← the record
AIAAIC-2031

ChatGPT exposes user chats to Google search

Sensitive user conversations on ChatGPT became searchable on Google due to a flawed sharing feature, impacting thousands of individuals and organisations across the world. What happened A “Share” option added by OpenAI let users create public links to their chats; some could also be marked as "discoverable," making them searchable by Google and other engines. As a result, over 100,000 discussions - including admissions of fraud, confidential business contracts, non-disclosure agreements, mental health issues, resumes, and personal advice - were exposed to the public by search crawlers and indexed on Google. The leak affected both professionals (such as doctors, lawyers and marketers) and individuals, with consequences including privacy and confidentiality violations and loss of confidence and reputational damage. It also raised the prospect of risks to personal safety and individual and organisational security, and exposed organisations using the tool to potential regulatory actions and legal liability. O penAI disabled the feature hours after it rolled out, describing it as a "short-lived experiment". However, the scraped dataset remained archived and outside of OpenAI or Google’s control - meaning the exposed data cannot now be fully deleted or retracted. Why it happened The incident resulted from poor product design choices and a lack of effective safeguards in ChatGPT's "Share" feature. OpenAI's robots.txt allowed public search engines to crawl shared paths, and a short-lived option permitted users to share and mark chats as discoverable; many users appeared to be unaware this made their private conversations open to everyone and the company failed to spell out the associated risks. What it means The fracas demonstrates the need for AI designers and developers to understand and ensure that the needs, expectations and behaviours of the users and other important stakeholders of their systems are incorporated. Specifically, it highlights the need for stronger privacy-by-default settings and clearer user warnings and transparency. System 🤖 ChatGPT Developer: OpenAI Country: Global Sector: Multiple Purpose: Share chat conversations Technology: Chatbot; Generative AI Issue: Confidentiality; Privacy; Security; Transparency

Date it happened
2025-07-01
Organisation involved
ChatGPT users
Product, system or model
ChatGPT
Where this came from
Share this incident
XLinkedInFacebookWhatsAppEmail
Attribution

This incident was imported from AIAAIC and is used under CC BY-SA 4.0. Our additions to it — the structured fields, the translation, the checks against other reports — are published under the same licence.

This is a record of what was reported, not a finding that anyone broke the law. If it names your organisation and you believe it is wrong, the corrections process is free and open to everyone.