Anthropic、Claude の共有チャットや Artifacts が Google に流出する可能性を警告
Anthropic は、ユーザーの Claude 共有チャットや Artifacts が意図せず Google に保存されるリスクがあるとして注意を呼びかけた。
AI深層分析を開く2026年7月28日 10:04
AI深層分析
キーポイント
Google 検索による漏洩の発覚
Reddit ユーザーが「site:claude.ai/share」などの演算子で Google を検索した結果、Claude の共有リンク経由で公開された会話や Artifacts が大量に検索結果に表示されていることが確認された。
機密情報の混在
漏洩したコンテンツの中には健康記録、企業の非公開文書、そして子供の名前と電話番号といった極めて機微な個人情報が含まれている事例が報告されている。
共有機能の意図との乖離
Claude のインターフェースは「リンクを知っている誰でも閲覧可能」と警告しているが、これは友人や同僚への共有を想定したものであり、インターネット全体に公開されることを意図していないと解釈されている。
競合他社との比較
Google Docs にも類似のリンク共有機能があるが、同社はドキュメントが公衆検索エンジンにインデックスされないよう対策を講じており、Claude の現状はこれと対照的である。
検索結果への露出はユーザーの公開行為によるもの
Anthropic は共有リンクが検索結果に表示されるのは、ユーザーがフォーラムや SNS などで公開した場合に限られると説明している。同社はチャットディレクトリやサイトマップを検索エンジンに提供していないため、リンクは推測不可能で発見不能であると主張する。
重要な引用
An untold number of Claude chats and Artifacts ... were found publicly searchable on Google over the weekend
Some reportedly contained health records, private company documents, and the names and phone numbers of children.
The language clearly implies that the feature is mainly intended to allow users to share their chats with friends, colleagues, and small groups — not the whole internet.
"We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google."
編集コメントを表示
編集コメント
AI ツールの共有機能は利便性を高める一方で、検索エンジンによる自動インデックス化という予期せぬリスクを伴う。開発側は「リンク限定」の意図が技術的に守られるよう、Robots.txt やメタタグなどの対策を再検討する必要があるだろう。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
先週末、Reddit のユーザーが「site:claude.ai/share」のような検索演算子を Google で入力したところ、共有された会話が一覧表示される現象が発見されました。これにより、Claude のチャットや Artifacts(ユーザーが Claude 内で構築できるインタラクティブなミニアプリやドキュメント)の無数の事例が、公的に検索可能になってしまったことが明らかになりました。中には健康記録や非公開企業の文書、さらには子供の名前と電話番号が含まれていたケースも報告されています。
この問題は、Claude の「チャット共有」機能に起因しているようです。この機能を使えばユーザーはリンクを作成でき、その URL を持つ誰でも会話やプロジェクトを閲覧できるようになります。ただし Claude のインターフェースでは、「リンクを知っている誰でも閲覧可能」と警告されており、これは主に友人や同僚、小規模なグループとの共有を想定した機能であることを明確に示しています。例えば Google ドキュメントにも類似の機能がありますが、あちらの文書が公的に検索可能になることはありません。
image「Keep private」オプションを選択した際の Claude の「チャット共有」機能のスクリーンショット画像クレジット: Screenshot/TechCrunch
image「Create public link」オプションを選択した際の Claude の「チャット共有」機能のスクリーンショット画像クレジット: Screenshot/TechCrunch
Anthropic は今回の情報漏洩について、ユーザー側の責任を問うかのような対応を示しました。TechCrunch の取材に対し同社は、「共有リンクが検索結果に表示されるのは、フォーラムや SNS 投稿など、検索エンジンが閲覧可能な場所に公開された場合に限られる」と説明。個人間で送られたプライベートなリンクは検索に現れないとも付け加えています。
広報担当のエイミー・ロザーサム氏は解説の中でこう述べています。「私たちはユーザーが Claude の会話内容を公的に共有するかどうかを自分でコントロールできるようにしています。プライバシー原則に沿って、チャットディレクトリやサイトマップを Google などの検索エンジンと共有することはありません。これらの共有リンクは、本人が自ら公開しない限り、推測したり発見したりすることはできません。誰かが会話を共有した場合、そのコンテンツは公的にアクセス可能になります。他のウェブ上の公開コンテンツと同様に、サードパーティのサービスによってアーカイブされる可能性があります」。
この問題は土曜日に Reddit のユーザーによって初めて指摘され、月曜日の朝には 404 Media が報じました。
月曜日の午後、TechCrunch が Reddit の投稿で示された方法に従って Google で検索したところ、結果は表示されませんでした。これは何らかの形で問題が解決された可能性を示唆しています。
問題が修正される前、Futurism は「実在する患者の詳細な医療報告書や、患者名が含まれる臨床試験の結果、小学生の名前と電話番号を共有した文書、社内限定の会社文書、従業員の個人情報を含む従業員レビュー」などが見つかったと報じていました。
公開されたアーティファクトにはコードや作業メモも含まれていました。少なくとも 1 つのケースでは、Fortune が報じたように「Anthropic によって共有」とラベル付けされたチャットで、Claude がエロティックなコンテンツを生成している様子が Google の検索結果に表示されていました。
Anthropic の利用ポリシーでは、性的に露骨なコンテンツの生成は明確に禁止されています。しかし、繰り返しや創意工夫を凝らしたプロンプトを通じて、AI チャットボットが自らのガイドラインに反するコンテンツを生成させるという事象は、主要な AI モデルにおいて定期的に表面化しているパターンです。
公開されたチャットから、問題のコンテンツがどのようにして生成されたのかはまだ明らかになっておらず、Anthropic は TechCrunch のこの特定の事例に関するコメント依頼に対してまだ回答していません。
Google のスポークスマン、ネッド・アリアンス氏は TechCrunch に対し、「Google や他の検索エンジンがウェブ上のどのページを公開するかを制御しているわけではなく、これらのページは多くの検索エンジンでインデックス化されました。サイト運営者には、ページのクロールやインデックス化を決定するための明確なコントロールを提供しており、私たちは常にその指示を尊重しています」と述べています。
昨年、フォーブスは同様の問題を報じました。数百件の Claude のチャットが検索エンジンにインデックスされたケースです。当時、Google は検索結果からページが消えるまでに約 600 件未満の会話をインデックス化していたと推計していました。今回の露出規模が昨年と同程度かどうかは独立した調査で確認されていませんが、複数のユーザーが、昨年のキャッシュを特定するために使われたのと同じ Google の検索クエリを通じて共有された会話を見つけたと報告しています。
また昨年、404 Media はある研究者が、公開用に設定されていた約 10 万件の ChatGPT の会話をスクレイピングできたことを報じていました。
Claude で公開リンクを有効にしたチャットを確認するには、「設定」→「プライバシー」→「共有されたチャット」へ移動してください。
当記事は、リンクを通じて購入が行われた場合に、編集部が少額のコミッションを受け取る可能性があることをお知らせするものです。ただし、これは編集の独立性には一切影響しません。
著者のロレンツォ・フランチェスキ=ビッチエライ氏はテッククリンチのシニアライターであり、ハッキングやサイバーセキュリティ、監視技術、プライバシー関連のニュースを専門に担当しています。
ロレンツォ氏への連絡や、彼からの outreach(接触)の真偽を確認したい場合は、lorenzo@techcrunch.com までメールを送るか、Signal で +1 917 257 1382 の暗号化メッセージ、または Keybase/Telegram の @lorenzofb へご連絡ください。
原文を表示
An untold number of Claude chats and Artifacts — the interactive mini apps and documents users can build inside Claude — were found publicly searchable on Google over the weekend, after Reddit users discovered that typing search operators like “site:claude.ai/share” into Google surfaced a long list of shared conversations. Some reportedly contained health records, private company documents, and the names and phone numbers of children.
The issue appears to have originated from Claude’s “share chat” feature, which allows users to create links that enable anyone with the assigned URL view a conversation or project. “Anyone with the link can view,” warns Claude’s interface. The language clearly implies that the feature is mainly intended to allow users to share their chats with friends, colleagues, and small groups — not the whole internet. Google Docs, for example, offers a similar feature and those documents don’t end up publicly accessible on Google.


Anthropic appeared to blame users for the exposure. When asked about what happened, the company told TechCrunch that share links only appear in search results when they’ve been posted somewhere search engines can see, like a forum or social media post; it added that a link sent privately to someone stays out of search.
Spokeswoman Amie Rotherham added in an explainer that: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves. When someone shares a conversation, they are making that content publicly accessible, and like other public web content, it may be archived by third-party services.”
The issue was first flagged by a Reddit user on Saturday and was first reported by 404 Media on Monday morning.
As of Monday afternoon, a test search by TechCrunch on Google following the method outlined in the Reddit post does not return any results, suggesting that the exposure has somehow been remediated.
Before the issue was fixed, Futurism reported finding “a detailed medical report of a real patient, clinical trial results that included patient names, documents sharing the names and phone numbers of primary school-aged children, company documents marked for internal use only, and employee reviews that included personal information about workers.”
Exposed Artifacts included code and work notes. In at least one case, Fortune reported, a chat labeled “shared by Anthropic” also showed Claude producing erotica.
Anthropic’s usage policy explicitly prohibits Claude from generating sexually explicit content, and getting a chatbot to produce material against its stated guidelines — through repeated or creatively framed prompting — is a pattern that has surfaced periodically across most major AI models. It isn’t yet clear from the exposed chat how the content in question was generated, and Anthropic has not yet responded to TechCrunch’s request for comment on this specific case.
Google spokesperson Ned Adriance told TechCrunch that “Neither Google nor any other search engine controls what pages are made public on the web, and these pages were indexed across many search engines. We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”
Last year, Forbes reported a similar issue in which hundreds of Claude chats were indexed by search engines — at the time, Google estimated it had indexed just under 600 conversations before the pages disappeared from search results. How closely the current exposure tracks that scale hasn’t been independently confirmed, though multiple users reported finding shared conversations through the same type of Google search query used to surface last year’s cache. Also last year, 404 Media reported that a researcher was able to scrape around 100,000 ChatGPT conversations that had been set to be shared publicly.
To review which Claude chats you set to have a public link, go to Settings -> Privacy -> Shared Chats.
*When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.*
Lorenzo Franceschi-Bicchierai is a Senior Writer at TechCrunch, where he covers hacking, cybersecurity, surveillance, and privacy.
You can contact or verify outreach from Lorenzo by emailing lorenzo@techcrunch.com, via encrypted message at +1 917 257 1382 on Signal, and @lorenzofb on Keybase/Telegram.
AI算出
主要ニュースainew評価高い
Anthropic の Claude システムにおける検索エンジンへの意図しない公開という、実証されたセキュリティ事象を扱っており、AI 関連の主要なトピックであるため ai_relevance は最高値となる。また、既存記事がない中で具体的な事例(医療記録や個人情報など)とベンダーの公式見解を報じているため novelty も高い。検索流入の可能性は「Claude」という明確な製品名があるため中程度以上だが、バージョン番号などの極端に特定されたキーワードはない。日本固有の企業情報や法規制に関する記述はほぼないため、日本の開発者・消費者への直接的な付加価値は限定的である。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 75
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み