Claude Chat Leak Tests NZ’s AI Rules as Agencies Race Ahead


New Zealand’s public service has been told, in blunt terms, to stop being “scared of AI” and start using it.

That directive just collided with an awkward reminder from across the Tasman and beyond: private conversations shared via Anthropic’s Claude chatbot appeared in Google search results, exposing everything from medical records to login credentials. In the AI era, “share” and “private” are proving to be very different words.

For the public servants now expected to draft policy and summarise reports with AI assistants, for the accountants at small firms pasting client spreadsheets into a chatbot, and for the university researchers running grant applications through Claude, this is not a curiosity story about one chatbot’s bug. It is a governance problem.

New Zealand’s Privacy Act 2020 puts clear obligations on any organisation handling personal information, and those obligations don’t evaporate the moment an employee clicks “share.”

Where the safeguard broke down

The root cause is a gap between what Claude’s sharing feature promises and what it technically enforces. Clicking “Share” on a Claude conversation generates a public URL meant for sending to one other person — the interface tells users that anyone holding the link can open it, which sounds like a closed loop. It isn’t.

Anthropic relies on a robots.txt instruction, in place since roughly September 2025, to ask search crawlers to leave shared-chat pages alone.

That instruction is a request, not a lock: if a shared link gets posted anywhere else on the open web, Google and Bing’s own crawling rules allow them to index it regardless, unless the page is separately marked “noindex.” As far as reporting has shown, Claude’s shared pages carried no such tag.

That loophole is what allowed a basic Google search trick — appending “site:claude.ai/share” to a query — to pull up a public archive of conversations and Artifacts (Claude’s term for the interactive apps and documents it generates) that were never meant to be discoverable.

What turned up ranged from harmless coding snippets to material with real stakes: clinical data tied to named patients, internal corporate records, staff performance reviews, and live API keys and login credentials.

Anthropic’s position is that it never hands search engines a directory or sitemap of shared chats, and that the links themselves can’t be guessed, meaning exposure occurs only when a user (or someone they sent the link to) posts it somewhere public.

Google’s line was the mirror image: it doesn’t decide what gets published on the web, only whether to honour the crawling instructions a site gives it, and, in this case, it says it did. Neither position is really in dispute; the failure sits in the space between them. The exact search queries that had been surfacing the chats stopped returning results within days, but any individual link already shared elsewhere kept working.

A comparable indexing incident hit Claude last year, and both ChatGPT and Grok have separately had user conversations turn up in search results.

Why it lands differently in Wellington

The timing matters. Finance Minister Nicola Willis has announced plans to cut around 9,000 public service roles by 2029, framing wider use of AI as one of the tools that will allow a smaller government workforce to keep functioning.

She’s described the current public service as slow to adopt AI and reliant on fragmented, overlapping IT systems. As more departments lean on tools like Microsoft Copilot and ChatGPT-style assistants for drafting and administrative work, the assumption has to be that staff will, at some point, share a chat externally — deliberately or by accident.

A leaked link containing a policy draft, a procurement document, or citizen data is a different order of problem than a leaked customer support transcript.

New Zealand’s Office of the Privacy Commissioner has already told organisations that relying on an AI tool doesn’t remove their obligations under the Privacy Act’s 13 Information Privacy Principles. If an employee shares an AI conversation containing customer or citizen data, the organisation, not the AI vendor, carries the accountability. That reframes the Claude story away from “the chatbot made a mistake” and toward employee training, data-handling policy, and internal AI governance.

SMEs have the most to lose from a single click

New Zealand’s economy runs on small and midsize businesses, many of which have adopted AI quickly precisely because they lack dedicated IT teams. Research from 2degrees and Deloitte Access Economics found that 82% of New Zealand businesses now use AI in some form, and that AI-adopting SMEs earned roughly 4.3% more in revenue than comparable non-adopters.

That kind of return is exactly why smaller firms keep pasting contracts, financial spreadsheets, HR files, and customer emails into chatbots, often without a formal policy on what should never go in.

For those businesses, the Claude incident is a clear reminder that a share link can mean “anyone with the link” and, occasionally, “anyone who finds it through search.”

What to do about this

Anthropic advises users to check Settings > Privacy > Shared Chats and revoke any links no longer needed — a five-minute task worth adding to any workplace AI checklist.

Beyond that, New Zealand organisations already sitting under Privacy Act obligations have concrete options: extend existing data-handling policies to explicitly cover AI chat exports and share links, add AI tools to the assets covered by a Privacy Impact Assessment, and set a default policy that no share link leaves the building without a second person checking what’s in it.

Treating every “share” button as potentially public, rather than private, costs nothing and would have stopped this particular leak before it started.

https://assets.techrepublic.com/uploads/2026/07/unnamed-3.png?f=jpeg



Source link
Joseph Ofonagoro

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img