180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-162
Consumer AI · United States · 2025 · Data exposure & egress

A reporter found nearly 4,500 shared ChatGPT conversations in Google's index through an ordinary site search, and OpenAI withdrew the discoverability setting the following day

By Ellie Harris · Filed Reported by Fast Company on 30 July 2025

Alleged: OpenAI developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

A reporter found nearly 4,500 shared ChatGPT conversations in Google's index through an ordinary site search, and OpenAI withdrew the discoverability setting the following day

What happened

It was reported that ChatGPT’s share feature created a shareable link to a conversation. A separate control in the resulting dialog, a checkbox labelled Make this chat discoverable with the subtitle Allows it to be shown in web searches, governed whether search engines could surface that link. Applying it was a separate and explicit choice. A screenshot of the dialog published on 3 August 2025 shows the box unchecked, but no source reviewed here establishes its default state. This was a setting behaving as specified rather than a breach or an unauthorised disclosure.

It was reported by Fast Company on 30 July 2025 that a basic Google site search using part of the link created when someone clicks Share returned nearly 4,500 conversations on the day the query ran. Fast Company records that many did not include personal details or identifying information, and that others contained deeply personal material, including struggles with addiction, experiences of physical abuse and serious mental health difficulties. The figure is a search engine result count for pages crawled under the share URL path, not a count of conversations that had been shared or a count of sensitive ones. It was then reported by TechCrunch on 31 July that the result could be reproduced on Google, Bing and other search engines, and that the material TechCrunch surfaced was largely mundane.

It was reported by TechCrunch that, hours after its article was published, OpenAI removed the feature that allowed users to make shared conversations discoverable by search engines. It was reported by Fast Company, The Register and PC Gamer that OpenAI’s chief information security officer described it as a short lived experiment to help people discover useful conversations, and said that ultimately the company thought the feature introduced too many opportunities for folks to accidentally share things they didn’t intend to, so it was removing the option and working to remove indexed content from the relevant search engines. That statement was made on X and is reproduced identically by all three; it was not read at its original location for this entry. Share links themselves were retained.

What an auditable version would have shown

It was reported that the reach of the sharing feature was established by an outsider running a query against a search engine. That query cannot say how many conversations were shared, how many carried sensitive material, or how long any had been retrievable. The figure that entered the public record, nearly 4,500, is the number Google returned, and it has been repeated since as though it counted something else.

An auditable version answers the question from the organisation’s own records. A record written when a share link is created says which conversation was published, whether the discoverability setting was applied, and what the user was shown when they applied it. Aggregated across shared links, that record answers how many were made discoverable and lets the organisation say so before a reporter asks. It does not establish whether the setting was appropriate to offer or whether its label was adequate. What it changes is that the scale of a publication becomes something the organisation can state from its own records.

Where the gap was

It was reported that content moved out of a private conversation and into a public search index through a checkbox in a dialog, and that the extent of that movement was first established from outside the company. An EgressGate performs a check where content would cross a trust boundary, classifying what a conversation contains and testing the destination. A transcript carrying health or abuse related material is then treated differently from one about a bathroom renovation before a discoverable link is minted. A ConductRecord preserves, per share event, the conversation identifier, the setting applied and the interface text presented at the time. That allows a company to establish afterwards what it published and what users were told. Neither control decides whether an opt-in of this kind is appropriate to offer, and neither removes content already crawled. What they change is that the organisation can measure its own exposure rather than learning its size from a site search.

What governance should have looked like

Where an organisation offers to make a user’s conversation retrievable by search engines, best practice would be for the content to be classified before the discoverable link is created, rather than after it is indexed. The consequence would be stated at the point of decision in terms of who will be able to find the material. A record of each publication and the setting applied would be kept so the organisation can establish the extent of what it has released.

Separately, Forbes reported search indexed chatbot conversations at two other companies in August and September 2025. Those reports concern different sharing and indexing mechanisms. They are listed in the sources below and are not treated here as evidence about the ChatGPT feature described above.

Failure Pattern: an opt-in setting made shared conversations retrievable through search engines, and the reach of that release became visible only when an outsider queried the search index for it.

Governance Principle: an organisation that offers to publish a user’s conversation should be able to show what it published, where that content became retrievable, and what the user was told at the moment of the decision.

The reference implementation of EgressGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and OpenAI could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →