Outsource IT Blog

Your Company's Data Might Already Be on Google.

Written by Umer Khalid | Jul 30, 2026, 8:24:44 PM
By Umer Khalid, President, Outsource IT Computing Inc. (OIT)

 

Someone's medical records are on Google right now. So are a stranger's clinical trial results, a list of kids' phone numbers, and a batch of company files marked "internal only." Nobody hacked anything. People just clicked "share" on an AI chatbot.

Last weekend, a wave of Claude conversations turned up in Google search results for anyone to read. The exposed material reportedly included a detailed medical report of a real patient, clinical trial data with real patient names, documents listing the names and phone numbers of primary school aged children, internal company files, employee reviews, and even API keys and login credentials.

The cause was almost embarrassingly simple. Users clicked the "share" button, which creates a public link. The warning said "anyone with the link can view." What it didn't say was that the link could get indexed by a search engine and handed to the entire internet. 

And here's what should really get your attention as a business owner: this keeps happening, and it isn't just one company.

 

This is not a one-off. It's a pattern.

  • August 2025, OpenAI: Thousands of shared ChatGPT conversations became discoverable on Google. Researchers surfaced roughly 4,500 chats containing names, locations, resumes, and deeply personal details before OpenAI pulled the feature. 
  • March 2023, OpenAI again: A software bug let some ChatGPT users see other people's chat titles and exposed payment information for about 1.2% of ChatGPT Plus subscribers during a nine hour window. 
  • 2023, Samsung: Engineers pasted proprietary source code and internal meeting notes into ChatGPT to save time. That confidential IP left the building in seconds, and Samsung ended up banning generative AI tools across major divisions.

Notice the common thread. It's not hackers. It's not sabotage. It's convenience. Someone wanted a faster answer, cleaner code, or a quick meeting summary, and one paste turned into an exposure event. 

What is Shadow AI?

Shadow AI is the unsanctioned, unmonitored use of consumer AI tools inside your business. It's the same story as "Shadow IT" a decade ago, when staff started using Dropbox and Slack long before anyone wrote a policy for them. 

Let me be blunt about your business. Your people are already using ChatGPT, Claude, Gemini, and Copilot. Today. To draft emails, summarize documents, and clean up spreadsheets. The only real question is whether they're doing it inside rules you set, or through personal accounts with zero guardrails.

When there's no approved tool and no policy, people default to whatever is fastest. That's how client records, health information, contracts, and source code quietly end up in a public AI model.

What is an Acceptable AI Use Policy, and why does it matter?

An Acceptable AI Use Policy is a short, plain-language document that sets the rules for how your team can use AI at work. A good one does four things:

  1. Names the approved tools and what each one is allowed to be used for.
  2. Draws a hard line around what can never go into a public AI tool: client data, personal health information, passwords, and internal records.
  3. Requires a human to review anything AI produces before it goes out the door.
  4. Bans autopilot decisions, so AI is never making clinical, hiring, or other high-stakes calls on its own.

That's not theory. That's the exact language I've been writing into client policies over the past few weeks.

What I've actually been building with clients

A big chunk of my time lately has gone into sitting down with clients and prospects and getting their governance in order. We've been drafting and tailoring:

  • Acceptable Use of IT Policy
  • Acceptable AI Use Policy
  • Incident Response Plan
  • Disaster Recovery Plan
  • Business Continuity Plan

These aren't templates pulled off a shelf. We build them around how the organization actually runs, the systems they use, and the rules they answer to, whether that's PHIPA in long-term care, PIPEDA, LSO obligations for law firms, or SOC 2 and ISO 27001 for companies selling to enterprise clients. 

Here's why I insist on doing all of them together. They work as a system. Your AI policy tells people what not to feed a chatbot. Your incident response plan tells them what to do the second something leaks. Your business continuity and disaster recovery plans keep you running while you clean up the mess. Skip one and the whole thing gets weaker.

Where OIT fits in

At OIT, we take businesses from "we're probably fine" to documented, defensible, and audit ready. We write the policies, put the technical controls behind them, and train your team so the rules actually stick instead of gathering dust in a shared drive.

Let's talk

If your business is using AI and you don't have an Acceptable AI Use Policy yet, or your incident response and continuity plans haven't been touched in years, contact us today.

We are offering a free, no-pressure consultation to review where you stand and show you the fastest ways to close the gaps. Your company's data doesn't need to become the next screenshot in a headline.

Umer Khalid is President of Outsource IT Computing Inc. (OIT), a managed IT services provider in Burlington, Ontario helping businesses across the GTA and Golden Horseshoe stay secure and compliant.