Late last month, a quiet but important story broke. Links that people had used to share conversations with Claude, Anthropic’s AI assistant, turned up indexed on Google and Bing, meaning conversations some people had assumed were private became searchable by anyone.
Wired reported that some of what surfaced included genuinely sensitive material such as medical details and personal documents; things nobody would have wanted findable with a quick search.
Anthropic stated the sharing feature itself had worked as intended – a shared link is a public link by design – and that the indexing issue has since been fixed.

Why this matters even if you’ve never used Claude
This article isn’t here to scare you into eliminating the use of AI, it just reiterates what we’ve always believed: people trust people, not platforms. AI is changing how content is getting discovered, but it’s raising the bar on substance, not lowering it.
Most businesses now have AI tools somewhere in the mix – whether that’s through a formal policy or, more likely, people quietly using ChatGPT, Claude, Copilot or similar to draft emails, summarise documents, or think through a problem faster. Often this happens without anyone in the business having decided, deliberately, that it should.
That’s not a criticism. It’s just how new tools spread. But it does mean the questions worth asking aren’t really about any one AI product. They’re about your business generally:
- What information is going into these tools? Client details, employee records, and commercial terms are the kind of thing that shouldn’t end up somewhere you haven’t checked.
- Do you know what happens to it once it’s in there? Not every tool handles data the same way, and the terms are rarely written for a quick read.
- Would you know if something had gone wrong? The Claude story only came to light because someone happened to notice. Most businesses wouldn’t necessarily find out that quickly.
None of this is about banning AI tools or being afraid of them. It’s about the same due diligence you’d apply to any new supplier or system – just applied to something that’s often adopted informally, one person at a time, without anyone stepping back to ask the obvious questions.
The employment angle is easy to miss
If your staff are using AI tools day to day, this isn’t just a data protection question – it’s a people one too. Do they know what’s safe to paste into a chat window and what isn’t? Is there any guidance at all, or is everyone making it up as they go?
A well-drafted policy on AI use at work does a lot of quiet good here. Getting it right is a bit more nuanced than a quick memo, though. It means thinking through what your teams actually use AI for, where the real risks sit for your business, and how to word it so people genuinely follow it rather than skim past it. When it’s done well, it doesn’t need to be restrictive or heavy-handed; most people want to do the right thing, they just need it set out properly. It’s the kind of thing worth getting right before an incident forces the conversation, rather than after.
What we’d suggest
If your business hasn’t had a proper look at how AI tools are being used, the Claude story is a gentle prompt to do it now, to protect your business and client confidentiality. A few starting points are:
- Ask what AI tools are already in use across the business, informally or otherwise.
- Check what your existing supplier and confidentiality obligations say about third-party tools and data sharing.
- Put something in writing for staff – brief, clear, and genuinely usable – about what’s okay to share with an AI tool and what isn’t.
This is exactly the kind of practical, unglamorous groundwork that saves a business real trouble later. It’s not about the mistrust of AI; it’s about making sure that when something does happen (and eventually, something will), it doesn’t catch you by surprise.
