Skip to main content
Back to Blog
AI Security
Shadow AI
Data Governance
Enterprise AI
Leadership
CISO

Your Team May Be Publishing Your Secrets to Google.

Jason Oglesby

By Jason Oglesby · July 29, 2026

Last week you could type one search into Google and read thousands of people's private Claude conversations. Some of them had crypto keys in them. Some had legal questions people thought were confidential. All of it sitting on the open web, one query away from anyone who went looking.

Nobody hacked anything. That's the part you need to sit with.

It Wasn't a Breach. It Was a Feature.

Here's what actually happened. Claude has a "Share with link" button. You click it to send a conversation to a coworker. The problem was that those shared pages didn't carry a noindex tag, the small piece of code that tells Google not to list a page in its results. So the search engines crawled them, indexed them, and served them up to the world.

Anthropic fixed it fast once it surfaced, and the Google results dropped off quickly. On Bing and Brave they hung around longer. And this isn't new. OpenAI made the exact same mistake the year before and ended up killing the share feature entirely.

Two of the most sophisticated AI companies on the planet shipped the same data leak through a convenience feature. Read that again, because it tells you something about the tools your team is using every day.

The Model Was Fine. Your People Are the Attack Surface.

The leak wasn't a model failure. Claude worked exactly as designed. The failure was a human clicking a button that did more than they thought it did.

That's the real story here, and it has nothing to do with Anthropic. Right now, today, your employees are pasting things into AI tools. Customer lists. Draft contracts. Source code. Financial numbers. Then some of them click share to loop in a colleague, and they have no idea where that link actually goes or who can find it.

You didn't approve those tools. You don't control their settings. You can't see what's been pasted into them or what's been shared out of them. That's shadow AI, and it's the fastest-growing hole in most companies' security right now. The Claude incident is just the version that made the news.

Picture your best salesperson pasting an entire deal, pricing and all, into a free AI account to get help writing a follow-up, then sharing the polished result with a teammate over a link. Nothing about that feels reckless in the moment. It feels productive. And every step of it is invisible to you until the day that link, or that data, shows up somewhere it shouldn't. Multiply that by everyone on your team, every day, and you have the actual shape of the risk.

"We Don't Have an AI Policy" Is a Policy

Here's the uncomfortable truth for a lot of leaders. If you haven't decided how your company uses AI tools, you've still decided. Your policy is whatever each employee improvises in the moment, on whatever free tool they signed up for, with whatever data happens to be on their screen.

That's not a policy. That's a coin flip you're running hundreds of times a day with your company's confidential information.

Simple and Secure means locked down by default. It means the safe path is the easy path, so people don't have to think about it. Right now, for most companies, the risky path is the default and nobody's watching.

What To Actually Do

This isn't hard, it's just unglamorous, which is why most people skip it.

Give people approved tools. Pay for the business or enterprise tiers of the AI tools your team already wants to use. They come with admin controls, they don't train on your data, and they let you manage sharing. Free consumer accounts are where the leaks happen.

Write down what never goes into a public AI tool. Customer data, credentials, contracts, anything covered by an NDA. Make it one page. Make it clear. Make sure everyone has read it.

Train people on what "share" actually does. Most of your team has no idea that a share link can be public. Ten minutes of explanation prevents the headline.

Go look at what's already out there. Search for your own company's information the way an attacker would. You might not like what you find, but you need to know.

None of that requires a new model or a big budget. It requires deciding to do the boring work before it becomes an incident instead of after.

The next leak won't come from a hacker breaking in. It'll come from someone on your team clicking a button they trusted. The only question is whether you did the boring work first.

Everyone Says AI Doesn't Pay. ServiceNow Just Booked a Billion.

ServiceNow's AI just crossed $1B in annual contract value while the headlines say AI doesn't pay. Both are true. The gap is the most important lesson in enterprise AI.

Read article

The Self-Serve AI Dream Is Dead. Good.

OpenAI just started selling human engineers alongside its agents. The company that makes the models admitting the model was never the hard part. Implementation is.

Read article

Stop Betting Your Company on One AI Vendor.

DeepSeek V4 just went GA: near-frontier, open-weight, a tenth the price. The lesson isn't to switch to it. It's that betting your company on one AI vendor is exposure, not focus.

Read article