Someone's medical records are on Google right now. So are a stranger's clinical trial results, a list of kids' phone numbers, and a batch of company files marked "internal only." Nobody hacked anything. People just clicked "share" on an AI chatbot.
Last weekend, a wave of Claude conversations turned up in Google search results for anyone to read. The exposed material reportedly included a detailed medical report of a real patient, clinical trial data with real patient names, documents listing the names and phone numbers of primary school aged children, internal company files, employee reviews, and even API keys and login credentials.
The cause was almost embarrassingly simple. Users clicked the "share" button, which creates a public link. The warning said "anyone with the link can view." What it didn't say was that the link could get indexed by a search engine and handed to the entire internet.
And here's what should really get your attention as a business owner: this keeps happening, and it isn't just one company.
Notice the common thread. It's not hackers. It's not sabotage. It's convenience. Someone wanted a faster answer, cleaner code, or a quick meeting summary, and one paste turned into an exposure event.
Shadow AI is the unsanctioned, unmonitored use of consumer AI tools inside your business. It's the same story as "Shadow IT" a decade ago, when staff started using Dropbox and Slack long before anyone wrote a policy for them.
Let me be blunt about your business. Your people are already using ChatGPT, Claude, Gemini, and Copilot. Today. To draft emails, summarize documents, and clean up spreadsheets. The only real question is whether they're doing it inside rules you set, or through personal accounts with zero guardrails.
When there's no approved tool and no policy, people default to whatever is fastest. That's how client records, health information, contracts, and source code quietly end up in a public AI model.
An Acceptable AI Use Policy is a short, plain-language document that sets the rules for how your team can use AI at work. A good one does four things:
That's not theory. That's the exact language I've been writing into client policies over the past few weeks.
A big chunk of my time lately has gone into sitting down with clients and prospects and getting their governance in order. We've been drafting and tailoring:
These aren't templates pulled off a shelf. We build them around how the organization actually runs, the systems they use, and the rules they answer to, whether that's PHIPA in long-term care, PIPEDA, LSO obligations for law firms, or SOC 2 and ISO 27001 for companies selling to enterprise clients.
Here's why I insist on doing all of them together. They work as a system. Your AI policy tells people what not to feed a chatbot. Your incident response plan tells them what to do the second something leaks. Your business continuity and disaster recovery plans keep you running while you clean up the mess. Skip one and the whole thing gets weaker.
At OIT, we take businesses from "we're probably fine" to documented, defensible, and audit ready. We write the policies, put the technical controls behind them, and train your team so the rules actually stick instead of gathering dust in a shared drive.
If your business is using AI and you don't have an Acceptable AI Use Policy yet, or your incident response and continuity plans haven't been touched in years, contact us today.
We are offering a free, no-pressure consultation to review where you stand and show you the fastest ways to close the gaps. Your company's data doesn't need to become the next screenshot in a headline.
Umer Khalid is President of Outsource IT Computing Inc. (OIT), a managed IT services provider in Burlington, Ontario helping businesses across the GTA and Golden Horseshoe stay secure and compliant.