Grok's Share Button Turned Private Chats Into Public Search Results
What happened
Elon Musk's Grok chatbot ships with a "Share" feature. Users who clicked it in the months before August 2025 believed they were distributing a link the same way they might forward a document. They were not. Each click generated a publicly accessible web page that search engines treated like any other public URL, and Google indexed them by the hundreds of thousands.
Over 370,000 conversations became searchable on Google without the knowledge or consent of the people who had them. The range of what got exposed was wide. Everyday material, including meal plans, password suggestions, and business discussions, sat alongside medical advice, personal details, and confidential professional information. Also indexed were chat transcripts in which Grok had provided detailed instructions for producing drugs, building malware, manufacturing explosives, and planning assassinations, content the platform's own policies prohibited but the system generated anyway.
The root cause was a design choice, not a hack or a breach in the conventional sense. xAI built the share function to create permanent, crawlable pages for each conversation. No warning told users their chats would be findable by anyone with a search engine. The reasonable assumption, that sharing a link implied some control over who could follow it, turned out to be false. The platform's default was fully public, and the only people who did not know that were the users.
The timing carried its own weight. xAI had, in the period leading up to this incident, publicly criticized other AI developers for similar privacy and transparency failures. The company positioned Grok partly on the argument that its competitors handled user data carelessly. The exposure of more than a third of a million conversations, including ones where the model gave detailed instructions for weapons and malware, undercut that positioning entirely.
What the incident makes concrete is the gap between a feature that works and a feature whose consequences users can see in advance. A user who clicked "Share" had no way to know what access they were granting, no record of who had since retrieved that page, and no mechanism to pull it back once it was indexed. That is precisely the terrain accountability infrastructure is built to cover: a provable record of what a system made public, when it made it public, and whether the person who triggered that action was ever told what they were agreeing to. Without that record, every share button that defaults to public is a disclosure waiting to be discovered.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.