# Pulse · July 28, 2026

> Google indexes shared Claude chats past a blocked noindex header, Google Ads mandates passkeys, and Snowflake ships MCP agent governance at Black Hat.

Canonical: https://brandonlazovic.dev/pulse/2026-07-28/  
Author: Brandon Lazovic  
Published: 2026-07-28

## Shared Claude chats surfaced in Google search because robots.txt disallow isn't noindex

Status: Confirmed  |  Topics: crawling-indexing-rendering, organic-search-core

Shared Claude chat links surfaced in Google search over the weekend of July 25-26, 2026, exposing medical records, internal documents, and children's names in some chats, per TechCrunch. Search Engine Journal's July 27 check of claude.ai's robots.txt found /share/* disallowed for all crawlers, yet those same URLs return an X-Robots-Tag: none (noindex) header Google can't read because it's blocked from crawling the page. Anthropic says only publicly posted links get indexed; unsharing a chat doesn't remove it from Google's index.

In plain terms: Robots.txt only tells search engines please don't visit this page; it can't erase a page that's already listed, which is why Google still showed chat links it was never allowed to open.

Why it matters: For any site using robots.txt to hide sensitive paths, this is a reminder that disallow only stops crawling, not indexing, and noindex only works if the crawler is allowed to read it.

Our take: Expect more of these disclosures as AI products ship shareable links faster than their crawl directives get audited. Any site treating robots.txt as an access control rather than a crawl hint is one linked mention away from the same exposure.

- [Search Engine Journal: Indexed Claude Chats Show Why Disallow Is Not Noindex](https://www.searchenginejournal.com/indexed-claude-chats-show-why-disallow-is-not-noindex/583852/)
- [claude.ai/robots.txt (verified 2026-07-28)](https://claude.ai/robots.txt)

## Google Ads API makes passkeys mandatory for new OAuth refresh tokens

Status: Confirmed  |  Topics: ads-paid

Starting August 5, 2026, Google Ads API's user authentication workflow will require a passkey to generate new OAuth 2.0 refresh tokens, replacing passwords and SMS/TOTP two-factor codes, per Google's Ads Developer Blog. Existing refresh tokens keep working unchanged. New passkeys carry a 7-day security delay before they're trusted. The requirement extends to Google Ads Editor, Ads Scripts, BigQuery Data Transfer Service, and Data Studio; service-account workflows are unaffected.

In plain terms: A passkey is a login tied to your device, like Face ID or a security key, instead of a password; Google is requiring one specifically for the process that mints API access tokens, not for everyday Ads login.

Why it matters: Agencies and SaaS platforms that mint OAuth tokens on behalf of Google Ads clients need a passkey enrolled well before August 5 to avoid onboarding delays from the 7-day trust window.

Our take: Passkey mandates are becoming Google's default lever for API-level account security, the same pattern that shaped April's 2FA rollout. Expect it to extend to other high-value APIs, like Merchant Center and Search Console, before long.

- [Google Ads Developer Blog: Passkey authentication requirement for the Google Ads API](https://ads-developers.googleblog.com/2026/07/passkey-authentication-requirement-for.html)

## Snowflake launches Cortex AI Gateway for agent and MCP governance

Status: Confirmed  |  Topics: ai-data-stack, llm-models-agents

At Black Hat 2026, Snowflake announced Cortex AI Gateway, a centralized layer built by integrating Natoma's MCP gateway to enforce identity, policy, and audit at the tool-call level for AI agents, covering both Snowflake-native tools and third-party ecosystems like Amazon Bedrock, Azure AI Foundry, ChatGPT, Claude Code, and Cursor. Alongside it, Snowflake moved Agent Identity tracking and AI Security Posture Management to general availability, and launched a new Data Exfiltration Prevention package into preview.

In plain terms: MCP is the connector standard AI agents use to plug into company databases and tools; governance here means Snowflake can now see and restrict what an agent actually does through that connector, not just whether it's allowed to connect.

Why it matters: MCP tool-call governance is becoming a checked box on enterprise AI security reviews, and this is a major data-cloud vendor bundling it directly into the platform rather than leaving it to a point solution.

Our take: MCP adoption inside the enterprise is outrunning its governance tooling, and Snowflake bundling identity, audit, and cost controls directly into the data platform is the shape most vendors will converge on rather than bolting a separate proxy in front of every agent.

- [Snowflake Blog: Snowflake Launches Cortex AI Gateway and Advanced AI Security at Black Hat 2026](https://www.snowflake.com/en/blog/enterprise-ai-security-agentic-mcp-governance/)

## SAP Business Data Cloud Connect for BigQuery reaches general availability

Status: Confirmed  |  Topics: ai-data-stack

SAP and Google Cloud announced general availability of SAP Business Data Cloud (BDC) Connect for BigQuery on July 27, 2026, giving zero-copy, bidirectional access between SAP data products and BigQuery without replicating or copying data. The connector supports SAP Business Data Cloud instances on Google Cloud and AWS, with Azure-hosted support coming soon, and is aimed at grounding AI agents (Gemini Enterprise, SAP Joule) in live operational data rather than stale exports.

In plain terms: Zero-copy means BigQuery can query SAP's data live, in place, instead of a pipeline exporting and reloading a duplicate copy that's already stale by the time it lands.

Why it matters: Zero-copy cross-platform data access removes one more excuse for stale product or inventory data feeding AI shopping and search surfaces, if your stack touches both SAP and BigQuery.

Our take: Zero-copy connectors are quietly becoming the default answer to the my AI agent is reasoning over three-day-old data complaint. Expect the same pattern to show up between BigQuery and other ERPs, like Oracle and Workday, before this becomes a differentiator instead of table stakes.

- [Google Cloud Blog: SAP and Google Cloud launch BDC Connect for BigQuery](https://cloud.google.com/blog/products/sap-google-cloud/sap-and-google-cloud-launch-bdc-connect-for-bigquery/)

## Shopify Payments drops the 8-currency limit on payout bank accounts

Status: Confirmed  |  Topics: platform-ecommerce

Shopify removed the 8-currency cap on bank accounts for multi-currency payouts in Shopify Payments as of July 27, 2026; merchants can now add one bank account per supported payout currency their region and plan allow. Multi-currency payouts let merchants receive customer payments in the currency charged, avoiding a currency conversion back to their home currency and keeping balances in currencies they already use to pay suppliers, staff, and taxes abroad. Fees still apply to non-domestic-currency payouts.

In plain terms: Multi-currency payouts mean a UK customer's GBP payment lands in a GBP bank account directly, instead of Shopify converting it to USD first and merchants losing a cut to the exchange rate both ways.

Why it matters: Merchants selling into many currencies can now cut FX conversion drag on every payout, not just a chosen 8, directly improving international margin without touching pricing or feeds.

Our take: Currency-account limits like this one are usually solved for the largest sellers first and rarely make headlines, so removing an 8-account cap signals Shopify is now optimizing payouts for mid-market international merchants, not just enterprise.

- [Shopify Changelog: Add a bank account for every payout currency in Shopify Payments](https://changelog.shopify.com/posts/add-a-bank-account-for-every-payout-currency)

## Shopify POS adds Bluetooth device-to-device login

Status: Confirmed  |  Topics: platform-ecommerce

Shopify POS launched quick nearby device login on July 27, 2026: a staff member with the POS Device Setup role can approve a new device from one already signed in, detected over Bluetooth (or via QR code scan without Bluetooth), then enter a store manager PIN, replacing manual credential entry on busy floors. New devices sign in for the current day only by default; merchants can enable a Forever session option in POS channel admin for longer sessions.

In plain terms: Instead of typing a username and password on a new register mid-rush, a manager taps approve on a phone that's already logged in, the same trust-transfer pattern as pairing a smart TV remote.

Why it matters: Faster device onboarding at the register cuts checkout-line friction during peak traffic, a direct conversion lever for brick-and-mortar retailers running Shopify POS at scale.

Our take: Device-to-device auth like this is Shopify importing a consumer-hardware pattern (think smart-home device pairing) into retail ops, and it reads as POS being engineered for speed of onboarding as a competitive axis, not just feature parity with Square or Clover.

- [Shopify Changelog: Quick nearby device login](https://changelog.shopify.com/posts/quick-nearby-device-login)

## Shopify POS cart sharing enables floor-to-register handoffs

Status: Confirmed  |  Topics: platform-ecommerce

Shopify released cart sharing for Shopify POS on July 27, 2026 (version 11.11, POS Pro only): any team member can pick up, continue, or close a colleague's cart from another device, with carts saving automatically and a view filtered to the signed-in staff member by default. This enables floor-to-register selling: an associate builds a cart with a customer, then hands it off for someone else to close at the register; any cart converts to a draft order in one action.

In plain terms: It's the retail equivalent of a shared cart in the cloud: whoever's holding the tablet inherits exactly what the last associate built, instead of re-ringing every item at the register.

Why it matters: Cart continuity across devices removes a common line-loss point: a customer who was mid-cart on the floor no longer has to restart at the register.

Our take: Cart-state-as-a-shared-object across devices is the same pattern e-commerce solved years ago with persistent server-side carts. Shopify porting it to physical POS suggests the online and offline retail stacks are converging on shared primitives rather than staying separate systems.

- [Shopify Changelog: Cart sharing on Shopify POS](https://changelog.shopify.com/posts/cart-sharing-on-shopify-pos)

## Google Search Console's page indexing report is stuck on weekly, not daily, data

Status: Observed  |  Topics: measurement-analytics, organic-search-core

Google Search Console's page indexing report has been intermittently stuck since June 11, 2026, per Search Engine Roundtable's Barry Schwartz, who has logged the gaps daily and says it recurred again on July 27. Data collapses into weekly, not daily, snapshots across three stretches so far: June 13-30 (18 days), July 1-10 (10 days), and July 11-24 (14 days), corroborated by SEO Brodie Clark's own account data on X. Google has not commented or acknowledged the issue.

In plain terms: Search Console's indexing report is supposed to update daily; instead it's been freezing for one to two-and-a-half weeks at a stretch since mid-June, so a change made today might not show up in the report for a while, and that isn't a sign the fix failed.

Why it matters: If your indexing-status debugging depends on day-over-day GSC deltas right now, budget for the report lagging weeks behind, not days, until Google fixes the pipeline.

Our take: Unannounced pipeline lag in a core GSC report is the kind of silent regression that only surfaces because independent practitioners are cross-checking their own dashboards daily. It's worth remembering the next time a report's silence looks like a ranking problem instead of a reporting one.

- [Spotted by Search Engine Roundtable (Barry Schwartz)](https://www.seroundtable.com/google-page-indexing-report-delays-static-data-41769.html)
