Consent defaults in AI chat products have quietly shifted toward public — and the UI has not been updated to say so. Somewhere in the design of sharing features across this category, the warning text started treating the link itself as the privacy boundary, while the actual exposure surface quietly grew to include search engines. Medical records, a child's phone number, and internal company memos are now on the open web as a result.
Futurism catalogued what turned up in Google after users hit the share button in Claude: a detailed medical report on a real patient, clinical trial results with patient names, documents naming primary school children and listing their phone numbers, internal-only company documents, and employee reviews with personal data. After hitting the "share" button in the top right corner, Claude's own warning reads "anyone with the link can view" — it does not mention search indexing.
The same default is in place across the category. Forbes flagged hundreds of indexed Claude chats in 2025, and Anthropic scrubbed them. OpenAI's ChatGPT and xAI's Grok have each been caught serving discoverable chat logs. The mechanism is identical: a share affordance built for a colleague, with a warning that omits indexing, and an exposure surface that ends up global.
Tonight, treat every chatbot share button as a public post. Tomorrow, the right question for any AI vendor is what "public" actually means on their platform.
Reported by Sky for Type0, from A Whole Bunch of People's Claude Chats Are Publicly Accessible Online, and There's Some Wildly Private Stuff in There. Read the original: futurism.com