An AI share link is not private: what should your company control?

You prepare a summary in Claude, ChatGPT or another AI assistant. To ask a colleague for feedback, you click Share.

You think you are sending a document to one person. Depending on the product and account, you may have created a page that anyone with the link can open.

The problem is not that every AI conversation is public. The problem is sharing without knowing which object leaves the workspace, who can open it and how access will end.

Answer in 60 seconds

  • A private conversation, an internal share and an anyone-with-the-link page are not the same space.
  • “Anyone with the link” does not mean “approved recipients only”.
  • What becomes visible depends on the object and account: conversation, artifact, file, export or connected-tool output.
  • Revoking a link, unpublishing an artifact and removing a search result are separate actions.
  • A useful AI policy gives staff a workable route: what they may share, where, who owns it and what to do when something goes wrong.

In this article

  1. What the Claude incident shows
  2. Private, internal, public or indexed
  3. What becomes visible depends on the object
  4. Use the Share button test
  5. What if the link has already circulated?
  6. What your AI use policy should add
  7. Conclusion
  8. Frequently asked questions

1. What the Claude incident shows

Anthropic says Claude chats are private by default. On Free, Pro and Max accounts, a user can then create a snapshot that anyone with the link can view (Anthropic).

Some of those public pages appeared in Google or Bing. Anthropic said it did not provide a directory or sitemap. A link could still be discovered after somebody placed it somewhere a search engine could crawl (WIRED).

The exact technical cause remains uncertain. Checks performed at different times found different configurations. This should not be reduced to a simple story about one missing tag (Search Engine Journal).

The more useful lesson is stable: a public link can travel beyond its first recipient.

This is not unique to Claude. OpenAI warns that a copy imported by another user may remain in that user’s history after the original ChatGPT shared link is deleted (OpenAI). Researchers have also studied public links from several assistant platforms. That establishes a cross-platform publication surface; it does not prove that every share was accidental (ShareChat).

2. Private, internal, public or indexed

Inside a team, the word “shared” sounds reassuring. In a product, it can describe four different states.

StateWho can open it?Useful control
PrivateAuthorised usersIdentity, permissions and revocation
InternalSigned-in organisation membersMembership, project access and attachments
Anyone with the linkAnyone who receives or finds the URLClean content, owner and inventory
Indexed or copiedSearch users, an archive or somebody holding a copySource revocation, search removal and copy handling

A difficult-to-guess URL is not access control. It can be forwarded, published or retained elsewhere.

Google also explains that a noindex instruction works only when its crawler can read it. A robots.txt rule controls crawling; it does not make a public page confidential (Google Search Central).

For sensitive information, the relevant control remains access: authentication, limited permissions or no public publication.

3. What becomes visible depends on the object

Do not rely on the word Share. Check the object and account.

ObjectAudience currently described by AnthropicPoint to check
Free, Pro or Max chatAnyone with the linkEarlier messages and displayed artifacts are visible
Consumer-published artifactAnyone with the linkIt can be used, copied or embedded elsewhere
Team or Enterprise chat or artifactAuthenticated organisation membersProject rights and attachments still matter

For a consumer chat, Anthropic says the original attached file is not included in the snapshot. The conversation and Claude’s answers remain visible. Information quoted or summarised from the file can therefore appear on the shared page.

For an artifact shared inside Team or Enterprise, Anthropic says authorised viewers may gain access to attachments from the source conversation (Anthropic - artifacts).

“Files are never shared” would therefore be the wrong rule.

Apply the same check to screenshots, exports, copied text and connected-tool output.

4. Use the Share button test

Before creating a link, answer five questions.

  1. What does the recipient need? The complete conversation, one answer or only the conclusion?
  2. What is actually on the page? Customer or employee data, contracts, non-public pricing, code, credentials, internal documents or strategy?
  3. Who can really open it? One person, a project, the organisation or anyone with the link?
  4. Who remains responsible? Who records, reviews and revokes the link?
  5. What private alternative should staff use? An internal project, permissioned folder, business workspace or cleaned document?

OWASP identifies sensitive-information disclosure through LLM inputs and outputs as a risk that requires data handling and access controls (OWASP). NIST’s voluntary AI Risk Management Framework also places governance, context, measurement and response across the AI lifecycle; using it does not prove a control works in your environment (NIST).

The inventory does not need to duplicate the content. Product, object, audience, owner and status may be enough.

Prohibition without a usable route encourages shadow tools. The approved path should be the easiest path.

Start by reducing the exposure.

  1. Revoke the chat share and unpublish related artifacts separately.
  2. Preserve the useful facts without redistributing the content.
  3. Identify what was visible and who could access it.
  4. Rotate exposed passwords, keys or tokens immediately.
  5. Look for public posts, search results, previews and copies.
  6. Involve the privacy lead, security lead, legal counsel, HR or contract owner according to the content.
  7. Fix the route that allowed the mistake.

Removing a Google result does not remove the source page. Disabling the source does not guarantee the immediate disappearance of every copy. Track the actions separately (Google).

If personal data was exposed without authorisation, the organisation may need a breach assessment under the laws that apply to it. Under the GDPR, documentation, authority notification and communication to affected people depend on the facts and level of risk; there is no universal response for every public link (European Data Protection Board).

6. What your AI use policy should add

Many policies name approved tools and prohibited inputs. They often miss one question: how does a conversation leave the tool?

Add:

  • approved accounts and sharing functions;
  • prohibited data and audiences;
  • covered objects: conversations, artifacts, files, exports and screenshots;
  • an owner and review or revocation trigger;
  • the approved private alternative;
  • an incident route and the specialists to involve.

For organisations operating in the EU, Article 4 of the AI Act requires AI literacy measures suited to people and context. Showing staff what the real Share control does is more useful than generic awareness. A policy or training session does not, by itself, establish compliance or security.

For the wider operating model, see our AI governance checklist for SMEs.

Conclusion: control the exit, not only the input

A useful policy does more than tell staff what they may ask an AI assistant. It explains how to share, with which audience, who remains responsible and how access ends.

Take one real sharing route. Check it from end to end. Fix the first missing control.

Bring us one sharing path. We’ll give you an honest read.

Bring the approved-tool list, current policy and one sharing route without sensitive content. IZZY can map the move from private conversation to internal collaboration or public publication, then identify the first missing operating control.

The answer may be a clearer rule, an account setting, a private workspace, training, an Agent Readiness Audit, a more controlled AI integration or a specialist decision. If a larger engagement is not justified, the call should make that clear too.

Frequently asked questions

No. Anthropic describes it as private by default. A user must create a public snapshot or publish an artifact. Team and Enterprise currently use organisation-only sharing.

No. It may require neither identity nor individual authorisation. The link can be forwarded, published, archived or copied.

Not necessarily. Revoking the source, removing a search result and dealing with external copies are separate actions.

No. That depends on the content, audience, applicable law and risk. Preserve the facts and involve the responsible privacy or legal specialist.

No. Connect it to the accounts people actually use, product settings, a private route, an inventory and a workable incident process.

Sources

Sources checked 29 July 2026. This article provides general operational guidance. It is not legal advice, a compliance assessment, a security audit or a forecast of commercial results.

izzy.agency teamEngineering & product insights from the izzy.agency team.We use AI in our research and preparation. The analysis, the sourcing and the writing are ours. How we work