Hundreds of user interactions with Anthropic's Claude AI were recently discovered to be accessible through public search engines. These logs, which appeared in search results when specific site-related queries were used, contained a variety of sensitive data, including personal contact details, CVs, and proprietary corporate information.

The issue stemmed from the chatbot's "share" feature. While users were informed that anyone with a link could view the conversation, the interface did not explicitly warn that these links could be indexed by search engines like Google, Bing, Brave, and Duck Duck Go. Reddit users first identified the exposure, noting that at least 25 pages of search results contained over 200 distinct conversations, some of which were only weeks old.

Advertisement

An Anthropic spokeswoman stated that users retain control over their shared links, noting that they are "not guessable or discoverable unless people choose to share them themselves." She added that once a conversation is shared, it becomes public content that may be archived by third-party services. Following the discovery, the search availability of these logs was removed over the weekend, likely through the use of standard tools that allow website owners to block indexing.

This incident follows similar privacy concerns involving other major AI platforms. Last year, both OpenAI's ChatGPT and X's Grok experienced issues where user chat logs were inadvertently made accessible via online search. A Google representative emphasized that the company respects directives from website owners regarding which pages are crawled and indexed, noting that the responsibility for controlling public access lies with the site operators.

Source: BBC News