The Take — A diary in Claude isn't a written threat

Share
The Take — A diary in Claude isn't a written threat

I think charging Carli Michelle Heller with a second-degree felony over a sentence she typed into Claude at 5:10 a.m. stretches Florida's written-threat statute past recognition. A message addressed to nobody is not a writing transmitted "in any manner in which it may be viewed by another person" — unless the only person who views it is your chatbot vendor's safety reviewer, and if that is the rule, nothing you type into any moderated app is private anymore.

Our morning brief and yesterday's deep dive walked through the record, so here is only what the argument needs: on September 26, Claude's automated monitoring flagged her message, a human review team judged it credible, and the Lee County Sheriff's Office arrested her four days later at her Bonita Springs home. She now faces a charge under Florida Statute 836.10 — a second-degree felony carrying up to 15 years and a $10,000 fine — with a court date in November. The statute makes it a crime to "send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record" containing a threat to kill or injure a person or commit a mass shooting, provided it is done "in any manner in which it may be viewed by another person." That last clause is doing all the work, and it is where the state's case and the statute's purpose part company.

That clause exists to separate posted threats from private speech. It is the statute's constitutional shock absorber: reach the note passed in class, the message sent to a victim, the threat published where strangers will see it — but leave the ravings of someone alone in a room alone. The First Amendment does not protect true threats, and Florida, like every state, narrows its statute with an audience element to keep it that way. Heller told investigators she used AI like a diary, per the sheriff's own account. She did not send the sentence to the Lee County Sheriff's Office; she did not send it to anyone; there is no report that she expected Claude to deliver it. If she procured no transmission to any person, the act the statute criminalizes never happened — what happened is that the platform read her text and forwarded it. Surveillance is not transmission, and a moderator is not the audience a sender threatens.

And the audience the state wants to count was created by the vendor's policy, not by her. The only human beings who read that sentence before the deputies arrived are employed by Anthropic, under a usage policy that reserves safety review. Take the prosecution's logic to its end and every service with human moderators has a criminal channel: mail providers scan for illegal material, chat apps review reported messages, social platforms moderate direct messages. If "may be viewed by another person" includes whoever the company's own reviewers are, then the audience element is satisfied by default for every digital message in existence, and the private-diary use case — which conversational products are designed and marketed to feel like — becomes prosecutable by definition. The deterrent would land on exactly the people typing in crisis at 5:10 a.m., not on plotters, who do not type their plans into a product with terms of service.

The counter-case is strong, and it deserves better than dismissal. The statutory text is genuinely broad — "post," "transmit," "any manner" — and the plainest reading of "may be viewed by another person" is foreseeability: the terms of service told her humans may read her conversations, so a human read it. Sheriff Carmine Marceno made the user-side version himself, warning that "you are never truly anonymous, specifically in AI chatrooms and searches." On the facts, the threat was not vague: a named law enforcement facility, stated intent, then a next-day post that she had gotten a new gun. Lee County arrested a second man the same week over an AI-generated image threatening Marceno — these prosecutors clearly treat AI channels as real channels, and a chatbot is not a locked drawer. Above all, the referral itself is defensible: Anthropic's published policy permits disclosure to law enforcement to prevent death or serious injury, and the industry's liability map now punishes silence — British Columbia sued OpenAI in September for flagging conversations and not referring them, Florida sued OpenAI in June over the Florida State University shooting, and thirty families added aiding-and-abetting claims in September. I would not want to be the vendor that sat on that message. As legal analyst Michael Raheb put it, prosecuting this is "not going to be easy," and the terrain is "a very slippery slope."

Why the take holds anyway: the referral and the charge are two different questions, and only one of them is close. Whether Anthropic should call the police is a corporate judgment call, and on these facts most of us would make it. Whether the state can turn a private sentence into a felony under a statute built around an audience is a question of law, and the state has to win it with Heller's act — send, post, transmit, procure — not with the platform's. The legislature can fix this cleanly tomorrow: if Florida wants threats typed into chatbots covered, it can say so, name the intent standard it means (did the sender mean to reach a person?), and write the duty in. What it should not get is a precedent that reads the audience element out of the law by treating the vendor's safety queue as the recipient. Courtrooms, not escalation queues, are where "another person may view it" should be settled.

What would change my mind: evidence that Heller intended the message to reach the Sheriff's Office — that she believed Claude would deliver it, or posted it where deputies' eyes were the point — would make this ordinary transmission and collapse the diary framing. So would an appellate ruling squarely holding that foreseeable platform review satisfies 836.10; if Florida's courts say it plainly, the honest response is to change the law, not complain about the charge. And if published data ever showed private chatbot threats converting into attacks at a rate that demands intervention before a crime exists, I would swap the whole debate for a legislated duty-to-warn with published thresholds — a rule written in the open, applied the same way to every vendor, instead of a standard no user has ever seen.

If the only person who reads your words before the police do works for the app, what exactly is a private message in 2026? Tell us in the comments.

Read more

Five found the same MCP hole — the protocol itself is the problem

Five found the same MCP hole — the protocol itself is the problem

The agent stack keeps discovering that its plumbing trusts the wrong things — and tonight's lead is a security flaw that five unrelated organizations had to patch separately before anyone called it by name. One vulnerability, five vendors: researchers say MCP's trust model is structurally broken. Independent researcher Syed Anas Mohiuddin has spent four months disclosing what he calls "protocol pivoting" — an attack where an adversary gets in through one protocol, then rides the trust assumpti

Altman says the world must accept AI's 'bad things'

Altman says the world must accept AI's 'bad things'

A heavy news day for AI governance and open weights: OpenAI's CEO is publicly pricing the trade-off his industry keeps dodging, Reflection finally put specs on the model it teased yesterday, and AMD is trying to set the terms before Nvidia's RTX Spark lands. Altman says the world should accept AI's "bad things" — and the labs' new pact agrees. In an interview released Monday on Politico's Decoded podcast, Sam Altman said OpenAI's position is "we believe that the world should accept some bad th

Today in AI — October 5, 2026

Today in AI — October 5, 2026

The day the ecosystem stopped pretending everyone is a partner: Meta and Microsoft quietly cut their Claude budgets, Washington gave AI policy a new name, and New York City put lab executives under oath. Elsewhere, one model learned to drive a robot, and Mac users finally got Apple Intelligence off their disks. Models & Research * Reka AI's Rho-1 collapses the multimodal stack into a single 19-billion-parameter model. The research preview runs text, images, video and robot control as token

OpenAI adds text watermarking to ChatGPT and Codex — EU first

OpenAI adds text watermarking to ChatGPT and Codex — EU first

Regulation is now shipping inside the product: OpenAI's EU-only watermark rollout lands today, Wikimedia publishes its evidence against OpenAI's agents, and two of Anthropic's biggest customers are easing off Claude. OpenAI is turning on invisible text watermarking in ChatGPT and Codex — starting with the European Union. Over the coming weeks, eligible EU users across all plans will get a machine-readable signal called textGrain woven into the text the model produces, while API customers anywh