{ "@context": "https://schema.org", "@type": "Article", "headline": "Your AI chats might be more public than you think - here's how to check", "description": "Thousands of Claude and Google Drive users have had shared links indexed by search engines. Here's what happened, and how SMEs using Claude, ChatGPT, Copilot and Gemini can check their exposure.", "author": { "@type": "Person", "name": "Richard Goddard", "jobTitle": "Marketing Director", "worksFor": { "@type": "Organization", "name": "Advantage Business Systems Limited" } }, "publisher": { "@type": "Organization", "name": "Advantage Business Systems Limited", "url": "https://www.advantage.co.uk" }, "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.advantage.co.uk/intelligence-hub/cyber-security/keeping-ai-chats-and-files-private" }, "about": [ { "@type": "Thing", "name": "AI data privacy" }, { "@type": "Thing", "name": "Microsoft Copilot" }, { "@type": "Thing", "name": "Cyber security for SMEs" } ], "citation": { "@type": "CreativeWork", "name": "How to keep your Claude chats and Google files private", "url": "https://www.theguardian.com/us-news/2026/jul/28/how-to-keep-your-claude-chats-and-google-files-private", "publisher": { "@type": "Organization", "name": "The Guardian" } } }

For business management solutions email us or call 020 3004 4600

Your AI chats might be more public than you think - here's how to check

Over the past couple of weeks, thousands of Claude users discovered something unsettling: conversations they had shared via a public link were turning up in Google and Bing search results. As first reported by the Guardian, some of those chats contained health information, internal company documents and personal details. A similar problem has been found with Google Drive files set to "anyone with the link", many of which have been sitting there, indexed and searchable, since as far back as 2003.

Anthropic's position is that it doesn't submit chat directories or sitemaps to search engines, and that a shared link only becomes discoverable if someone posts it publicly somewhere else, at which point it can get crawled and archived like any other web page. That's technically true, and it's also exactly how these things end up exposed. A link shared "just with a colleague" gets forwarded, pasted into a Slack channel, dropped into a support ticket, or posted on a forum, and from there it's one crawl away from being public. As one privacy researcher put it: sharing is fragile. Once a link exists, you've lost control of where it travels.

For an SME, this isn't just an awkward headline. If your team is using Claude, ChatGPT, Copilot or Gemini day to day, the odds are good that someone, somewhere, has generated a shareable link to a chat or a document without thinking too hard about who might eventually see it.

What actually happened

Claude allows users to create a public link to a chat, similar to sharing a Google Doc. Anyone with that link can view the full conversation, including any files or artifacts attached to it. Because many of those shared pages didn't carry a "noindex" tag, search engines were able to crawl and list them once the links were shared anywhere public. Google Drive has the same underlying issue: documents set to "anyone with the link can view" are discoverable the same way, and a Guardian search using this technique turned up exam papers, confidentiality agreements and site-specific test results going back over two decades.

The important distinction: nothing was hacked, and private, unshared conversations were never exposed. This was about content that users had actively chosen to share, without realising how far "shared" could travel.

What to check, tool by tool

Claude Go to Settings > Privacy > Shared chats (and Shared artifacts) and review what's listed. Anything you don't recognise, or don't need publicly accessible, can be set back to private from there.

Google Drive There's no single dashboard for this, so it means going document by document, checking the "Share" settings and switching general access from "Anyone with the link" to "Restricted" or to named people, unless there's a genuine reason for it to stay open.

Copilot (Microsoft 365) Copilot inherits whatever permissions already exist on your SharePoint, OneDrive and Teams content, so this is less about a Copilot-specific setting and more about your underlying file permissions. This is exactly the kind of oversharing our Microsoft Copilot Readiness Assessment is designed to catch before Copilot goes live, but it's worth using this story as a prompt to review "anyone with the link" sharing across your tenant generally, not just AI-adjacent files. (For background on what Copilot actually does with your data, see our glossary entry.)

ChatGPT and Gemini Both offer a temporary or incognito-style chat mode that avoids saving history and isn't used for model training. Neither is a substitute for good judgement about what goes into the chat in the first place.

The bigger point for a business

Individually, none of this is dramatic. Collectively, it's a reminder that AI tools sit inside the same data governance conversation as email, file shares and CRM records, not outside it. A few habits go a long way:

  • Treat a "shareable link" the same way you'd treat an email attachment: fine for the person it's intended for, not something to assume stays contained.
  • Keep genuinely sensitive material (client data, HR records, financial details, credentials) out of AI chat tools altogether unless you're using an enterprise deployment with proper data controls.
  • Periodically audit shared links and stale permissions, in Claude, Drive and your Microsoft 365 tenant alike, rather than assuming they'll never resurface.
  • If in doubt, apply the postcard test: if you wouldn't be comfortable with the content on the back of a postcard, don't share it via an open link.

This ties into a wider theme we've been tracking on the Intelligence Hub: AI adoption is moving faster than most SMEs' governance. Our piece on what the new wave of Copilot rollouts means for smaller businesses covers the same ground from the deployment side.

Get a proper picture of your exposure

You don't need to take our word, or Google's, for how exposed your business currently is. Two starting points:

  • If AI tools are already in use across your team, our Cyber Security Services can review sharing settings, permissions and data handling across your Microsoft 365 tenant, not just the AI layer.
  • If you're planning a Copilot rollout, or have one underway, our Microsoft Copilot Readiness Assessment examines data and permissions across SharePoint, OneDrive and Teams specifically, so oversharing gets caught before Copilot can surface it to the wrong people.

Get in touch on 020 3004 4600 or hello@advantage.co.uk, or contact the team to talk it through