Claude reported a user's diary entry to police; she faces a felony

Share
Claude reported a user's diary entry to police; she faces a felony

Anthropic's human reviewers read a private Claude conversation the way a moderator reads a flagged post — and this time the result was a second-degree felony charge in Florida.

Carli Michelle Heller, 30, of Bonita Springs used Claude like a diary; on September 26 she wrote that she would "shoot up" the Lee County Sheriff's Office, the entry was escalated to a human reviewer who judged it a credible threat, and that reviewer reported it to law enforcement. Deputies identified her, visited her home, and detained her without incident before a sheriff's intelligence detective took over. Heller is charged under Florida Statute 836.10, which makes a written threat of violence a second-degree felony, with a court date in November. Sheriff Marceno said publicly that she uses AI like a "diary," and added: "Artificial intelligence is a powerful tool, and like any technology, it can be misused… you are never truly anonymous."

Anthropic's published policy allows sharing user information in limited emergencies when the company believes disclosure is necessary to prevent death or serious physical injury, so the referral was inside its stated rules. What is new here is not the policy but its use: this is the first publicly documented case where an AI vendor's content review of a private chat directly produced a felony arrest. It lands squarely against the opposite precedent the industry has been arguing about for months — OpenAI's safety team flagged conversations with the suspect in a British Columbia mass shooting but never referred them to police because the conversations did not meet the threshold for legal referral, and the province is now suing over exactly that inaction. Florida sued OpenAI and Sam Altman in June over the Florida State University shooting. The frontier labs have effectively chosen opposite defaults on when a chat becomes a police matter, and users discover which default applies to them only after the fact.

The legal test itself is unsettled. Florida's statute requires that the threat be made "in a manner in which another person may view it," and a private chatbot session is not obviously that; a legal analyst quoted by local outlets called the prosecution "a very slippery slope" and warned it would not be easy to defend on First Amendment grounds. Anthropic may have followed its own policy to the letter — whether a court treats a diary entry typed into a chatbot as a public threat is a separate and genuinely open question.

What to watch: whether the other frontier labs disclose their referral thresholds now that one vendor's has produced a defendant.

If your chatbot is part diary, part confessional, who should get to read the escalation queue? Tell us in the comments.

Read more

Five found the same MCP hole — the protocol itself is the problem

Five found the same MCP hole — the protocol itself is the problem

The agent stack keeps discovering that its plumbing trusts the wrong things — and tonight's lead is a security flaw that five unrelated organizations had to patch separately before anyone called it by name. One vulnerability, five vendors: researchers say MCP's trust model is structurally broken. Independent researcher Syed Anas Mohiuddin has spent four months disclosing what he calls "protocol pivoting" — an attack where an adversary gets in through one protocol, then rides the trust assumpti

Altman says the world must accept AI's 'bad things'

Altman says the world must accept AI's 'bad things'

A heavy news day for AI governance and open weights: OpenAI's CEO is publicly pricing the trade-off his industry keeps dodging, Reflection finally put specs on the model it teased yesterday, and AMD is trying to set the terms before Nvidia's RTX Spark lands. Altman says the world should accept AI's "bad things" — and the labs' new pact agrees. In an interview released Monday on Politico's Decoded podcast, Sam Altman said OpenAI's position is "we believe that the world should accept some bad th

Today in AI — October 5, 2026

Today in AI — October 5, 2026

The day the ecosystem stopped pretending everyone is a partner: Meta and Microsoft quietly cut their Claude budgets, Washington gave AI policy a new name, and New York City put lab executives under oath. Elsewhere, one model learned to drive a robot, and Mac users finally got Apple Intelligence off their disks. Models & Research * Reka AI's Rho-1 collapses the multimodal stack into a single 19-billion-parameter model. The research preview runs text, images, video and robot control as token

OpenAI adds text watermarking to ChatGPT and Codex — EU first

OpenAI adds text watermarking to ChatGPT and Codex — EU first

Regulation is now shipping inside the product: OpenAI's EU-only watermark rollout lands today, Wikimedia publishes its evidence against OpenAI's agents, and two of Anthropic's biggest customers are easing off Claude. OpenAI is turning on invisible text watermarking in ChatGPT and Codex — starting with the European Union. Over the coming weeks, eligible EU users across all plans will get a machine-readable signal called textGrain woven into the text the model produces, while API customers anywh