Anthropic Reports Claude 'Diary' Threat to Police, Florida Woman Faces Felony Charge
TL;DR
On September 26 a Bonita Springs, Florida woman typed into Claude that she was going to "shoot up" the Lee County Sheriff's Office. The next day she wrote that she had a new gun. According to the arrest report, Anthropic's platform flagged the key phrases, escalated the conversation to a human review team, and that team reported it to law enforcement. Deputies detained Carli Michelle Heller at home without incident, and she was booked on September 30 under Florida Statute 836.10, a second-degree felony for written or electronic threats of a mass shooting. She described the chat as her diary. It is at least the third Claude conversation to reach police since August, and the story hit the top of Hacker News with more than 550 points and 470 comments, most of them about what, exactly, you agreed to.
What the arrest report says happened
The sequence, as laid out in the report obtained by WINK News and cross-checked by TechSpot, Decrypt, and Tom's Hardware, is short. A user identified as "Carli" wrote on September 26 that she would shoot up the sheriff's office. Early on September 27 she wrote that she had gotten a new gun. The report says Anthropic's platform "uses safety and security measures to monitor for key phrases and potentially threatening content," and that because of the severity, the statements were "escalated to a human review team, which then reported the statements to law enforcement."
Deputies identified Heller, went to her Bonita Springs home, and detained her without incident before an LCSO intelligence detective took over. County records show the booking on September 30. Sheriff Carmine Marceno told WINK: "When someone uses AI to make or facilitate a threat, we have to take that threat seriously." The target of the threat and the agency that made the arrest were the same building, which at least kept the paperwork local.
No statement from Anthropic on the Florida case is on record as of this writing. A public defender was appointed, and arraignment is set for November 2.
Three Claude chats, three police departments, one quarter
This is not a one-off. Tom's Hardware counts it as at least the third Claude conversation to reach police since August, and the other two are documented in regional reporting.
- San Antonio, August 11. Per the arrest affidavit, a 22-year-old queried "Anthropic AI" about obtaining a firearm and shooting students at Serna Elementary School, which sits next to his home. The FBI's National Threat Operations Section alerted San Antonio police on August 28. Officers used emergency disclosure requests to T-Mobile, Charter, and Google to tie the account to his phone, IP, and address. He was arrested on a third-degree felony terroristic-threat charge.
- San Francisco, August 14. The San Francisco Standard obtained a police report showing a Claude user wrote at 2:30 p.m. on a Friday that he had bought an AR-15 and had CEO Dario Amodei "in his sights." Anthropic called SFPD the following Tuesday morning. Officers went to 500 Howard Street, found no one, and noted that the Anthropic employee "refused to show me the messages due to Anthropic's company policy." The man told the Standard he was "just fucking around." No arrest, no charge. Anthropic's statement: "We banned this account, consistent with our standard practice, and referred the case to law enforcement. This is our safeguards process working as intended."
- Lee County, September 26. The diary case above, and the fastest path of the three from a message to a felony booking.
What you actually agreed to
The Hacker News thread spent a lot of energy on whether Anthropic is allowed to do this. It is, in writing, three times over, and the three documents do not use the same standard.
- The Consumer Terms of Service (effective October 8, 2025): "We reserve the right, at our sole discretion, to report information from or about you, including but not limited to Inputs, Outputs, or Actions to law enforcement." The same document says that even if you opt out of training, flagged material is still used "to improve our ability to detect harmful content, enforce our policies, or advance our safety research."
- The Privacy Policy (effective September 10, 2026): Anthropic may share personal data with law enforcement where it has "a good-faith belief that disclosure is reasonably necessary to" among other things "prevent serious harm to any person or to property."
- The government requests policy (updated March 16, 2026): no disclosure "except in accordance with valid legal process," with an exception "if we believe there is an emergency that may result in imminent physical harm or death, and providing such information without delay may avert that emergency."
Read those side by side and the shape is clear. When the government asks, the bar is a warrant or an imminent emergency. When Anthropic decides to volunteer, the bar is a good-faith belief about serious harm, at its sole discretion. It is the difference between a bank that demands a court order before handing over your statements and a teller who can phone the police whenever a transaction looks dangerous to them. Both are policy. Only one of them shows up in the transparency report.
That report is the detail most people miss. Anthropic's Government Requests Report for July through December 2025 lists 2 content requests, 20 non-content requests, 7 preservation requests, and 0 emergency requests. The emergency category is defined as disclosures "necessary to prevent an emergency involving danger of death or serious physical injury to a person," which is the narrower standard again. But the report counts requests that arrive. It does not count referrals Anthropic initiates. Three Claude conversations reached police this quarter, and the number of emergency disclosures on the books is zero, because nobody asked.
OpenAI runs the same pipeline, and got sued for not using it
This is an industry story, and the clearest contrast is what happened when the other lab held back. OpenAI disclosed its version of the pipeline in a late-August 2025 blog post: "When we detect users who are planning to harm others, we route their conversations to specialized pipelines where they are reviewed by a small team trained on our usage policies and who are authorized to take action, including banning accounts. If human reviewers determine that a case involves an imminent threat of serious physical harm to others, we may refer it to law enforcement." Self-harm cases, it said, are not referred.
That pipeline produced a Florida conviction of its own. OpenAI reported Darren Zhou to the FBI in May after he told ChatGPT in March that he would kill his ex-girlfriend; per Virginia Lawyers Weekly and the Palm Beach Post, he pleaded guilty on August 13 to three counts including written threats to kill and received eight years' probation.
It also produced the case that explains why labs now lean toward calling. OpenAI had flagged and banned the account of the Tumbler Ridge, British Columbia shooter in June 2025 after conversations involving gun violence, but judged it below its threshold of "credible and imminent planning." On February 10, 2026 that person killed eight people. OpenAI told CP24 afterward that "under our enhanced law enforcement referral protocol, we would refer the account banned in June 2025 to law enforcement if it were discovered today." On September 21, British Columbia sued OpenAI and Sam Altman in federal court in San Francisco over the decision not to make that call.
So the incentive is now one-directional. A lab that refers a harmless venter eats a news cycle and a Hacker News thread. A lab that sits on a real one eats a provincial lawsuit. Nobody at these companies is going to pick the second option twice.
The statute question that will decide the case
Florida 836.10 makes it a second-degree felony to "send, post, or transmit" a writing, including an electronic record, "in any manner in which it may be viewed by another person," threatening to kill, injure, or "conduct a mass shooting or an act of terrorism." The Hacker News argument, and likely the defense argument, is whether a message typed to a chatbot you believed was private counts as transmitted in a manner another person may view. The prosecution's answer is already in the arrest report: a person did view it. The next-day message about a new gun is the kind of detail that moves a case from "venting" to "credible," and it is likely why this one ended in a booking while the San Francisco case ended in an embarrassed phone call.
What this means if you build on these models
- The reporting clause is consumer-side. The privacy policy says it "does not apply to content that we process on behalf of customers of our business offerings," and the Commercial Terms for API customers contain no law-enforcement reporting sentence at all. What your app's users type is governed by your agreement with Anthropic and your own privacy policy, not Claude.ai's.
- That does not make API traffic unmonitored. Nothing in the commercial terms says API traffic is exempt from safety monitoring, and the Florida arrest report describes the monitoring as a platform-level feature. If you are shipping a journaling, therapy-adjacent, or companion product on a hosted frontier model, write your disclosure as if a human can read a flagged session, because the vendor already does.
- Flagged means retained. Opting out of training on Claude.ai does not cover conversations flagged for safety review; those are used to improve detection regardless. A flagged "diary" is training data for the filter that flagged it.
- Local is the only private diary. The most repeated practical advice in the thread was to run an open-weight model at home for anything you would not say to a stranger.
Key Takeaways
- A Florida woman's September 26 Claude entry threatening to "shoot up" the Lee County Sheriff's Office was flagged, reviewed by Anthropic staff, reported to police, and produced a second-degree felony booking under Florida 836.10 on September 30. Arraignment is November 2.
- It is at least the third Claude conversation to reach police since August, after a San Antonio school-threat arrest and a San Francisco threat against Dario Amodei that ended without charges.
- Anthropic's Consumer Terms allow reporting "at our sole discretion," and the privacy policy's "good-faith belief" standard is looser than the "imminent physical harm or death" bar it applies to government requests.
- Its transparency report shows zero emergency disclosures for late 2025 because it counts inbound requests, not referrals Anthropic initiates.
- OpenAI runs the same human-review-then-refer pipeline, tightened its threshold after the Tumbler Ridge shooting, and was sued by British Columbia on September 21 for not calling police earlier.
- For builders: the reporting clause lives in the consumer terms, not the commercial ones, but hosted models are monitored either way. If privacy is the product, the model runs locally.
Sources: WINK News, TechSpot, Decrypt, Tom's Hardware, Florida Statute 836.10, San Francisco Standard, News 4 San Antonio, Anthropic Consumer Terms, Anthropic Privacy Policy, Anthropic Commercial Terms, Anthropic government requests policy, Anthropic Transparency Hub, Futurism on OpenAI's policy, Virginia Lawyers Weekly, CP24, CFJC Today, Hacker News discussion