A Florida woman reportedly used Claude like a private diary until an alleged threat triggered Anthropic’s safety systems and eventually reached law enforcement.
Carli Michelle Heller, 30, was arrested after messages allegedly described plans to attack the Lee County Sheriff’s Office. According to local reports, Anthropic’s systems flagged the conversation, human reviewers examined it, and the company then alerted authorities.
The case offers a rare look at what can happen when a chatbot conversation crosses from automated safety monitoring into a real-world emergency response.
How the events unfolded
According to WINK News, citing the arrest report, Heller wrote on Sept. 26 that she was going to “shoot up” the Lee County Sheriff’s Office.
Gulf Coast Now reported that the first message was sent at 5:10 AM. The following day, she reportedly told Claude that she had obtained a new gun. The second message was registered by 1:07 AM and apparently, in combination with the first, triggered the AI safety systems.
Heller later told authorities that she used Claude like a “diary.” Yet Anthropic’s safeguards still flagged the message because the user’s specific use of the tool doesn’t override the systems AI providers include in their tools.
Anthropic says it generally requires valid legal process before disclosing user information to government authorities. Its policies also allow the company to share information proactively when it believes an emergency involving imminent physical harm or death may be prevented by doing so.
That notification set off the police response, which has led to Heller being detained. Heller is to be charged with making a written threat of violence, which is a second-degree felony under Florida law. She’d be due for court in November.
Another case of AI flagging conversations
AI companies have faced growing scrutiny over how their chatbots respond when users discuss dangerous behavior, with critics pointing to cases where systems have allegedly failed to intervene or have continued conversations that should have triggered stronger safeguards.
The Heller case shows the opposite side of that debate: Anthropic’s systems reportedly flagged the conversation, escalated it to human reviewers, and ultimately alerted law enforcement.
And it is not an isolated case. Tom’s Hardware reports that Heller’s arrest is at least the third recent incident in which a Claude conversation reached police. In August, a San Antonio man was arrested after an Anthropic chat allegedly involved discussion of shooting at a nearby elementary school. Another Claude user in San Francisco allegedly threatened Anthropic CEO Dario Amodei and said he had purchased an AR-15.
Anthropic isn’t alone in this either. Tom’s Hardware reports that in March, OpenAI alerted the FBI over a Florida ChatGPT conversation in which a user allegedly discussed killing his ex-girlfriend.
More must-read AI coverage
- SS&C Intralinks DealCentre AI vs. Datasite: Which platform is built for the future of dealmaking?
- SS&C Intralinks FundCentre AI vs. Juniper Square: Which platform better supports modern private markets fund managers?
- Why Data, Not Models, Determines AI Success
- The Rise of the AI-Native Factory: How Physical AI Is Transforming Manufacturing
What this means for chatbot privacy
AI chats may feel private because users interact with them alone, but the companies operating those services still process the conversation.
Users should also think carefully about what they do when they are angry or distressed. Using an AI chatbot to turn that anger into a plan for harming another person can move a situation from an emotional outburst toward conduct with real legal consequences.
Seeking help, contacting someone who can mediate the dispute, or stepping away from the situation is a much safer route.
There is also a separate lesson about privacy. AI chatbots may feel more private because users interact with them alone through a screen, but the company operating the service still processes the conversation.
Once users enter sensitive information, they are no longer the only party with access to it, and depending on the provider’s policies and the circumstances, the information may be reviewed, retained, or disclosed.
The broader lesson is that AI chats can feel private without being fully confidential. When safety systems detect what providers consider an imminent threat, a conversation may move from automated moderation to human review and, in rare cases, law enforcement.
You can check this guide on what you should never enter into a chatbot if you are unsure of what your conversation with any AI chatbot should look like.
Other news: OpenAI CEO Sam Altman says society should accept some bounded AI harms to preserve the technology’s broader benefits and accessibility, while drawing the line at potentially catastrophic risks.