Confirmed
Shared Claude chats surfaced in Google search because robots.txt disallow isn't noindex
Shared Claude chat links surfaced in Google search over the weekend of July 25-26, 2026, exposing medical records, internal documents, and children's names in some chats, per TechCrunch. Search Engine Journal's July 27 check of claude.ai's robots.txt found /share/* disallowed for all crawlers, yet those same URLs return an X-Robots-Tag: none (noindex) header Google can't read because it's blocked from crawling the page. Anthropic says only publicly posted links get indexed; unsharing a chat doesn't remove it from Google's index.
In plain termsRobots.txt only tells search engines please don't visit this page; it can't erase a page that's already listed, which is why Google still showed chat links it was never allowed to open.
Why it mattersFor any site using robots.txt to hide sensitive paths, this is a reminder that disallow only stops crawling, not indexing, and noindex only works if the crawler is allowed to read it.
Our takeExpect more of these disclosures as AI products ship shareable links faster than their crawl directives get audited. Any site treating robots.txt as an access control rather than a crawl hint is one linked mention away from the same exposure.
Confirmed
Google Ads API makes passkeys mandatory for new OAuth refresh tokens
Starting August 5, 2026, Google Ads API's user authentication workflow will require a passkey to generate new OAuth 2.0 refresh tokens, replacing passwords and SMS/TOTP two-factor codes, per Google's Ads Developer Blog. Existing refresh tokens keep working unchanged. New passkeys carry a 7-day security delay before they're trusted. The requirement extends to Google Ads Editor, Ads Scripts, BigQuery Data Transfer Service, and Data Studio; service-account workflows are unaffected.
In plain termsA passkey is a login tied to your device, like Face ID or a security key, instead of a password; Google is requiring one specifically for the process that mints API access tokens, not for everyday Ads login.
Why it mattersAgencies and SaaS platforms that mint OAuth tokens on behalf of Google Ads clients need a passkey enrolled well before August 5 to avoid onboarding delays from the 7-day trust window.
Our takePasskey mandates are becoming Google's default lever for API-level account security, the same pattern that shaped April's 2FA rollout. Expect it to extend to other high-value APIs, like Merchant Center and Search Console, before long.
Confirmed
Snowflake launches Cortex AI Gateway for agent and MCP governance
At Black Hat 2026, Snowflake announced Cortex AI Gateway, a centralized layer built by integrating Natoma's MCP gateway to enforce identity, policy, and audit at the tool-call level for AI agents, covering both Snowflake-native tools and third-party ecosystems like Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, and Cursor. Alongside it, Snowflake moved Agent Identity tracking and AI Security Posture Management to general availability, and launched a new Data Exfiltration Prevention package into preview.
In plain termsMCP is the connector standard AI agents use to plug into company databases and tools; governance here means Snowflake can now see and restrict what an agent actually does through that connector, not just whether it's allowed to connect.
Why it mattersMCP tool-call governance is becoming a checked box on enterprise AI security reviews, and this is a major data-cloud vendor bundling it directly into the platform rather than leaving it to a point solution.
Our takeMCP adoption inside the enterprise is outrunning its governance tooling, and Snowflake bundling identity, audit, and cost controls directly into the data platform is the shape most vendors will converge on rather than bolting a separate proxy in front of every agent.
Confirmed
SAP Business Data Cloud Connect for BigQuery reaches general availability
SAP and Google Cloud announced general availability of SAP Business Data Cloud (BDC) Connect for BigQuery on July 27, 2026, giving zero-copy, bidirectional access between SAP data products and BigQuery without replicating or copying data. The connector supports SAP Business Data Cloud instances on Google Cloud and AWS, with Azure-hosted support coming soon, and is aimed at grounding AI agents (Gemini Enterprise, SAP Joule) in live operational data rather than stale exports.
In plain termsZero-copy means BigQuery can query SAP's data live, in place, instead of a pipeline exporting and reloading a duplicate copy that's already stale by the time it lands.
Why it mattersZero-copy cross-platform data access removes one more excuse for stale product or inventory data feeding AI shopping and search surfaces, if your stack touches both SAP and BigQuery.
Our takeZero-copy connectors are quietly becoming the default answer to the my AI agent is reasoning over three-day-old data complaint. Expect the same pattern to show up between BigQuery and other ERPs, like Oracle and Workday, before this becomes a differentiator instead of table stakes.
Confirmed
Shopify Payments drops the 8-currency limit on payout bank accounts
Shopify removed the 8-currency cap on bank accounts for multi-currency payouts in Shopify Payments as of July 27, 2026; merchants can now add one bank account per supported payout currency their region and plan allow. Multi-currency payouts let merchants receive customer payments in the currency charged, avoiding a currency conversion back to their home currency and keeping balances in currencies they already use to pay suppliers, staff, and taxes abroad. Fees still apply to non-domestic-currency payouts.
In plain termsMulti-currency payouts mean a UK customer's GBP payment lands in a GBP bank account directly, instead of Shopify converting it to USD first and merchants losing a cut to the exchange rate both ways.
Why it mattersMerchants selling into many currencies can now cut FX conversion drag on every payout, not just a chosen 8, directly improving international margin without touching pricing or feeds.
Our takeCurrency-account limits like this one are usually solved for the largest sellers first and rarely make headlines, so removing an 8-account cap signals Shopify is now optimizing payouts for mid-market international merchants, not just enterprise.
Confirmed
Shopify POS adds Bluetooth device-to-device login
Shopify POS launched quick nearby device login on July 27, 2026: a staff member with the POS Device Setup role can approve a new device from one already signed in, detected over Bluetooth (or via QR code scan without Bluetooth), then enter a store manager PIN, replacing manual credential entry on busy floors. New devices sign in for the current day only by default; merchants can enable a Forever session option in POS channel admin for longer sessions.
In plain termsInstead of typing a username and password on a new register mid-rush, a manager taps approve on a phone that's already logged in, the same trust-transfer pattern as pairing a smart TV remote.
Why it mattersFaster device onboarding at the register cuts checkout-line friction during peak traffic, a direct conversion lever for brick-and-mortar retailers running Shopify POS at scale.
Our takeDevice-to-device auth like this is Shopify importing a consumer-hardware pattern (think smart-home device pairing) into retail ops, and it reads as POS being engineered for speed of onboarding as a competitive axis, not just feature parity with Square or Clover.
Confirmed
Shopify POS cart sharing enables floor-to-register handoffs
Shopify released cart sharing for Shopify POS on July 27, 2026 (version 11.11, POS Pro only): any team member can pick up, continue, or close a colleague's cart from another device, with carts saving automatically and a view filtered to the signed-in staff member by default. This enables floor-to-register selling: an associate builds a cart with a customer, then hands it off for someone else to close at the register; any cart converts to a draft order in one action.
In plain termsIt's the retail equivalent of a shared cart in the cloud: whoever's holding the tablet inherits exactly what the last associate built, instead of re-ringing every item at the register.
Why it mattersCart continuity across devices removes a common line-loss point: a customer who was mid-cart on the floor no longer has to restart at the register.
Our takeCart-state-as-a-shared-object across devices is the same pattern e-commerce solved years ago with persistent server-side carts. Shopify porting it to physical POS suggests the online and offline retail stacks are converging on shared primitives rather than staying separate systems.
Observed
Google Search Console's page indexing report is stuck on weekly, not daily, data
Google Search Console's page indexing report has been intermittently stuck since June 11, 2026, per Search Engine Roundtable's Barry Schwartz, who has logged the gaps daily and says it recurred again on July 27. Data collapses into weekly, not daily, snapshots across three stretches so far: June 13-30 (18 days), July 1-10 (10 days), and July 11-24 (14 days), corroborated by SEO Brodie Clark's own account data on X. Google has not commented or acknowledged the issue.
In plain termsSearch Console's indexing report is supposed to update daily; instead it's been freezing for one to two-and-a-half weeks at a stretch since mid-June, so a change made today might not show up in the report for a while, and that isn't a sign the fix failed.
Why it mattersIf your indexing-status debugging depends on day-over-day GSC deltas right now, budget for the report lagging weeks behind, not days, until Google fixes the pipeline.
Our takeUnannounced pipeline lag in a core GSC report is the kind of silent regression that only surfaces because independent practitioners are cross-checking their own dashboards daily. It's worth remembering the next time a report's silence looks like a ranking problem instead of a reporting one.