
You prepare a summary in Claude, ChatGPT or another AI assistant. To ask a colleague for feedback, you click Share.
You think you are sending a document to one person. Depending on the product and account, you may have created a page that anyone with the link can open.
The problem is not that every AI conversation is public. The problem is sharing without knowing which object leaves the workspace, who can open it and how access will end.
Answer in 60 seconds
- A private conversation, an internal share and an anyone-with-the-link page are not the same space.
- “Anyone with the link” does not mean “approved recipients only”.
- What becomes visible depends on the object and account: conversation, artifact, file, export or connected-tool output.
- Revoking a link, unpublishing an artifact and removing a search result are separate actions.
- A useful AI policy gives staff a workable route: what they may share, where, who owns it and what to do when something goes wrong.
In this article
- What the Claude incident shows
- Private, internal, public or indexed
- What becomes visible depends on the object
- Use the Share button test
- What if the link has already circulated?
- What your AI use policy should add
- Conclusion
- Frequently asked questions
1. What the Claude incident shows
Anthropic says Claude chats are private by default. On Free, Pro and Max accounts, a user can then create a snapshot that anyone with the link can view (Anthropic).
Some of those public pages appeared in Google or Bing. Anthropic said it did not provide a directory or sitemap. A link could still be discovered after somebody placed it somewhere a search engine could crawl (WIRED).
The exact technical cause remains uncertain. Checks performed at different times found different configurations. This should not be reduced to a simple story about one missing tag (Search Engine Journal).
The more useful lesson is stable: a public link can travel beyond its first recipient.
This is not unique to Claude. OpenAI warns that a copy imported by another user may remain in that user’s history after the original ChatGPT shared link is deleted (OpenAI). Researchers have also studied public links from several assistant platforms. That establishes a cross-platform publication surface; it does not prove that every share was accidental (ShareChat).
2. Private, internal, public or indexed
Inside a team, the word “shared” sounds reassuring. In a product, it can describe four different states.
| State | Who can open it? | Useful control |
|---|---|---|
| Private | Authorised users | Identity, permissions and revocation |
| Internal | Signed-in organisation members | Membership, project access and attachments |
| Anyone with the link | Anyone who receives or finds the URL | Clean content, owner and inventory |
| Indexed or copied | Search users, an archive or somebody holding a copy | Source revocation, search removal and copy handling |
A difficult-to-guess URL is not access control. It can be forwarded, published or retained elsewhere.
Google also explains that a noindex instruction works only when its crawler can read it. A robots.txt rule controls crawling; it does not make a public page confidential (Google Search Central).
For sensitive information, the relevant control remains access: authentication, limited permissions or no public publication.
3. What becomes visible depends on the object
Do not rely on the word Share. Check the object and account.
| Object | Audience currently described by Anthropic | Point to check |
|---|---|---|
| Free, Pro or Max chat | Anyone with the link | Earlier messages and displayed artifacts are visible |
| Consumer-published artifact | Anyone with the link | It can be used, copied or embedded elsewhere |
| Team or Enterprise chat or artifact | Authenticated organisation members | Project rights and attachments still matter |
For a consumer chat, Anthropic says the original attached file is not included in the snapshot. The conversation and Claude’s answers remain visible. Information quoted or summarised from the file can therefore appear on the shared page.
For an artifact shared inside Team or Enterprise, Anthropic says authorised viewers may gain access to attachments from the source conversation (Anthropic - artifacts).
“Files are never shared” would therefore be the wrong rule.
Apply the same check to screenshots, exports, copied text and connected-tool output.
4. Use the Share button test
Before creating a link, answer five questions.
- What does the recipient need? The complete conversation, one answer or only the conclusion?
- What is actually on the page? Customer or employee data, contracts, non-public pricing, code, credentials, internal documents or strategy?
- Who can really open it? One person, a project, the organisation or anyone with the link?
- Who remains responsible? Who records, reviews and revokes the link?
- What private alternative should staff use? An internal project, permissioned folder, business workspace or cleaned document?
OWASP identifies sensitive-information disclosure through LLM inputs and outputs as a risk that requires data handling and access controls (OWASP). NIST’s voluntary AI Risk Management Framework also places governance, context, measurement and response across the AI lifecycle; using it does not prove a control works in your environment (NIST).
The inventory does not need to duplicate the content. Product, object, audience, owner and status may be enough.
Prohibition without a usable route encourages shadow tools. The approved path should be the easiest path.
5. What if the link has already circulated?
Start by reducing the exposure.
- Revoke the chat share and unpublish related artifacts separately.
- Preserve the useful facts without redistributing the content.
- Identify what was visible and who could access it.
- Rotate exposed passwords, keys or tokens immediately.
- Look for public posts, search results, previews and copies.
- Involve the privacy lead, security lead, legal counsel, HR or contract owner according to the content.
- Fix the route that allowed the mistake.
Removing a Google result does not remove the source page. Disabling the source does not guarantee the immediate disappearance of every copy. Track the actions separately (Google).
If personal data was exposed without authorisation, the organisation may need a breach assessment under the laws that apply to it. Under the GDPR, documentation, authority notification and communication to affected people depend on the facts and level of risk; there is no universal response for every public link (European Data Protection Board).
6. What your AI use policy should add
Many policies name approved tools and prohibited inputs. They often miss one question: how does a conversation leave the tool?
Add:
- approved accounts and sharing functions;
- prohibited data and audiences;
- covered objects: conversations, artifacts, files, exports and screenshots;
- an owner and review or revocation trigger;
- the approved private alternative;
- an incident route and the specialists to involve.
For organisations operating in the EU, Article 4 of the AI Act requires AI literacy measures suited to people and context. Showing staff what the real Share control does is more useful than generic awareness. A policy or training session does not, by itself, establish compliance or security.
For the wider operating model, see our AI governance checklist for SMEs.
Conclusion: control the exit, not only the input
A useful policy does more than tell staff what they may ask an AI assistant. It explains how to share, with which audience, who remains responsible and how access ends.
Take one real sharing route. Check it from end to end. Fix the first missing control.
Bring us one sharing path. We’ll give you an honest read.
Bring the approved-tool list, current policy and one sharing route without sensitive content. IZZY can map the move from private conversation to internal collaboration or public publication, then identify the first missing operating control.
The answer may be a clearer rule, an account setting, a private workspace, training, an Agent Readiness Audit, a more controlled AI integration or a specialist decision. If a larger engagement is not justified, the call should make that clear too.
Frequently asked questions
No. Anthropic describes it as private by default. A user must create a public snapshot or publish an artifact. Team and Enterprise currently use organisation-only sharing.
No. It may require neither identity nor individual authorisation. The link can be forwarded, published, archived or copied.
Not necessarily. Revoking the source, removing a search result and dealing with external copies are separate actions.
No. That depends on the content, audience, applicable law and risk. Preserve the facts and involve the responsible privacy or legal specialist.
No. Connect it to the accounts people actually use, product settings, a private route, an inventory and a workable incident process.
Sources
- Anthropic - Share and unshare chats
- Anthropic - Publish and share artifacts
- WIRED - Private Claude Chats Exposed in Google and Bing Search Results
- Search Engine Journal - Indexed Claude Chats Show Why Disallow Is Not Noindex
- Google Search Central - Block Search indexing with noindex
- Google - Remove web results from Google Search
- OpenAI - ChatGPT Shared Links FAQ
- OWASP - Sensitive Information Disclosure
- NIST - AI Risk Management Framework
- European Data Protection Board - Personal data breaches
- European Union - Artificial Intelligence Act
- ShareChat - A Dataset of Chatbot Conversations in the Wild
Sources checked 29 July 2026. This article provides general operational guidance. It is not legal advice, a compliance assessment, a security audit or a forecast of commercial results.