Industry Solutions Banking & Finance Healthcare Manufacturing Legal Government & Defense How It Works Cost Savings Knowledge Blog About Request Demo
4 min read

Your AI Vendor Shipped a Feature Last Night

A public cloud AI service can change what your data does without asking you. The 2025 ChatGPT share incident is the clearest example of what that costs.

An executive reading a breaking news story alone in an empty office before the working day has started
The exposure was created on someone else's roadmap. You find out on their timeline too.

Your AI vendor shipped a feature last night, and you will read about it in the news.

The quick version

On a multi-tenant public cloud AI service, the vendor decides what the product does and ships that decision to every customer at once. A convenience feature can change what data can leave your tenancy, your change control has no authority over it, and the discovery event is usually a headline. A dedicated deployment you control removes that specific category of risk.

In July 2025, OpenAI added a checkbox to the ChatGPT share dialog reading “Make this chat discoverable,” with one line of grey text underneath: “Allows it to be shown in web searches.” Users ticked it. Google crawled the resulting pages. A Fast Company investigation found roughly 4,500 conversations surfacing in a single site search, containing resumes, proprietary code, and legal strategy.

OpenAI removed the option within hours of the story running. Their CISO, Dane Stuckey, said the feature “introduced too many opportunities for folks to accidentally share things they didn't intend to.” That response was fast and candid, and the underlying decision was defensible when someone made it. None of that helped the enterprises whose material was already indexed.

Is the same thing happening again right now?

Possibly, and we are flagging it as unconfirmed rather than established. Reports circulating on Reddit and social media in late July 2026 describe Claude share links appearing in Google results. Coverage so far comes from smaller outlets and aggregators rather than the major security press, and we have seen no statement from Anthropic. Treat what follows as a developing account.

What people found is straightforward. A search for the share path returned page after page of conversation addresses, and opening them revealed real private material, including work product and personal details nobody appeared to have meant for an audience. The conversations were readable by anyone holding a link, and the links were listed in a search engine where anyone could collect them in bulk.

The mechanism differs from the ChatGPT case in a way that matters for anyone trying to prevent this. Anthropic's robots.txt disallows crawling of share paths, so Google was never permitted to read those pages, which is why the circulated results carry the “No information is available for this page” notice. The addresses reached the index anyway, from links posted elsewhere on the web.

That distinction is easy to dismiss as pedantry, and it is the opposite. Blocking a crawler and preventing indexing are different operations. Using the first to accomplish the second has a known failure mode, because a blocked page keeps collecting inbound links into the index while the crawler never sees the noindex tag that would remove it. The exposure persists precisely because the block appears to be working.

The reason to mention an unconfirmed story at all is that the shape is familiar. Whatever the final facts, the customers involved learned about it from strangers on a forum.

Why does this keep happening to careful companies?

Because the exposure came from a product decision, and on a multi-tenant public cloud service those decisions belong to the vendor. A security team can complete a rigorous review of an AI tool in March and find itself operating a materially different tool by July. The evaluation was accurate on the day it was performed. It describes software that has since been replaced underneath it.

This is not carelessness at the vendor. Commercial cloud AI products ship continuously to a shared codebase, which is why they improve so quickly. One release reaches every tenant at the same time, so the same velocity that produces useful features produces features nobody in your organization asked for or assessed.

What does that do to your change control?

It routes around it entirely. Your internal process governs what your own teams deploy, reviewed and approved on your own timeline. It carries no authority whatsoever over what a vendor deploys into a product your teams have already been cleared to use.

So the sequence runs backwards from how governance is supposed to work. The feature ships, users adopt it because it is convenient, exposure accumulates against no alarm anywhere in your environment, and the discovery event turns out to be a journalist or an outside researcher rather than your own monitoring. Then remediation happens on the vendor's schedule. OpenAI moved quickly. You are still waiting on someone else's rollout, and explaining an incident you had no ability to prevent.

What is different about running the model yourself?

The surface area is whatever you deployed, and it changes when you decide to change it. Nobody ships a sharing feature into your environment overnight. There is no public link format available, because there is no public. Data never leaves your network, so no external index exists that could accumulate it in the first place.

To be precise about what separates the two, because the word “hosted” gets used for both. The distinction is not who owns the rack. It is who decides what the software does. A dedicated Cognetryx deployment is still yours in the way that matters when it runs in a colocation facility, or in a walled-off private cloud tenancy, or when a partner operates it for you under contract. The instance is yours, the version is yours, and an upgrade happens when you schedule it. What creates the exposure in these incidents is a shared multi-tenant product where one vendor decision reaches every customer simultaneously.

That is a narrower claim than “more secure,” and the distinction matters. Private infrastructure does not make you immune to mistakes. You can misconfigure permissions, over-index a repository, or grant access too broadly, and we have written about how to avoid exactly those failures. What it removes is a specific category of risk: the one where your exposure changes without your involvement, and you learn about it from a headline.

What should you do about it now?

Ask your AI vendors two questions in writing. How do we learn about a new feature that changes what data can leave our tenancy, and can we opt out before it ships rather than after?

Then ask an internal one. If a vendor shipped something tomorrow that made our material discoverable, how would we find out, and how long would it take?

For most regulated institutions the honest answer to that second question is the same one it was in July 2025, which is that you would find out when everyone else did. It is the same dependency problem that surfaced when Hugging Face could not use commercial cloud models to investigate its own breach.

That is the gap Cognetryx was built to close. Your deployment is a dedicated instance on infrastructure you control, so there is no shared product whose terms can be revised beneath you, no share dialog for anyone to add, and no external index your documents can ever reach. Retrieval honors the permissions your systems already enforce, and every answer is logged where your own auditors can get to it. When your AI surface area changes, it changes because your people decided to change it, on a date you can name.

Sources: Chris Stokel-Walker, “Google is indexing ChatGPT conversations, potentially exposing sensitive user data,” Fast Company, July 31, 2025. Amanda Silberling, “Your public ChatGPT queries are getting indexed by Google and other search engines,” TechCrunch, July 31, 2025. The Dane Stuckey quotation is from his August 1, 2025 statement announcing removal of the feature, as reproduced by multiple outlets.

See what you control when the model is yours

A short assessment shows what a private deployment looks like inside your network, including which parts of your AI surface area stop depending on somebody else's release notes.

Book a Free AI Strategy Assessment →

Frequently asked questions

How can an AI vendor change our security posture without our approval?

By shipping a product change to a tool your teams are already cleared to use. Multi-tenant cloud services release continuously to a shared codebase, so a feature can alter what data can leave your tenancy without any review on your side. Your change control governs what your own teams deploy and carries no authority over the vendor's roadmap.

What happened with ChatGPT shared conversations in 2025?

In July 2025 OpenAI added a checkbox to the share dialog reading Make this chat discoverable, which allowed the resulting pages to be crawled. A Fast Company investigation found roughly 4,500 conversations in a single site search, including resumes, proprietary code, and legal strategy. OpenAI removed the option within hours.

Does running AI on your own infrastructure make it more secure?

It removes one specific category of risk rather than making a deployment secure by default. You can still misconfigure permissions or over-index a repository, and those failures require the same discipline as any other system. What disappears is exposure that changes without your involvement, on a schedule you do not set.

What should we ask an AI vendor about new features?

Ask in writing how you will be notified of any feature that changes what data can leave your tenancy, and whether you can opt out before it ships rather than after. Then ask internally how you would detect such a change yourself, and how long that detection would take.

Keith Kennedy

Keith Kennedy, CISSP

Founder & CEO, Cognetryx

Keith is an IT thought leader with nearly 20 years of experience architecting secure technology solutions for regulated industries. He holds a CISSP certification and advises institutions on secure AI architecture, access control, and keeping sensitive data inside the network. About Keith