The uncomfortable thing about AI sharing is that it often feels private until it suddenly behaves like publishing.
That is the tension behind a new report from Digital Trends, which found that public Claude chat links and Claude Artifacts had been indexed by Google, making some shared AI conversations discoverable through search.
The important distinction is that this was not Google breaking into private Claude accounts. The pages involved were created through Claude’s own sharing surfaces: links users had generated to make a chat or Artifact public. But once those pages were available to the open web, some became searchable beyond the original audience the user may have imagined.
That gap between “I shared a link” and “this can appear in Google” is where the trust problem lives.
UPDATE, ITS WORSE THAN THE CHATS
the same thing is happening with shared artifacts. every app, doc, dashboard and tool people published from claude is also sitting indexed and searchable
people have already pulled up internal company dashboards, full project plans with client… https://t.co/ZzezhlDbom pic.twitter.com/Ljk3zzXL4N
— Om Patel (@om_patel5) July 26, 2026
Public links are still publishing
Digital Trends reports that indexed Claude pages could expose prompts and Claude’s responses from shared conversations. The same issue also affected Artifacts, Claude’s standalone outputs that users can create and share, such as documents, code-based projects, or interactive pieces.
Anthropic told the publication it had taken steps to stop shared Claude conversations from being indexed going forward, and that it was working on removing already indexed pages from search results. That matters, because the damage pattern here is familiar: a user creates a share link for a specific reason, then the web treats that link as a public page unless the product clearly tells search engines otherwise.
This is not just a technical SEO mishap. It is a product-language problem. “Share” sounds social. “Publish” sounds permanent. “Indexable” sounds like something only a search engineer thinks about. For most users, those distinctions collapse into one button.
And with AI chats, the contents can be more sensitive than a normal post. People use chatbots for work drafts, legal questions, personal decisions, health anxieties, client research, code, job applications, and private brainstorming. Even if a user chooses to share one conversation, they may not understand that the link could travel into a search engine and sit there outside the context of the original exchange.
The privacy UI has to catch up with AI behavior
Claude is not alone in facing this problem. AI products are increasingly asking users to treat outputs as shareable assets: chats, canvases, agents, generated apps, summaries, notebooks, and collaborative documents. The more useful these tools become, the more they blur the line between private workspace and public webpage.
That makes the interface more important than the model. Users do not need a lecture on robots.txt or noindex tags. They need products that make the exposure obvious before the link is created, and controls that let them revoke, unpublish, or audit what has already been shared.
We have seen similar control questions appear across social platforms, from supervision tools to privacy settings and post-level visibility. The difference with AI is that a single shared chat can contain both the question and the reasoning trail behind it. It is not just content; it is context.
For brands and teams using Claude or any AI assistant at work, the practical takeaway is simple: treat shared AI links as public unless the product explicitly says otherwise. Do not paste confidential prompts, client information, internal strategy, unreleased creative, or personal data into any conversation that may later be shared outside the workspace.
The bigger consequence is sharper. AI companies are no longer just competing on model quality. They are competing on whether users can understand where their words go after they click share.