a similar incident led Google to estimate it had indexed just under 600 Claude conversations before the pages disappeared from results. How closely the current exposure tracks that scale has not been independently confirmed, though multiple users reported finding shared conversations using the same query pattern that surfaced last year's cache. The pattern extends beyond Anthropic — last year, a researcher scraped roughly 100,000 ChatGPT conversations that users had set to be shared publicly.

Some of the exposed material sits awkwardly with Anthropic's own usage policy. At least one indexed chat, labeled as shared by Anthropic itself, showed Claude producing erotica, which the company's policy prohibits. Getting a chatbot to produce content against its stated guidelines through creative prompting is a familiar pattern across major models, and it is not yet clear how that specific chat was generated. Anthropic has not commented on that individual case.

Related · from this week
AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates
Jaeden Schafer · 5 min read →

For users who want to audit their exposure, the settings path inside Claude is Settings → Privacy → Shared Chats, which lists every conversation with an active public link. Revoking a link removes the live page, though cached copies on third-party services and search-engine snapshots can persist for some time after removal. The Futurism findings — patient records, children's contact details, internal documents — suggest a meaningful share of users did not understand the link was truly public.

The design question is whether 'anyone with the link' is a defensible default in 2026. Google Docs uses similar wording and does not end up indexed, because Docs pages sit behind authentication and are not served as public HTML. Claude's share links, by contrast, are plain public URLs — the moment one lands in a Reddit post, a Discord message that gets scraped, or a public GitHub gist, it is indexable. That is a UX gap more than a security bug, but the practical outcome is the same.

The broader takeaway for the AI product market is that share-and-collaborate features are now a first-class attack surface for AI companies, alongside training-data leaks and prompt injection. Consumer AI is being used for medical intake, HR reviews, and internal company work — categories where users treat the chatbot the way they treat a private notes app. Anthropic will likely need to make the public-link toggle louder, add a no-index directive on share pages, or move shared conversations behind a viewer authentication step. Until frontier labs treat 'shared' and 'public' as distinct states, the next incident of this shape is a matter of when, not if.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates
Security

AI bug hunting arms race doubles vulnerability payouts as exploit discovery accelerates

Google and Apple face 2–10x more bug submissions; researchers report tripled output, forcing bounty programs to rebalance economics.

Jaeden Schafer5 min read
Anthropic logo
Analysis

University of Washington student ships interactive map of AI data center policy

Isabelle Reksopuro's tool uses Claude to refresh four times daily, charting buildouts from The Dalles to Texas.

Jaeden Schafer4 min read
Anthropic logo
Business

Google pledges up to $40B to Anthropic as compute crunch deepens

The deal lands days after Amazon's $5B injection and values Anthropic at $350B, with both investors tying further capital to performance targets.

Jaeden Schafer4 min read