AI safety systems can detect user threats in chatbot conversations, leading to law enforcement notification, with policies varying by company and user data retention dependent on flagging for policy violations, creating a privacy paradox as AI interactions become more natural

AI safety systems can detect user threats in chatbot conversations, leading to law enforcement notification, with policies varying by company and user data retention dependent on flagging for policy violations, creating a privacy paradox as AI interactions become more natural

AI safety systems can detect user threats in chatbot conversations, leading to law enforcement notification, with policies varying by company and user data retention dependent on flagging for policy violations, creating a privacy paradox as AI interactions become more natural

Carli Michelle Heller, 30, of Bonita Springs, Florida, was arrested after messages she allegedly sent through Anthropic's Claude were flagged by the company's safety systems. According to investigators, she wrote that she was going to "shoot up" the Lee County Sheriff's Office. The conversation did not remain private, leading to her arrest.

Flagged chats go to human reviewers, who decide whether to notify law enforcement. Deleted chats can still be retained if flagged: up to two years for inputs and outputs, up to seven years for classification scores.

Heller wrote on September 26 that she was going to attack the sheriff's office. The following day, she allegedly wrote that she had obtained a new gun. The messages were escalated to a human review team, which then notified law enforcement.

The case raises a pertinent question as people use chatbots for far more than search: What actually happens when you tell an AI you are planning a crime?

The chatbot is not simply "reading" your diary

The first distinction is between the AI model and the safety systems around it. According to Anthropic, Claude uses a combination of automated systems and human review to detect harmful activity. Its safety architecture includes classifiers, specialised machine-learning systems designed to identify specific policy violations in real time. Multiple classifiers can monitor a conversation at the same time.

These systems are not trying to decide whether a person is a criminal. Their job is to identify potentially harmful activity and enforce the company's rules. That distinction matters in Heller's case. The AI did not decide she was guilty or order her arrest. The reported sequence was simpler: the conversation triggered a safety system, the material was escalated for human review, and law enforcement was notified. The human step matters because a sentence can mean different things depending on its context. Someone asking how a shooting happened in a historical event is not necessarily planning one. Someone repeatedly naming a target, describing an intended attack, and mentioning access to a weapon is a different situation. AI companies have to judge where a conversation crosses that line.

Heller's is not the first such case. In another Florida case, former Goldman Sachs analyst Darren Zhou was reported to have used ChatGPT to discuss plans to sexually assault and kill his former girlfriend. OpenAI alerted the FBI after detecting the conversations, leading to his arrest in May. Zhou later pleaded guilty and was sentenced to eight years' probation.

When does a chatbot company call the police?

There is no universal rule that every threatening sentence typed into ChatGPT, Claude, or Gemini results in a police report. Companies set their own safety and law-enforcement policies, and users should not assume identical thresholds or procedures. Anthropic's safeguards are designed to identify harmful activity, while its law-enforcement process allows authorities to request account records through formal legal channels.

OpenAI says most enforcement happens directly between the company and the user. But when a conversation indicates an imminent and credible risk of harm to others, it says it may notify law enforcement. It also says high-risk cases can undergo a more detailed investigation involving additional context and expertise. That means there are two separate questions. Can the company detect something potentially dangerous? And does it believe the danger is serious enough to involve authorities? Who decides that a threat is credible is not set by any single AI safety standard. It is decided within each company's policies, systems, and human-review processes.

What happens after a chat is flagged?

Anthropic says ordinary consumer conversations deleted from a user's history are automatically deleted from its backend within 30 days. Conversations flagged as violating its Usage Policy are treated differently. For those, Anthropic says it can retain inputs and outputs for up to two years, while trust and safety classification scores can be retained for up to seven years. Information may be kept longer where required by law or necessary to combat Usage Policy violations. Deleting a conversation from your visible history is not necessarily the same as making every associated record disappear. That does not mean every flagged conversation will be handed to the police, or that employees routinely read everyone's chats. According to Anthropic, employee access to conversations is restricted, with designated Trust & Safety personnel able to access them when necessary for safety enforcement. But once a serious safety concern is detected, a conversation can come under a different set of controls.

Why people confide in chatbots

Heller reportedly described her use of Claude as a diary. That behaviour is not unusual. Anthropic's own research has found that some users turn to Claude for emotional or interpersonal conversations. In a study of around 250,000 Claude conversations, the company identified a category of "affective" interactions involving emotional support, advice, and companionship. The significance is not that AI has become everyone's therapist. It is that the relationship between user and chatbot is changing. People tell chatbots things they may not post publicly: relationships, anxieties, work problems, personal decisions, and, sometimes, disturbing thoughts. The conversational interface encourages a sense of privacy. But a chatbot is still a commercial digital service.

What about India?

For Indian users, the legal picture is more complicated than asking whether "AI chats are private". The Digital Personal Data Protection framework provides rights around personal data but also contains provisions on processing for the prevention, detection, and investigation of offences. The government notified the DPDP Rules in November 2025 with a phased commencement schedule, so the provision applicable at a particular point needs to be checked rather than assuming the entire framework operates at once.

The Information Technology Act also contains separate provisions dealing with interception, monitoring, and decryption, while Section 69B concerns the monitoring and collection of traffic data for cybersecurity. If an AI conversation becomes evidence in an Indian criminal case, the Bharatiya Sakshya Adhiniyam, 2023 provides the framework for admitting electronic records, subject to specified conditions and certification requirements. An AI conversation is not automatically "evidence" simply because it exists. Its value would depend on how it was obtained, preserved, authenticated, and presented in a particular case.

The privacy paradox

The more natural these systems become, the more likely people are to treat them as private spaces. But the more powerful their safety mechanisms become, the less accurate it is to think of those conversations as completely private. That does not mean every uncomfortable thing you type will be reported to the police. It does mean users should understand the difference between a conversation that feels private and one that is legally or technically confidential.

Heller's case began with someone talking to a chatbot as though she were writing in a diary. It ended with the conversation becoming part of a law-enforcement investigation. As AI moves into roles once held by search engines, advisers, and confidants, the question may no longer be only what a chatbot can tell us. It may also be what happens to what we tell the chatbot.