Claude Reveals Sensitive Data on Google

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Accessible Claude Discussions on Google
This weekend, Reddit users discovered that discussions and artifacts, including interactive mini-apps, shared via Claude, an artificial intelligence platform, were publicly accessible on Google. By using search operators like "site:claude.ai/share," they were able to access a multitude of shared conversations. Some of these discussions contained sensitive information such as medical records, private business documents, as well as names and phone numbers of children.
Sharing Feature at Fault
The issue appears to stem from Claude's "share a discussion" feature. This option allows users to create links that, once shared, enable anyone with the URL to access the conversation or project. Claude's interface warns that "anyone with the link can see," and the language used implies that this feature is primarily intended for restricted sharing with friends or colleagues, not for public dissemination on the Internet. Unlike Google Docs, where documents do not automatically become public, Claude seems to have allowed for unintended exposure.
Anthropic's Response
Anthropic, the company behind Claude, seemed to place the responsibility for this exposure on the users. The company explained to TechCrunch that shared links are indexed by search engines only if they are posted on forums or social networks. A link sent privately should not appear in search results. Amie Rotherham, a spokesperson for Anthropic, clarified that the company does not share directories of discussions or sitemaps with search engines like Google. The links are supposed to be non-guessable unless voluntarily shared by users.
Discovery and Resolution
The leak was initially reported by a Reddit user on Saturday and was covered by 404 Media on Monday morning. By Monday afternoon, a test search on Google following the method described in the Reddit post returned no results, suggesting that the exposure had somehow been rectified. Before this fix, Futurism had found sensitive documents, including medical reports and personal information about children and employees.
Inappropriate Content Generated
The exposed artifacts also included code and work notes. Fortune reported that a discussion labeled "shared by Anthropic" showed Claude generating erotic literature, which goes against Anthropic's usage policy that explicitly prohibits the creation of sexually explicit content. It remains unclear how this content was generated, and Anthropic has not yet commented on this particular case.
Google's Position
Ned Adriance, a spokesperson for Google, stated that neither Google nor any other search engine controls which pages are made public. These pages have been indexed by several search engines. Google provides website owners with tools to decide whether their pages can be crawled or indexed, and adheres to these guidelines.
Previous Incidents
Last year, a similar issue was reported by Forbes, where Google estimated it had indexed just under 600 Claude conversations before they were removed from search results. Although the extent of the current exposure is not confirmed, several users have reported finding shared conversations in the same manner. Additionally, 404 Media had reported that a researcher had extracted about 100,000 ChatGPT conversations set to be shared publicly.
Checking Shared Discussions
To check which Claude discussions you have shared publicly, you can access "Settings -> Privacy -> Shared Discussions" in the Claude interface.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.