Anthropic Reports Claude User to Police Over Diary Entry

A Florida woman faces felony charges after her Claude diary entry threatening a mass shooting was flagged by AI and sent to police.

Policy · Source: Hacker News

What happened

A Florida woman used Anthropic's Claude as a personal diary. On September 26, she wrote an entry threatening to attack the local Sheriff's office. She explicitly stated she planned to shoot up the building. Claude's automated safety systems immediately flagged the prompt. The system escalated the text to a human reviewer at Anthropic for further inspection.

The human reviewer read the prompt and determined the threat was credible. Anthropic then handed the user's data over to law enforcement. Police identified the user as Carli Michelle Heller. Deputies visited her home in Bonita Springs and detained her without incident. An intelligence detective took over the investigation. She now faces a second-degree felony charge under Florida Statute 836.10 for making a written threat of violence.

Anthropic states its policy allows sharing user data in limited emergencies to prevent death or serious physical injury. This aggressive reporting comes right after OpenAI faced massive legal backlash for doing the opposite. British Columbia recently sued OpenAI and Sam Altman for failing to report an 18-year-old user who later committed a mass shooting. Florida also sued OpenAI in June over the 2025 Florida State University shooting. Anthropic is clearly refusing to take that same risk.

Key facts

Why it matters

Trust and safety is no longer just about filtering bad outputs. It is about actively policing user inputs. If you build an AI wrapper or a consumer AI product, your users expect strict privacy. But platform providers like Anthropic and OpenAI are monitoring prompts and employing human reviewers. You are caught in the middle of this surveillance apparatus. Your users think they are writing in a private diary. Your upstream provider is acting as a proactive security network. This fundamental disconnect will destroy user trust.

The legal liability for AI companies is shifting rapidly. OpenAI got sued for not reporting a user because the chats did not meet the threshold for legal referral. Anthropic is now reporting users to avoid the exact same fate. This creates a massive chilling effect for consumer AI applications. Users will stop trusting AI with sensitive personal data if they know human reviewers are reading it. Builders will need to decide between using hosted models with strict surveillance or hosting open-source models to guarantee real user privacy.

For builders

Zero privacy in hosted AI models

Do not market your AI applications as completely private if you rely on Anthropic or OpenAI APIs. Human reviewers can and will read flagged prompts. If you promise absolute privacy, you will face severe backlash when your provider leaks user data to the police.

Legal liability forces aggressive moderation

Major AI companies are terrified of being sued for real-world violence. They will over-index on reporting users to law enforcement to protect themselves. Expect higher false positive rates and more aggressive API bans for your users as safety filters tighten.

Opportunity for local and open models

Consumer trust in cloud AI is dropping fast. This creates a massive market opportunity for local AI and self-hosted open-source models. Builders who can guarantee absolute privacy by running models entirely on-device will win users who refuse to be monitored.

My take

I warn founders about this constantly. You cannot build a sustainable business on the assumption that OpenAI or Anthropic will protect your users. If you want real privacy and control, you have to host the models yourself.

Original reporting: Hacker News. This is my rewrite and opinion.

More AI news for builders