Some of the exposed chats carried CVs with names and contact details, others proprietary work research. The links left search results over the weekend, by which point copies were circulating.
More than 200 exchanges between users and Claude, the AI chatbot built by Anthropic, were open to anyone on the internet: the links showed up on search engines such as Google for a query restricted to a single website, running to at least 25 pages of results. Some of the conversations had taken place only weeks earlier.
Those links came from chats users had opted to share, and search engines including Google had stored them, putting them within reach of the general public. Users on Reddit were the first to notice that the shared conversations could be read this way.
Over the weekend the chat logs stopped turning up in search results. Many had already been copied and passed around widely on the internet.
Some of the exposed chats held personal and work information. Several were from people asking for help with their CVs, which gave away who they were, how to reach them and where they had worked. Others appeared to be proprietary work research run through the chatbot, including in healthcare, along with transcripts of private conversations. In one exchange in April, a user had Claude write up a blog entry on cloud security, never published, that drew in specifics about a company project.
Claude's sharing feature does tell the user that any person holding the link is able to read the conversation. It says nothing outright about the link potentially surfacing in Google or other search results.
An Anthropic spokeswoman said Claude users retain control over whether and when to share their conversations, and that links to conversations could not be guessed at or found unless users decided of their own accord to share them. Once someone shares a conversation, she said, they are putting that content into public view, and, as with any other material published on the web, third-party services may keep an archived copy of it.
Which pages go public on the web is not Google's decision to make, a spokesperson for the company told the BBC — websites themselves take that step. Site owners are given plain controls over whether their pages may be crawled or indexed, the spokesperson said, and those instructions are honoured without exception. Keeping a link out of search results is a simple matter under that procedure, but nothing happens unless the owner of the site sets it in motion.
ChatGPT ran into an almost identical problem with shared chat logs last year, and OpenAI eventually changed how easily they could be accessed. Grok, the AI chatbot built into X, had hundreds of thousands of its chat logs made publicly available through online search, also last year.