This week, a Reddit user ran a plain site:claude.ai/share search on Google and found strangers' Claude conversations sitting in the results, some of them carrying what looked like internal business detail. Google put the number at just under 600 shared conversations indexed before the pages disappeared from search results, TechCrunch reports, and Anthropic moved to pull the exposed pages once the discovery surfaced. On the numbers alone, this reads like a contained, quickly fixed slip, not a crisis.

What was actually sitting in those indexed pages argues against that comfortable reading. Reviewing the exposed conversations directly, Futurism found a detailed medical report and clinical trial results naming real patients, documents listing the names and phone numbers of primary-school-aged children, internal company documents, and employee reviews containing workers' personal information. That is not a hypothetical about what an employee might paste into a chat. It is a record of what was, for a window of time, actually searchable.

Set against precedent, that reading holds up even better. A researcher found nearly 100,000 ChatGPT conversations that users had set to share publicly had been scraped and indexed by Google, 404 Media reported in August 2025. Claude's exposure this week is well under one percent of that figure. Anthropic's fast pulldown looks, by comparison, like the system working as intended.

Google's Claude count is a rounding error next to the ChatGPT leak dated August 2025.

It is worth slowing down on that comparison, because both of those numbers describe the same narrow thing: what a search engine happened to index before someone noticed. Neither describes what is unrecoverable. More than 130,000 shared conversations from AI chatbots including Claude, Grok and ChatGPT are permanently readable on the Internet Archive, 404 Media found in August 2025, independent of whatever Google's index shows this week or what Anthropic fixes next.

Bar chart comparing conversations exposed: 600 Claude conversations indexed by Google in 2026, 100,000 ChatGPT conversations indexed by Google in 2025, and more than 130,000 chatbot conversations permanently readable on the Internet Archive.

Source: TechCrunch; 404 Media; 404 Media. Chart: The Signal.

That is the real shape of this kind of leak: a search engine's index can be cleaned up in days, but a page already crawled by an archive cannot be un-crawled. The just-under-600 figure that made this week's headlines is the smallest and least durable number in the story. The question worth asking is not how many chats Google happened to catch. It is what happens once one of those chats belongs to an Indian company's customer, not a hobbyist testing a chatbot.

Where the liability actually sits

India answered a version of that question in November 2025, before this leak happened. A Press Information Bureau backgrounder on the DPDP Rules, 2025 states that a Data Fiduciary that fails to maintain reasonable security safeguards against a personal data breach can be fined up to ₹250 crore, and that a separate failure to notify the Data Protection Board or affected individuals of a breach can draw up to ₹200 crore. Those are two distinct tracks, not one number softened by an "or."

Bar chart of the two DPDP penalty ceilings: a security-safeguard failure can draw up to 250 crore rupees, and a breach-notification failure up to 200 crore rupees, as of November 2025.

Source: Press Information Bureau backgrounder on the DPDP Rules, 2025. Chart: The Signal.

The second track has a hard clock attached. The Digital Personal Data Protection Rules, 2025, published by the Ministry of Electronics and Information Technology, state that once a Data Fiduciary becomes aware of a personal data breach, it must give India's Data Protection Board an updated, detailed account within 72 hours. A Data Fiduciary, in the Act's own terms, is whoever determines the purpose and means of processing someone's personal data, which in an ordinary business relationship is the Indian company, not the AI vendor whose product it used.

That framing matters here because Anthropic's disclosure obligations, whatever they turn out to be, run to Anthropic's own users and to whichever regulators have jurisdiction over Anthropic. They do not automatically discharge an Indian company's own 72-hour clock to update India's Data Protection Board on a breach it has become aware of. If an employee at an Indian firm pasted a customer's personal data into a Claude conversation, shared the link for a colleague, and that link was one of the roughly 600 Google indexed this week, the firm's breach-notification duty plausibly starts the moment that firm becomes aware of the exposure, whether or not Anthropic ever names that firm in its own account of the incident. The company does not get to wait for Anthropic to do its notifying for it.

Most Indian firms are not set up to catch this

The gap between that legal exposure and actual readiness is wide. IBM's 2025 Cost of a Data Breach Report finds that the average cost of a data breach for an Indian organisation hit an all-time high of ₹22 crore in 2025, 13 percent higher than the year before, and the same report finds most Indian firms still unprepared for the AI-specific version of that risk.

Readiness measure (India, 2025)Figure
Average cost of a data breach₹22 crore, an all-time high
Organisations with AI access controls in place37%
Organisations with no AI governance policy, or still writing oneNearly 60%

Source: IBM's 2025 Cost of a Data Breach Report.

Those numbers describe general AI use inside Indian companies, not the Claude leak specifically. But they are the backdrop the leak lands on: a workforce that has adopted AI chat tools for real business tasks faster than most employers have written a policy governing what goes into them, in a legal environment where the penalty for getting the response wrong is now denominated in hundreds of crores.

The honest objection

The strongest case against reading this as an Indian-company liability event is that none of it has been tested. The DPDP Rules are new, no Data Protection Board enforcement action has yet defined what counts as an Indian Data Fiduciary "becoming aware" of a breach that happened on a foreign vendor's platform, and a regulator weighing its first cases may reasonably start with companies that controlled the data infrastructure directly, not every employer whose staff used a popular chatbot. Anthropic's own quick pulldown, and the fact that the exposed count is small, could also blunt any argument that real harm occurred.

That case deserves weight, but it does not remove the exposure, it only delays when someone tests it. The statute and its 72-hour notification clock are already written into the published rules; a Data Protection Board does not need to have ruled on a case yet for a company's legal team to have to decide, this week, whether an employee's shared link falls inside that clock. Waiting for the first enforcement action to define the boundary is a bet that a compliance officer, not a regulator, usually loses.

The Signal

The 600 conversations Google indexed are not the number to watch. What matters is whether any of them belonged to an Indian company's customer, and whether that company's legal team is already treating its own DPDP clock as running, rather than waiting for Anthropic to say something first. Anthropic can only ever answer for its own platform, not for what an Indian Data Fiduciary owes India's Data Protection Board. A leaked chat is not just a security incident anymore; in India it is also a jurisdiction question, and the 72 hours do not pause for someone else to go first.

Reporting basis: the count of Claude conversations indexed before removal is per TechCrunch's reporting, citing Google's and Anthropic's own figures. The specific contents found inside the exposed conversations are per Futurism's own review of the indexed pages. The 2025 ChatGPT indexing figure and the Internet Archive permanence figure are both per 404 Media's original reporting. The DPDP penalty ceilings and the 72-hour breach-notification duty are drawn directly from a Press Information Bureau backgrounder and from the Digital Personal Data Protection Rules, 2025 as published by the Ministry of Electronics and Information Technology, both primary government documents. The India data-breach cost and AI-governance figures are from IBM's 2025 Cost of a Data Breach Report, produced with the Ponemon Institute. The comparison putting the Claude count at well under one percent of the 2025 ChatGPT figure is The Signal's calculation from those two totals. The reading of how India's Data Fiduciary definition applies to an employee's shared AI chat is The Signal's own analysis of the published rules, not a regulatory determination, and it remains untested by any enforcement action to date.