Reddit users uncovered a startling privacy flaw in Anthropic's Claude AI platform when a simple Google search using the operator site:claude.ai/share returned a long list of shared conversations. The results included not only routine work notes but also highly sensitive information: real‑patient medical reports, clinical trial data with patient names, internal company documents marked "for internal use only," and even the names and phone numbers of primary‑school‑aged children.
Anthropic's "share chat" feature generates a URL that anyone with the link can view. The interface warns users that the link is "public," implying it should be shared only with trusted parties. In theory, the link is not guessable and should remain invisible to search engines unless the user posts it publicly. The company, however, pointed to user behavior as the cause of the exposure.
Spokeswoman Amie Rotherham told TechCrunch, "We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves." She added that once a user makes a conversation public, it can be archived by third‑party services just like any other web content.
The breach first surfaced on Reddit Saturday and was reported by 404 Media on Monday morning. By Monday afternoon, a test search performed by TechCrunch no longer displayed any results, indicating that Anthropic or the affected users had likely removed the publicly shared links or that Google had de‑indexed the pages.
Before the apparent remediation, Futurism documented a range of exposed artifacts: a detailed medical report of a real patient, clinical trial results including patient identifiers, documents listing children's personal data, code snippets, and work notes. Fortune also highlighted a conversation labeled "shared by Anthropic" that produced erotica, a clear violation of Claude's usage policy, which prohibits sexually explicit content. Anthropic has not commented on how that particular content was generated.
Google's response, delivered by spokesperson Ned Adriance, emphasized that search engines do not control what pages become public. "Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives," he said.
The incident mirrors a similar episode last year when hundreds of Claude chats were indexed by search engines, with Google estimating just under 600 conversations before they disappeared from results. At that time, 404 Media also reported a researcher scraping roughly 100,000 publicly shared ChatGPT conversations, underscoring a broader challenge in managing AI‑generated content that users deem private.
Anthropic advises users to review their shared chats by navigating to Settings → Privacy → Shared Chats. The company maintains that the share link feature is intended for collaboration, not for open‑internet distribution, and it urges users to choose the "Keep private" option when confidentiality is required.
While the immediate exposure appears to have been contained, the episode has reignited debate over how AI platforms balance ease of collaboration with robust privacy safeguards. As more businesses and individuals integrate conversational AI into sensitive workflows, the pressure mounts on developers to ensure that a single mis‑clicked link does not become a data‑leak vector.
Questo articolo è stato scritto con l'assistenza dell'IA.
News Factory APP - notizie agentiche per potenziare il tuo SEO e AEO.