Your Confessions, Indexed

Conversational AI Watch

Conversational AI Watch

The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  July 28, 2026  |  Issue #109

▶ WATCH🎧 QUICK LISTEN🎧 DEEP DIVE
CAW #109 infographic: hundreds of private Claude conversations indexed by Google and Bing, the EU ordering Android open to rival AI assistants, Anthropic and OpenAI taking open-weights positions to Washington, a Delaware ruling letting a chatbot defamation suit reach discovery, X purging 42,000 chatbot reply accounts, and OpenAI's Presence platform answering its own support line.
Jess Jessop

JessJessop.Info

Jess's Take

Your Confessions, Indexed

Hundreds of private Claude chats surfaced on Google, and nothing malfunctioned. A Delaware judge opens a new frontier for defamation law.

Somewhere in the hundreds of chatbot conversations that surfaced on Google this weekend are somebody’s medical scare, somebody’s legal trouble, and at least one cryptocurrency wallet key. People clicked share, and share meant publish.

. . .

The machinery of accountability moved while the links were coming down. Brussels fixed the rulebook that opens Android’s assistant slot to Gemini’s rivals. A Delaware judge held that a man who put Google’s lawyers on written notice can take its chatbot’s words to discovery. And the two companies that sat out the open-weights letter finally moved: one published a position paper, the other flies to Washington this week.

. . .

X threw out 42,000 accounts for pointing chatbots at strangers with no human in the loop. And the good news: the agent answering OpenAI’s own phone line now resolves three support calls in four, behind guardrails the industry learned the hard way.

Reader Pulse

Tuesday's read, in one tap

🔥  Best briefing going
✏️  Sharper for reading it
💪  Not how I see it
🤔  You lost me midway
💬  Something else here

Forward to a colleague →  ·  Join the discussion →

. . .

THE SHARE BUTTON WAS A PUBLISH BUTTON. Hundreds of conversations that Claude users chose to share turned up in Google and Bing search results over the weekend, browsable by strangers. The exposed material included cryptocurrency wallet keys, medical and legal discussions, and erotica. Nothing was hacked. The feature worked exactly as built.

Reddit users in a Claude discussion community made the discovery around July 25 and 26, with one search: every page Google had indexed under claude.ai/share. Joseph Cox at 404 Media reported it July 27; Wired, Fortune, and BBC News followed.

. . .

Here is how the feature works, per Fortune. Clicking share creates “a snapshot of your conversation at its own web address, meant to be sent to one person or a small group with that link.” But the page lived at a public URL, and indexing public URLs is what search engines do.

. . .

No one broke in. The share button did what a publish button does.

. . .

What surfaced, per Fortune and 404 Media: wallet keys that control cryptocurrency. Names and addresses. Source code and work notes. Legal matters. Medical matters. Explicit content.

People bring a chatbot the things they tell no one. A conversation with a machine feels private the way a diary feels private.

. . .

Anthropic told Fortune: “We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google. These shareable links are not guessable or discoverable unless people choose to share them themselves.”

. . .

By Monday, the Google search technique no longer surfaced the links. Some remained reachable on Bing, and every link already shared stays live for anyone who holds it.

. . .

This has happened before. In August 2025, close to 100,000 ChatGPT conversations were exposed the same way, by Fortune’s accounting, through a sharing feature with a “make this chat discoverable” checkbox. OpenAI removed the checkbox and called it “a short-lived experiment.” xAI’s Grok had a similar exposure.

Three major labs. The same feature. The same result.

. . .

No US federal law treats what you tell a general-purpose chatbot as confidential: no privilege, no HIPAA-style duty on the company. When the exposure is designed behavior rather than a breach, the person whose wallet key is now searchable carries the entire loss, and no statute requires anyone to notify them.

For Legislators: No confidentiality statute reaches the chatbot transcript, and because this was designed behavior rather than a breach, breach-notification laws likely never triggered. Three identical incidents at three labs is the record now in front of you.

For Families: Check whether you or your kids ever clicked share on a chatbot conversation. Claude’s settings allow revoking shared links. Every link already out remains live until it is deleted.

For Builders: Shared-conversation pages need noindex headers, and the share button needs a plain-language warning that the link is a public web page.

For Counsel: An industry's third identical incident starts to look like a design norm problem, and an FTC unfairness angle. Separately, audit what your employees paste into chatbots.

Source: Fortune, July 27, 2026, https://fortune.com/2026/07/27/a-trove-of-users-seemingly-private-conversations-with-anthropics-claude-ai-chatbot-showed-up-in-google-search-results/; 404 Media (Joseph Cox), July 27; Wired, July 27; BBC News, July 28.

Why it matters: The gap between what “share with one person” means to a user and what a public URL means on the open web has now exposed private conversations at OpenAI, xAI, and Anthropic in turn. Until the design changes or a confidentiality duty exists, the person typing carries the risk, and most of them do not know it.

Comment on this story →  ·  Forward this →

. . .

BRUSSELS HANDS RIVALS THE KEYS TO ANDROID. The statutory clock on the European Commission’s Android proceedings expired yesterday, Monday, July 27. The decision that beat it, adopted July 16 under the Digital Markets Act, is now the fixed rulebook: two legally binding orders requiring Google to open Android to competing AI assistants and to share Google Search data with rivals.

The Commission opened the proceedings on January 27, aimed at eleven Android features relevant for AI services, and the law gave it six months to act. It adopted the final decision on July 16.

. . .

The first measure rewires the phone itself. Competing AI assistants get the same access to Android’s operating-system features that Google’s own Gemini has: custom wake words that work the way “Hey Google” does today, and system-wide entry points.

The access goes deeper than the wake word. A rival assistant can read what is on the user’s screen and execute tasks across apps on the user’s behalf: booking a taxi, running location queries, suggesting replies. Rivals get hardware resources sufficient to run as responsively as Gemini, and the on-device context flows Gemini uses. The order covers roughly 60 percent of EU Android users.

. . .

The second measure opens the vault: third-party search engines, and AI chatbots that offer search, become eligible to receive Google Search click and query data, under a multi-layered anonymisation method and a fair-pricing formula.

. . .

Start with what the slot is worth. The assistant that ships as the default on a phone is the assistant that gets the conversation, the data, and the subscription. Google reserved that slot on Android for Gemini.

The Commission just priced that reservation at zero. In the EU, rivals get the slot by law, not by paying for placement.

. . .

The calendar is set. Search data access opens in January 2027. Android interoperability arrives with the next major Android release, Android 18, and by August 1, 2027 at the latest.

No other jurisdiction has done this. In the United States, the antitrust case over Google’s search business has produced no equivalent mandate at the assistant layer. For OpenAI, Anthropic, Perplexity, and every other maker of a conversational assistant, the decision converts the Android assistant slot from Google’s private preserve into a market.

For Legislators: A working regulatory template now exists, with dates, safeguards, and a pricing formula attached. No US statute or court order currently requires anything comparable.

For Investors: The EU assistant slot on Android just became contestable, on a timeline already on the calendar: search data in January 2027, full interoperability by August 1, 2027 at the latest.

For Builders: Wake-word invocation, screen context, and cross-app execution APIs are coming to Android in the EU. Plan the roadmap against Android 18, not against a someday.

For Reporters: Two questions decide how real this gets: whether Google appeals, and whether the anonymisation of search data holds up under privacy scrutiny once rivals start receiving it.

Source: European Commission, DMA specification decisions on Alphabet, adopted July 16, 2026, https://digital-markets-act.ec.europa.eu/commission-provides-guidance-google-ai-interoperability-android-and-sharing-google-search-data-under-2026-07-16_en; Commission specification-proceedings page, opened January 27, 2026.

Why it matters: For the first time anywhere, a regulator has ruled that the assistant built into a phone’s operating system cannot be the only assistant the operating system serves. The rulebook is fixed, the dates are on the calendar, and the first data starts flowing in January.

Comment on this story →  ·  Forward this →

. . .

THE ABSENT ANSWER, ONE IN PRINT, ONE IN PERSON. Last week, 25 technology companies signed a letter urging Washington not to restrict open-weight AI models. OpenAI and Anthropic, the two biggest American makers of conversational AI, did not sign it. On Monday, Anthropic’s CEO published his answer. This week, OpenAI’s CEO takes his to Washington in person.

Critics spent the interval asking why the two companies stayed off the letter. On Monday, July 27, Anthropic CEO Dario Amodei answered with a post titled “Anthropic’s Position on Open-Weights Models.” The core line: “Anthropic has never advocated for a ban on open-weights models.”

He went further. “A blanket ban on open-weights models is neither the correct remedy nor something we have called for.” The post names two concerns: authoritarian governments developing more powerful AI than the United States, and misuse, because with open weights “it is very difficult to apply guardrails to them.” A ban, he argues, addresses neither: bad actors would not use legitimate channels anyway.

. . .

What he asks for instead is specific. First, chip export controls: “We should not sell powerful chips or chipmaking equipment to China,” plus a crackdown on smuggling. Second, restrictions on “industrial-scale distillation operations” that let a rival improve a model without proportional access to chips.

Third, universal testing: “All sufficiently capable models, open and closed, should go through mandatory safety testing.”

. . .

The other absent company chose a different venue. Sam Altman travels to Washington this week to meet senior Trump administration officials, lawmakers, and economists, per CNBC. He will preview OpenAI’s upcoming family of models and field questions about cybersecurity and open weights. Among the meetings, per Reuters-syndicated reporting: Senator Mark Warner of Virginia, the top Democrat on the Senate Intelligence Committee.

One absent company has published its position. The other is taking meetings.

. . .

Follow the money and the sides sort themselves. Anthropic and OpenAI sell closed models by subscription and API. Open-weight rivals price the same capability at zero. Every option on Washington’s table this week moves billions: export controls move Nvidia’s China revenue, distillation rules move the cost structure of every cheap rival, and mandatory testing raises the floor for everyone.

For Legislators: The two companies absent from the industry letter have now put positions on the record. Amodei’s three asks are specific enough to mark up: chips, distillation, testing.

For Investors: Watch which of the three asks survives contact with Congress.

For Builders: The ask that touches you is the third one. “All sufficiently capable models, open and closed, should go through mandatory safety testing” includes the model you ship.

For Reporters: Ask Altman’s team what OpenAI’s written position on open weights actually is. Unlike Anthropic, OpenAI has not published one this week.

Source: Anthropic, “Anthropic’s Position on Open-Weights Models,” Dario Amodei, July 27, 2026, https://www.anthropic.com/news/position-open-weights-models; CNBC, July 27, 2026, https://www.cnbc.com/2026/07/27/altman-trump-china-open-weight-ai.html

Why it matters: The two companies that skipped the open-weights letter now shape the debate anyway, with a published framework and a week of Washington meetings. The proposals on the table would not ban the weights. They would touch chips, distillation, and testing, and each of those levers is priced in someone’s billions.

Comment on this story →  ·  Forward this →

. . .

A NEW FRONTIER FOR DEFAMATION LAW. On Friday, Judge Meghan A. Adams of the Delaware Superior Court denied Google’s motion to dismiss, in its entirety, in Robby Starbuck’s defamation suit over what Google’s chatbots said about him. Her opinion calls the case “a new frontier for defamation law, in which artificial intelligence tools are allegedly employed to effectuate the defamatory ends of their makers.”

Google released Bard, its first chatbot, in March 2023. By December of that year, per the opinion, Starbuck, a Tennessee filmmaker, journalist, and activist, learned Bard was falsely tying him to a “notorious white supremacist” and would, when asked, provide an argument in favor of his execution.

. . .

On December 13, 2023, Starbuck posted on X asking for a retraction, tagging Google’s corporate accounts and Chief Executive Sundar Pichai. A Google employee, Carla Sonnenberg, reached out the same day. In February she emailed that she had tried to help and failed, and had resigned the day before. Google merged Bard into Gemini that same month; the opinion calls all of it Google AI.

. . .

On July 31 and August 12, 2025, Starbuck’s counsel sent written notices that Google’s legal department received. Then came the outputs the suit is built on. Every one of them, per the opinion, was generated between August 14 and 21, 2025. After the notices.

. . .

In that week, the complaint alleges, Google AI falsely stated that Starbuck had been accused of sexual assault and harassment by multiple women, that at least eight women had accused him of misconduct, and that he had been accused of rape of a minor.

The opinion’s list goes on. Stolen valor. Restraining orders, including one sought by an ex-wife who does not exist. A criminal conviction. “An unacceptable level of risk to children” from a “confirmed criminal record” that was fictitious. And, repeatedly, participation in the January 6, 2021 Capitol riot.

. . .

The “sources” Google AI cited for these claims were themselves fabricated, the complaint alleges. The opinion notes Google does not contend the outputs are true.

. . .

Then the number. Starbuck alleges Google AI itself admitted it had provided false statements about him to 2,843,917 unique users, his children and colleagues among the recipients. The court declined to dismiss that allegation as incredible at this stage, and held it supplies the inference that third parties received the outputs.

. . .

He put Google’s lawyers on written notice. The machine kept going.

. . .

Google ran the industry playbook: its outputs carry veracity disclaimers, and it cited Walters v. OpenAI, the Georgia case OpenAI won at summary judgment in 2025. The court distinguished it. In Walters, no evidence showed OpenAI knew the output would be false. Here, Starbuck alleges he told Google’s legal department the machine was defaming him before the outputs were produced, and Google did nothing.

The court declined to take judicial notice of the disclaimers at this stage, and refused to discount Starbuck’s allegation that Google AI admitted to holding a “deliberate, engineered” bias against him.

. . .

On damages, the court applied Tennessee law, under which emotional-distress injury suffices without proof of reputational loss, citing the backdrop of the assassination of political commentator Charlie Kirk, and Starbuck’s own history of death threats.

. . .

The denial is not a merits ruling. The court accepted the complaint’s allegations as true only for the motion, and the allegations are unproven in court. But the case now proceeds to discovery: the first known US chatbot-defamation suit to get there on a notice-and-continued-output theory.

For Counsel: The defense that won Walters, disclaimers plus hallucination framing, just lost in Delaware. What defeated it was documented notice to the legal department followed by continued output. The notice letter is now the highest-leverage document in AI defamation, on both sides of the v.

For Legislators: No new statute did this. Ordinary tort law, applied on ordinary pleading standards, reached chatbot output. The open question is whether notice-and-continued-output becomes the de facto national standard while you debate.

For Builders: Starbuck’s first complaint to Google was December 2023. The outputs he sued over came twenty months later, after the one employee who tried to help had resigned. A user-facing report-and-correction channel that actually works is now a litigation shield.

For Reporters: Discovery will probe how Google AI produced these outputs and whether the alleged “deliberate, engineered” bias holds up against the evidence. Every lab’s general counsel will be reading the transcripts with you.

Source: Opinion, Starbuck v. Google LLC, Del. Super. Ct., C.A. No. N25C-10-211 MAA (July 24, 2026), Adams, J., https://reason.com/wp-content/uploads/2026/07/StarbuckvGoogle.pdf; Bloomberg, July 24, 2026.

Why it matters: A court just held that a plaintiff who documents notice and keeps receipts can take an AI company to discovery over what its chatbot says. The machine’s alleged audience was 2.8 million people, and its alleged sources were invented. Whether that is a hallucination or a design choice is now a question for the evidence, not the marketing.

Comment on this story →  ·  Forward this →

. . .

42,000 BOTS, NO HUMAN IN THE LOOP. On Friday, July 24, X’s head of product Nikita Bier announced the platform had found and removed 42,000 accounts that were using chatbots to automate replies to other users. The reason he gave is the plainest line a platform has drawn all year: no machine engagement “without a human in the loop.”

Bier’s post, in full: “We found 42,000 accounts automating replies using chatbots and have removed them from the platform. X’s core value is providing an authentic pulse on humanity, and using AI to programmatically engage with users without a human in the loop runs counter to our mission.”

. . .

The accounts were not posting into the void. They were replying, at scale, to other people’s posts: engagement farming, reply spam, growth-marketing schemes in which a language model answers thousands of strangers to build an audience or push a product. Users widely welcomed the removal; AFP-syndicated coverage noted the machine-written replies felt unpleasant and inauthentic next to human conversation.

. . .

This is not a first strike. In October 2025, X removed 1.7 million bots for reply spam; in April 2026, Bier described “identifying and suspending 208 bots per minute” during an earlier sweep.

. . .

The line is not “no AI on the platform.” X sells access to Grok, its own conversational AI, built into the same platform. The line X drew is narrower: no AI passing as a human participant in conversation, at scale, without a human in the loop. Which chatbots powered the removed accounts has not been disclosed.

. . .

There is a business reason the line sits exactly there. X sells advertisers engagement and sells users paid verification. A reply written by a machine and counted as a human is not just annoying. It is inventory fraud against the people paying for the audience.

. . .

No federal law required any of this. California’s B.O.T. Act, in force since 2019, requires bots that try to influence purchases or votes to disclose what they are, but it binds the bot’s operator, not the platform. What happened Friday was voluntary, self-defined, and reversible.

. . .

X just enforced, at scale, a human-in-the-loop rule that no legislature has written.

For Legislators: The definition, the threshold, and the enforcement all belong to one company, and can change whenever that company does.

For Investors: Bot purges are margin defense. And 42,000 accounts in a single sweep is a floor, not a ceiling, on LLM-driven engagement farming.

For Builders: If your growth tooling auto-replies to strangers using a language model, X just declared it a removable offense.

For Reporters: Ask X how it distinguishes a chatbot-automated account from a human using AI drafting tools. The boundary definition is the whole game, and it has not been published.

Source: Nikita Bier (@nikitabier), X, July 24, 2026, https://x.com/nikitabier/status/2080747924380856519; AFP-syndicated coverage, July 25-27, 2026; Social Media Today, April 9, 2026.

Why it matters: A platform whose stated core value is “an authentic pulse on humanity” just conceded that 42,000 accounts were machines conversing as people, and that the only thing standing between users and synthetic conversation is the platform’s own discretion. The rule that stopped them is not law. It is one company’s policy.

Comment on this story →  ·  Forward this →

. . .

THE MACHINE TAKES THE CALL. On Wednesday, July 22, OpenAI launched Presence, an enterprise platform for deploying and managing real-time voice agents and chatbots, in limited availability. The proof point, reported by VentureBeat, is OpenAI’s own phone line: the company says the system now resolves 75 percent of inbound support issues without a human.

Presence is not a chatbot. It is the management layer: a company launches a voice or chat agent scoped to one job, handling billing issues, insurance claims, or employee IT service requests. Each deployment gets only the information and system access that job requires. Before an agent faces a customer, it runs through simulation testing; after deployment, Codex-driven improvement loops keep working on it.

The phone tree, the most hated conversational interface ever built, is the thing being replaced.

. . .

OpenAI’s first customer is itself. Presence now runs the company’s own English-language phone support line, where it handles open-ended requests, verifies callers, uses account context, and takes approved actions.

The caveat, plainly: the 75 percent is OpenAI measuring OpenAI. It describes one support line, at a company whose customers are unusually comfortable talking to software, and no independent audit of it exists. “Resolved without human assistance” is the vendor’s definition of resolved.

. . .

The early customers have names: BBVA Mexico, SoftBank Corp, and Retail Insurance Australia. One step further: SoftBank and BBVA are also financial backers of OpenAI’s DeployCo subsidiary, per the trade coverage, so the flagship launch customers are, in part, investors in OpenAI’s own deployment vehicle. That does not make the deployments fake. It does make the logos a weaker signal than they look.

. . .

What makes this the good news is the architecture, because it concedes a year of hard lessons. Scoped access instead of an agent that can touch everything. Simulation before the first customer call. Approved actions, not open-ended autonomy. A human escalation path for the 25 percent the machine cannot close.

After a year of stories about agents doing too much with too little supervision, the notable thing about Presence is how much of it is fencing.

For Investors: The enterprise voice-agent category now has OpenAI as a direct platform competitor.

For Builders: The pattern worth copying is the complete fence: one job, scoped access, simulation testing, approved actions, human escalation. The 25 percent that escalates is where trust is won or lost.

For Legislators: A caller reaching Presence is talking to a machine that verifies identity and takes actions on accounts. Disclosure rules for AI callers vary by state and mostly target the calling side, not the answering side.

For Workers: The direction is unambiguous: entry-level phone support is being automated first.

Source: VentureBeat, “OpenAI unveils Presence, a new platform that lets enterprises launch and manage realtime voice agents and chatbots,” July 22, 2026, https://venturebeat.com/orchestration/openai-unveils-presence-a-new-platform-that-lets-enterprises-launch-and-manage-realtime-voice-agents-and-chatbots; OpenAI Presence product materials, July 2026.

Why it matters: Every company that ever built a phone tree accepted that customers would hate it. Presence is a bet that a fenced conversation beats the buttons, and its design reads like a catalog of what went wrong when agents ran loose. The 75 percent is OpenAI grading its own homework. The fencing is the news.

Comment on this story →  ·  Forward this →

A conversation with a machine feels like a room with a door. This week the door turned out to be a URL, the transcript turned out to be an exhibit, and the reply in your mentions turned out to be one of 42,000 machines.

. . .

What stood between the private conversation and the public one, in every case, was policy: a company’s crawler rules, a platform’s bot sweep, a vendor’s limits on its agent. Policy is what a company can revoke.

The courts and the regulators spent the week deciding what it costs a company when policy is all there is.

Today's Question

Hundreds of private Claude chats landed on Google. Whose failure?

The company that built the button
The user who clicked share
The engines that indexed them
All three of them

One tap. Results on the other side.

The Book • Out Now

Therapist in the Loop book cover: a therapist and a client in armchairs joined by a glowing loop of light

Therapist in the Loop

by Jess Jessop

One billion people live with a mental health disorder. Most will never see a therapist. Into that gap has rushed a generation of chatbots that talk like clinicians and answer to no one.

The book lays out the architecture this newsletter tests against every statute and docket: client, therapist, and machine, governed by Six Laws offered as an open safety standard.

The machine can help. It cannot be left in charge.

Get the Book on Amazon →

Kindle, hardcover, and paperback

More On Our Radar

The caseworker cited a document that never existed. A UK Upper Tribunal judge found the Home Office refused a woman's asylum claim citing a Morocco country-policy note that "has never existed," writing that the refusal letter "bears hallmarks consistent with the use of artificial intelligence" and calling it a potentially extremely serious failing. The state's own paperwork, hallucinated. Source

Perplexity's agent moves into Windows. Personal Computer, Perplexity's desktop agent, began rolling out to paying Max subscribers on the world's most popular desktop operating system, with reach into local files and Office apps, a voice mode, and a promised set of approval gates for sensitive actions, an audit trail, and a kill switch. Source

The robot teacher is on hold. Salamanca City Central School District paused its $57,590 Realbotix humanoid pilot, and the AI teaching-assistant avatar that came with it, after parent backlash and a letter from New York State Education Commissioner Betty Rosa citing concerns about a humanoid robot in a high school classroom. Source

A lawsuit asks to pause ChatGPT Health. Scott Winters sued OpenAI in San Francisco County Superior Court, alleging ChatGPT reassured him his pain was minor hours before he was hospitalized with a massive pulmonary embolism. Beyond damages, the suit seeks an injunction pausing ChatGPT Health pending independent safety review. Source

Brush your brain. Every day.

Watch the 20-second video that started a movement

This Issue

Your verdict on the page

Print it as is
Saving the clipping
Not how I'd rule
One story lost me
More to say

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

ClinicianAssist.ai  |  BetterMind.Space  |  JessJessop.info

Subscribe  |  Archive  |  Unsubscribe