Risks of “Share Link” Features in AI Chatbots
Shared conversations from major AI platforms using the “anyone with the link can view” option are being indexed by public search engines like Google, according to recent reports. When a user generates a shared URL to collaborate, that interaction is hosted on the open web. Search crawlers can discover these URLs, potentially exposing whatever data was included in the prompt and giving anybody access to your chats.
Why This Matters at VCU
Protecting institutional data is vital. Within the VCU community, faculty, staff, students, and researchers often use AI to manage operations, draft communications, and generate and analyze text. The use of native shared links can expose sensitive data or intellectual property.
The Risk to Avoid
Users must avoid settings that grant open, public access to data. When utilizing the share functionality in AI tools, enabling “anyone with the link can view” can immediately move the data to the public domain and make it indexable.
Preferred Workflow for Secure Collaboration
To protect data and maintain institutional compliance, users should utilize VCU-supported platforms like the VCU Google Workspace. Within this environment, users can share information securely with specific colleagues using a VCU eID, ensuring data remains within the university’s protected ecosystem.

Next Steps: Review any past links generated in consumer AI tools and remove those sharing permissions.
We strongly recommend conducting university business within Category 2 tools like VCU’s licensed Gemini, which have a Data Protection Agreement (DPA) in place. Even within a Category 2 tool, keep your inputs limited.
Learn more about appropriate data types with our Data Classification Tool.
Categories AI and Emerging Tech Policy and Guidance, AI Risks, Google Gemini Features