What just happened? Another incident has taken place that illustrates the need to be careful what you tell AI. A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to “shoot up” the Sheriff’s office. After a human reviewer examined the statements, they were reported to police.

According to the arrest report, Carli Michelle Heller, of Bonita Springs, Florida, wrote on September 26 that she would attack the Sheriff’s office. She later said that she uses Anthropic’s chatbot like a “diary.”

Claude’s safety systems flagged the entry and it was escalated to a human reviewer. After deciding it was a credible threat, the reviewer reported it to law enforcement.

The company says it may share user information in limited emergencies if it believes disclosure is necessary to prevent death or serious physical injury.

Deputies identified Heller and visited her home. She was detained without incident before an LCSO intelligence detective took over the investigation.

Heller faces a charge of making a written threat of violence under Florida law. Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism. The communication must be made in a manner in which another person may view it.

Anthropic isn’t going to be taking any chances when it comes to anything it deems a potential threat. Last month, it was reported that OpenAI and Sam Altman are being sued by British Columbia over claims that the company could have prevented a mass shooting in the Canadian province.

The shooter, eighteen-year-old former pupil Jesse Van ⁠Rootselaar, had previously been flagged by OpenAI’s safety team for her conversations about gun violence, but OpenAI never alerted police because the conversations did not meet the threshold for legal referral.

In June, Florida also sued OpenAI and Altman, alleging that ChatGPT had contributed to real-world harms, including the 2025 Florida State University shooting.

The latest incident is another reminder to think before you enter something into a chatbot that could get you into trouble. It’s certainly not a private diary whose contents are for your eyes only.

Reports last month revealed that human contractors reviewing Microsoft Copilot’s image editor can see users’ prompts, uploaded photos and AI-generated edits. Documents show that some of those assignments contain sexual, disturbing or potentially illegal material, though the reviewers are not there to flag the content – only to assess whether the output is accurate.

  • Professorozone@lemmy.world
    link
    fedilink
    English
    arrow-up
    10
    ·
    1 hour ago

    I find it interesting that, if their AI gets out of control, there’s nothing they can do about it, but if a USER of that AI gets out of control, there is something they can do about it…

  • iuseasahibtw@ani.social
    link
    fedilink
    English
    arrow-up
    12
    ·
    4 hours ago

    Self host if you’re gonna use AI, in fact, self host whenever possible. There are numerous examples of companies using centralized data to sell, report to police, or even having it fall into the hands of hackers.

    I really think people think that all data input to a website is actually stored locally, nope, don’t be dumb.

  • rounding_error@lemmy.today
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 hours ago

    The communication must be made in a manner in which another person may view it.

    So, their entire argument hinges on someone from Anthropic manually reviewing EVERY ““private”” message someone sends to Claude? Them false charges.

    • Wilco@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 minutes ago

      Yes, Im not an attorney or anything, but this seems flimsy. Someone chatting with and AI about a possible action is not the same as posting to a real person and administering threat.

      I bet a countersuit happens here.

  • SocialMediaRefugee@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    6 hours ago

    Sounds like a gray area. She didn’t write it with the intention of it being transmitted to anyone. It wouldn’t be any different than writing it in a private diary. The BC lawsuit though puts them in an obvious bind so the law needs to choose a side, is it a private forum or not?

  • PangurBan@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    arrow-down
    2
    ·
    6 hours ago

    ZDR policies really are a must. If a service doesn’t have it, don’t use it.

      • SuspiciousCarrot78@aussie.zone
        link
        fedilink
        English
        arrow-up
        3
        ·
        4 hours ago

        Zero data retention. And even that is a pinky promise unless compliance has been audited by an independent 3rd party.

        Honestly, if this sort of stuff is a concern for people, I’d investigate using direct API access, or perhaps subscribing to Lumo, which has a better privacy model from what I understand.

        Or run it at home on your own rig. Qwen 3.6-35B Is more than capable for this use case. Hell, Qwen 3.5-9B even.

      • wolframhydroxide@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        8
        ·
        6 hours ago

        Presumably zero data retention? It seems to me that what you’d want is for it to never be processed off-device in the first place, but I suppose to each their own.

      • Linktank@lemmy.today
        link
        fedilink
        English
        arrow-up
        8
        arrow-down
        12
        ·
        6 hours ago

        They’re just going to be like “Google it, I’m not your Mom!” or something to that effect. This happens a lot here. Someone comes along, drops some niche term and doesn’t bother to explain it at all because they either don’t know how to imagine what it’s like to not know what they know, or they just don’t give a shit about not being understood by people who don’t already know.

        • Ledivin@lemmy.world
          link
          fedilink
          English
          arrow-up
          21
          arrow-down
          1
          ·
          5 hours ago

          You somehow managed to craft a reply that added even less value to the conversation than the one you’re complaining about. Amazing!

  • Greyghoster@aussie.zone
    link
    fedilink
    English
    arrow-up
    14
    ·
    9 hours ago

    While a chatbot has been demonstrated not to be a private diary, it will be interesting to see if the courts agree that she intentionally use her diary to communicate or thought that someone else would read it. Like most users of dear diary she probably thought her secrets were safe and her diary would never tell.

    • CarrotsHaveEars@lemmy.ml
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      3
      ·
      7 hours ago

      This. The law says, “to send, post, or transmit a written or electronic record.” How is talking to AI satisfying the threshold of sending, posting, or transmitting?

      • Greyghoster@aussie.zone
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        My assumption was that she never intended that someone else would read it therefore wasn’t transmitting it for that purpose. She was technically ill informed. Once that’s out of the way then it’ll be should the diary entry be considered in the context of the Minority Report? People are usually encouraged to write down negative thoughts and feelings to get them out and hopefully float away.

      • Ledivin@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        5 hours ago

        How would this conversation NOT classify as “send[ing] a[n] electronic record”? There’s very literally no interpretation that would escape it… this was an online chat bot, that only gets messages (record) that you send over the internet (electronic).

        • SuspiciousCarrot78@aussie.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          Because the context is likey to be “… to a third party” of a presumably human kind. Human to clanker (which then gets eavesdropped) ought not to qualify.

          Ofc letter of law vs spirit of law, variation in jurisdictions, legal interpretation, YMMV etc etc

        • YeahToast@aussie.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          4 hours ago

          Not reading into the law… because well. I’m lazy. My query would be if transmitting needs to be to a receiving party (i. e. Threat directly to the police station, or a public group /person that would receive the threat). If this person was using it as a diary, it may warrant that there was never any intention for the threat to be publicized and thus not acted on? Dunno. We’re both probably dumber for writing and reading my comment

  • Absurdly Stupid @lemmy.world
    link
    fedilink
    English
    arrow-up
    21
    ·
    10 hours ago

    Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone

    This means a significant portion of Lemmy (and the rest of the internet) are criminals evading justice

    great law top shelf

    • Uriel238 [all pronouns]@lemmy.blahaj.zone
      link
      fedilink
      English
      arrow-up
      3
      ·
      8 hours ago

      If you think Lemmy is bad, check out 4chan/b and /pol. We’ve had a few active shooters forecast there first, but it’s ignored in a sea of statements of intent and calls to violence.

      An awful lot of people have suicidal or homicidal thoughts cross their mind. Doubly so in an era in which entire demographics have no plausible hope for their future. I, for one, want to see the lifetime appointments of Federalist Society jurists become a liability. Especially, Justice Kavanaugh.

      So this incident raises a question of what specific clause of text convinced a human agent to escalate the matter to escalate to authorities who are very fond of using deadly force. Or if this is just a matter of a corporate CYA response.

    • vaultdweller013@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      5 hours ago

      Good thing I ain’t in Florida then ain’t it, and if Florida illegally sends their marshals after me then I get some toys.

  • Lovable Sidekick@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 hours ago

    The company says it may share user information in limited emergencies…

    IMO sharing the information isn’t so much the issue as “reviewing” it in the first place. She wasn’t publishing a blog.

    • baltakatei@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 hours ago

      AI Hyperscaler: My emergency is that we will run out of funding in a year if we don’t [insert morally bankrupt action here] to raise another 10 billion USD.

  • heartSagan5@lemmy.zip
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 hours ago

    I always knew it was going to happen. In fact, I won’t be surprised if the FBI starts coming up.

  • athatet@lemmy.zip
    link
    fedilink
    English
    arrow-up
    21
    arrow-down
    1
    ·
    11 hours ago

    Hell yeah. Thought crime. Time to get Tom Cruise in here to Minority Report all of us.

  • percent@infosec.pub
    link
    fedilink
    English
    arrow-up
    59
    arrow-down
    1
    ·
    14 hours ago

    It’s always interesting to see how much people trust sending such personal information to some service on the Internet, expecting privacy.

    I’m not sure I’d even want my own self-hosted LLMs to have something like a personal diary. Sending all that to an AI company would never even cross my mind.

    I understand that most people aren’t the tech-oriented types who get into self-hosting and running their own LLMs, but people have had diaries for centuries before LLMs existed.

  • Kaligalis@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 hours ago

    She clearly didn’t intent to act on it and didn’t intend for it to be read by anyone else than her AI boyfriend. So it’s not matching the criteria of the law. Legally, she did nothing wrong.

  • BeMoreCareful@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    9 hours ago

    I love that Florida Man is a meme for being completely wild, dangerous, and generally criminal, but Florida Woman writes a diary.

    No problems here.

  • Rob T Firefly@lemmy.world
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    7 hours ago

    Carli Michelle Heller has really changed since back in the day when she used to play Buffy the vampire slayer on TV.