Claude Chats Appearing in Google: What Does That Teach us About AI Privacy?
There are few phrases more likely to make anyone sit up and take notice than hearing “oh, by the way, your private chats may be on Google”, yet that was the concern this week after reports emerged that some shared Claude conversations and artefacts have been appearing in search results.
Now, we’re keen AI users here at Fifosys, and some of the stuff Claude specifically has done to improve business processes or reporting would genuinely have taken weeks - if not longer - to get to that same level of output. But let’s be real, we’ve all asked AI a dumb question or two, and it’s not that I’m secretive as a person, I’d just rather my private conversations were, well, private.
Now, if you’re in a rush, it might be better to come back to this post later, but the short version is this: based on current reporting, it doesn’t appear that all your private Claude conversations have suddenly been exposed. And, at the time of writing, they’re no longer able to be seen on Google.
The issue appears to have involved chats or artefacts shared via public links, which could, in some cases, be indexed by search engines. WIRED reported that Claude shared chats were protected by robots.txt, but some pages lacked a noindex tag, which can matter when search engines decide what to list. Anthropic said shared links are not guessable unless people choose to share them, but shared conversations are publicly accessible once shared. (wired.com)
For many UK SMEs and mid-market organisations, this is exactly the sort of grey area that causes real-world data exposure. It’s often not a dramatic breach, nor is it someone in a hoodie breaking through seven firewalls. As is the case here, it’s usually just a flaw or an error in a useful business tool, a convenient button, a slightly unclear sharing model, and business information travelling further than anyone intended.
All in all, a very modern problem - but an increasingly common one, too.
What actually happened with Claude shared chats?
Apologies to any seasoned users of Claude, who may feel like we’re about to teach you to suck eggs here, a tad. But chats include an option to create shared versions of conversations. Anthropic’s own help guidance says shared chat snapshots include messages sent before the chat was shared, including artefacts, while messages sent afterwards remain private unless the user updates the shared snapshot. Users can also unshare chats by changing visibility from public to private. (support.claude.com) (support.claude.com)
The recent concern has arisen because some of these publicly shared links appeared in Google and Bing search results. Reports from places like the BBC, WIRED, TechCrunch, Neowin and others on social media described users finding shared Claude conversations or creations through search.
And yet, the lesson isn’t simply “don’t use Claude” or “AI is unsafe”. That would be too easy, and honestly, not particularly useful if you’re trying to move with the times.
Put simply, AI tools are now part of the same data governance problem as email, cloud storage, messaging apps, browser extensions, file-sharing platforms, and SaaS tools. If staff can paste sensitive information into a system, generate content from it, and share the output externally, then that system is part of your security environment, irrespective of whether your business formally recognises that or not.
Why this matters for UK SMEs
Many smaller and mid-sized organisations are already using AI in their daily work. Often sensibly. From our perspective, we’re having more and more conversations about how to roll it out for companies, we’re writing weekly blogs, we’re hosting webinars… I could go on, but you get the picture.
Everyone has their own unique use cases, whether it’s to summarise meeting notes, draft documents, tidy spreadsheets, explain code, rewrite customer emails, compare contract wording, brainstorm proposals, or turn messy notes into something readable.
At its core, AI is useful. In many cases, very useful.
The risk so often appears when people use AI tools with business data, yet fail to establish clear rules. For example:
A manager pastes internal financial information into a chatbot to summarise it.
A sales team uses AI to refine proposal language containing client details.
HR asks for help rewriting sensitive employee communications.
A technical team shares logs, scripts, credentials, architecture notes or supplier information.
Someone creates a public link because it is easier than exporting a document.
We’ve said it before, and we’ll say it again, none of these examples - or indeed any other than you can conjure up - is loaded with a level of bad intentions. They require a normal working day, mild time pressure, and a button at the top of their chat that says “share”.
That’s also precisely why AI privacy shouldn’t be treated as a niche IT policy.
A public link doesn’t mean a private link
One of the awkward lessons here is that “anyone with the link” can feel private, even when technically? It isn’t.
People are used to sharing documents this way. Google Drive, Microsoft 365/SharePoint, Notion, Canva, project tools, and AI platforms all have some version of link sharing. In practice, users often think of these links as semi-private because they are long, hard to guess, and are only sent to specific people.
But remember, “not easy to guess” is a long way from “controlled access”.
If a public link is posted somewhere, crawled, forwarded, logged, saved in another system, or picked up by a search engine, the organisation can quickly lose track of it. That’s really not unique to Claude; Claude is just the latest high-profile reminder, and one that makes headlines sound scarier, especially given last week’s ‘AI gone rogue!’ fiasco.
It feels like the key question you may be left with is: “Oh great. Which AI tool made the headline this week?” (Don’t worry, we’ll tell you in our weekly roundup)
But actually, you should be asking: “Where in our organisation can people create public links to sensitive information, and do we know exactly how those links are controlled?”
What should businesses do now?
Start with a practical AI sharing audit. Not a 90-page policy exercise - nobody is going to read that out of the gate. You just need enough structure to establish and find the obvious gaps before they become awkward.
A good jumping-off point is to ask staff to review any AI chats, artefacts, or generated outputs they have shared publicly. Claude users can check shared chats through Settings > Privacy > Shared chats, according to Anthropic’s guidance. (privacy.claude.com) Anything containing client data, personal data, credentials, internal documents, legal advice, HR material, financial information or commercially sensitive details should be removed from public access immediately.
Second, define what information should never be pasted into consumer AI tools. This should be simple enough for people to remember. A good starting point would include personal data, client confidential information, passwords, API keys, contracts, source code that should not leave the business, incident details, and anything under NDA.
Third, decide which AI tools are approved for business use - and get users on the business account so your inputs aren’t absorbed and used to train the AI models. If people are using personal accounts because the business has not provided a better route, the business still carries the risk, but has less visibility. That’s not an ideal trade.
Fourth, set rules for sharing. Public links should be treated as publishing, not collaboration. If the content wouldn’t be something you’re fine with having on a page of your site, it shouldn’t be shared through a public AI link.
Fifth, train people on the difference between private, internal, restricted, and public. It sounds basic, I know, but it’s where a lot of data exposure happens. The problem is rarely that people don’t care; modern tools just make visibility settings feel deceptively casual.
The bigger AI governance point
AI governance, at any level, really doesn’t need to start with a grand strategy document that nobody opens after the launch meeting. We outline this in a few other blogs, it comes up in our webinars, and we’ll share it here, too.
For most SMEs, it starts with answering a few grounded questions:
Which AI tools are staff actually using?
What business data is being entered into them?
Are personal accounts being used for company work?
Can users create public links?
Who reviews and revokes shared content?
What happens if sensitive information is accidentally exposed?
Are AI tools covered in onboarding, offboarding and acceptable-use policies?
Really, with these questions, you should get a good enough picture. It encompasses client confidentiality, GDPR risk, supplier assurance, cyber insurance, contract obligations and reputation.
And, in our experience, this is where many organisations are currently exposed, because AI adoption has just moved at a faster pace than internal governance. Staff have found useful tools to help their work before the business has even become aware of them, let alone built the guardrails around them.
It’s the perfect storm for where avoidable risk lives.
What good looks like
A proportionate approach to AI privacy should give people enough freedom to work effectively while making risky behaviour harder.
That might include documenting approved AI platforms (with ownership), clear data classification rules, browser or endpoint controls, logging where appropriate, staff guidance, and regular reviews of publicly shared content. For some organisations, it may also mean using enterprise AI services with stronger admin controls, retention settings and internal sharing restrictions.
The aim is not to stop people from using AI. I mean, that ship hasn’t just sailed, it’s circled the harbour, made a long-winded voyage, come back and written all about its journey a la Homer and the Odyssey.
The aim now is to make AI use visible, intentional and aligned with the organisation’s risk appetite.
Final thought
The Claude shared chat issue is a blip, and it’s already been fixed by the time we actually wrote about it, but it serves as a useful reminder: data leakage often happens through convenience.
A public link is convenient. A quick AI summary is convenient. Sharing a generated artefact with a colleague is convenient. None of those things is inherently wrong, and we’re not going to vilify anyone for doing it.
But just be mindful that any and all convenience needs boundaries.
For UK SMEs and mid-market organisations, please, don’t panic. Just use this as a reminder to bring AI use into normal IT and security management: know which tools are being used, decide which data can go where, control public sharing, and ensure staff understand the difference between “shared” and “safe”.
Because in 2026, AI privacy isn’t a future concern. It’s something that’s already sitting inside everyday workflows, waiting for someone to click the wrong button.