Reverse the situation and the media would also turn that into outrage. Imagine someone shoots up a sheriff's office and then it turns out they declared it to some chatbot, and the AI company failed to detect and report it, and "didn't push back enough" whatever that would mean, and hence the AI was implicitly complicit etc. That would also be a major PR catastrophe.
Damned if you do, damned if you don't. Same as with social media platforms. That's because only a tiny tiny sliver is for true privacy when that means "bad things might happen" or bad people, such as your political enemies, may do stuff you don't want.
I have some sympathy for Anthropic here because I've seen the headlines after OpenAI failed to report a shooter in a similar situation. So from their perspective, it's damned-if-you-don't, damned-if-you-do.
However, people need to get it in their heads that they're not chatting with their secret BFF, they're chatting with Big Tech. Before LLMs, Big Tech had no way to scrutinize the bulk of what was going on within their services, so you could have a secret hate diary in Google Docs. Now, everything you say or write can be automatically screened for red flags on a planetary scale, and probably will be because that's what the regulators and "concerned citizens" will demand. In a couple of years, you'll be biting your tongue a lot more often in private chats.
> Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism. The communication must be made in a manner in which another person may view it.
I think Anthropic did the right thing here; but the sheriff's office are probably demonstrating why she dislikes them. Writing a diary entry to a chatbot is clearly not how this law was intended to be used.
EDIT: Actually, on reflection, making this report to the people she was upset about was probably not the right call. If they'd sent it to the FBI, there'd be a much lower chance that someone felt the need to assert their "authority".
How can you charge someone for making a threat when you only read the threat by spying on them? Surely that has to be thrown out in court? They didn’t actually send the threat to anyone, you just obtained it by spying.
“But there can be no valid knowledge about the future. As soon as precognitive information is obtained, it cancels itself out. The assertion that this man will commit a future crime is paradoxical. The very act of possessing this data renders it spurious. In every case, without exception, the report of the three police precogs has invalidated their own data. If no arrests had been made, there would still have been no crimes committed.”
Philip K. Dick, Minority Report, 1955
While I accept that this sort of thing is well with in the ToS and regular course of business of any major online platform, it hits different coming from an AI company for some reason.
I have told llms all kinds of stories to find out what its answers would be. I always make it sound like it is the truth to make sure the AI answers in a way that it would if somebody actually said this. I also tested internal flagging systems of the ai company I work at with the most evil things a person can ever say to find out if it would flag them.
Of course I did not mean any of that stuff, but how can you make sure a human reviewer knows you did not mean it while the llm does not know that you did not mean it.
I guess its a miracle I am not in jail yet.
Flagging people for anything said to an llm sounds wrong to me because an LLM is not a real person and while some people put in their internal thoughts, others just roleplay and the two are inseparable just from reading it.
Tech companies have always done this. Don’t misread that as blanket support for it, but consider Anthropic’s position here. Do they want a headline to come out that says “woman used Claude to plan murder” or “Anthropic reported potentially dangerous person to the police”? AI being dangerous is already a hot topic, and this seems like a sensible move to me. If you want a guarantee of privacy, you’ll need to run your own models locally.
I don't understand how she violated this law:
> Heller faces a charge of making a written threat of violence under Florida law. Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism.
She didn't threaten anything, she wrote down that she was going to do it. A "threat" is more than a mere statement, especially when written in what is described as a "diary".
> A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to "shoot up" the Sheriff's office.
Obviously I don't want anyone to shoot up anything, but this seems like a weak case legally speaking.
The law seems overly broad with "may be viewed by another person". Most of these laws have the intent of not causing public panic with regards to posts that others may see, not stuff that one assumed was private. This is further supported by the definition of threat, which is generally defined as requiring malicious intent.
I would think a good lawyer could get this charge dropped. I would like to see what judge approved the warrant and how they felt the elements were met.
I have a hunch she wins the case, on the basis that an LLM isn't a person and an (assumed) private expression of anger to a machine assistant doesn't meet the statutory threashold which requires that a threat be communicated to some other person.
Of course, that could change if there's evidence that she took action in pursuit of a goal, like buying ammunition or repeatedly driving around the entrance to her alleged target.
This is a classic case of "Damned if they did, Damned if they didn't". Given this has come out, and Anthropic is considered to be the beacon of transparency, it would be appropriate for them to share what their thresholds are. The article also reports Open AI not considering the threat credible enough to alert, so there's clearly some thresholding that people need to be aware of.
Anthropic commits literal felonies by stealing millions of books and violating Copyright like it doesn't exist: no charge.
One unfortunate woman who happened to write the wrong thing in the wrong place is now having her life turned upside-down for perceived thought-crime.
To Anthropic, and all employees working there, your company's product and the result of your work is cruelty. You are enabling it and pushing it down everyone's throat. You can never again claim that you are the "ethical" AI company, for no such thing exists.
It is unlawful for any person to send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record, including an electronic record, in any manner in which it may be viewed by another person, when in such writing or record the person makes a threat to: (a) Kill or to do bodily harm to another person; or (b) Conduct a mass shooting or an act of terrorism.
— via https://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Disp...
The DA is serious about "in any matter."
Chatbot transcripts should have the same legal protection as phone calls. Judge's warrant needed to access them.
Anthropic (in discussion with Pentagon) claimed mass surveillance is their red line.
Yet, they do automated mass surveillance of their users on behalf of police.
Could this be considered free speech? Most of the limitations I know of require you to say it to or in front of other people as to create a panic or make someone feel threatened. Is it a crime to say to yourself "Im going to blow up New York." or about threats of self-harm? How about "Im going to steal the Mona Lisa!"?
To me this is just straight up thought crime, they just don't have a way to directly read your thoughts yet. But they will spy on you and try and catch you out for it.
I guess we probably want our tech to work exactly like this.
It should catch normal people becoming unstable so that they can receive help. It is just highly unfortunate that the US legal system works in ways where now this woman's name is public.
___
Of course, we also want purely private tech, but that needs a certain level of merit and sanity filter.
1791138022 | Florida woman used Claude as a diary, then Anthropic reported an entry to police | https://www.techspot.com/news/114091-florida-woman-used-clau... | https://news.ycombinator.com/item?id=49956424 | 0 comments
1791144575 | Florida woman used Claude as a diary, then Anthropic reported an entry to police | https://www.techspot.com/news/114091-florida-woman-used-clau... | https://news.ycombinator.com/item?id=49957340 | 0 comments
1791147034 | Florida woman used Claude as a diary, then Anthropic reported an entry to police | https://www.techspot.com/news/114091-florida-woman-used-clau... | https://news.ycombinator.com/item?id=49957692 | 0 comments
1791149399 | Florida woman used Claude as a diary, then Anthropic reported an entry to police | https://www.techspot.com/news/114091-florida-woman-used-clau... | https://news.ycombinator.com/item?id=49958089 | 3 comments
1791213096 | Florida woman arrested for allegedly making threats in an AI chat | https://www.theverge.com/ai-artificial-intelligence/1004747/... | https://news.ycombinator.com/item?id=49965895 | 2 comments
First I posted to the (likely dup article) https://news.ycombinator.com/item?id=49965895#49966728. Wanted to post here, after reading more.
Is this an invasion of their privacy (reporting to police)? Yes, but possibly warranted?
Should a social worker have contacted them rather than the police? Probably, if for no other reason than to ask if they were serious about harming someone.
Difficult questions, I'm still undecided on whether it's OK to always ignore someone's rants, even if it may be (or they think it may be) a private diary.
Actually charging them with a felony seems pretty quick to accuse. (Maybe I missed a hint about how long the investigation took before the felongy charge?)
Oh man, what a crazy time to be alive.
Over in Europe they want to read all ofd our private messages, yet these chatbots, pretending to be our friends, will snitch on us just for our thoughts.
It's getting pretty orwellian out there.
I guess all the "private model" people are right. Don't want to end up in jail (or even charged with something) for asking a crazy hypothetical question or something.
Should the public have an expectation of total privacy for their chats? It seems responsible for a chat provider to report things like this.
If they were to offer total privacy, is it ok for the public to use chat to get advice on _how_ to commit a crime? Basically everyone agrees that crime-committing advice is inappropriate…but if it is not ok to get advice, that means there must be a portal for law enforcement to step in when that may have happened. Then the question becomes what is the line for when to report? In other words, the issue needs to be adjudicated.
But we don’t want OpenAI/Claude to have some $20/hour reviewer making decisions that are this high stakes…we need the courts to do the judicial work because they (1) have a public charter, (2) have meaningful expertise and specialization at interpreting the law and (3) we can hold them accountable.
For the sake of argument what would happen if she had kept the diary locally and claude code scanned the file?
What would happen if it had scanned a file it didn’t have permission to look at and found this threat?
I honestly don’t know how I feel about this. On the one hand if you’re using claude as a diary you have no expectation of privacy and she was talking about committing a very serious crime.
This still makes me feel queasy though.
I can’t believe people are using these proprietary models/subscriptions as personal assistants, sending their most personal context, thoughts, documents and information to the providers. Some even give them full disk access. After using their services for long enough, Anthropic/OpenAI essentially have your entire life mapped out to an insane level of detail, likely including detailed contents of your computer/phone.
People used to say that Facebook knew more about you than your closest friends/relatives. And compared to that, this is just on a completely different level. Absolutely insane.
Not weighing in on the privacy issue but using Ollama you can run a smaller agent like Qwen 3.6 35b a3b on a sufficiently potent laptop. Pair it with something like Hermes for a nice interface and you have more than you might need for diary like usage.
If you want technology that won't report you to the police for credible threats at they can easily detect perhaps create your own. I hear pen and paper work great for this.
I expect that anything I type / dictate / post / purchase on the web be it a chat conversation with an AI, a post on social media, a dm, a blog post, a blockchain reference, or an assett in a bucket, will be manually reviewed and forwarded to the authorities. It is their duty to do so, and I am glad that they do. If this woman did harm someone we would be hearing "why didn't Anthropic do something about this."
Florida statute 836.10 puts the bar at the "sending, posting, or transmission of, a [...] record, in any manner in which it may be viewed by another person"
I think the defendant could successfully defend themselves by claiming they did not know (or intend!) the message could be viewed by another person, as they were plainly using it as a private diary.
> making a written threat of violence under Florida law.
A diary constitutes making a threat?
Oh boy the roleplaying part of LLM world is in for a bad time
In any case this is proof that law and negative PR can influence tech companies, including frontier AI providers.
Then again, I wish this worked in a way that would give users more privacy and agency, instead of less.
This is practically entrapment. All the AI labs sure don’t shy from plastering annoying disclaimers everywhere saying their tool can make mistakes. Shame on them for not also reminding everyone continually that anything you submit can and will be used against you. Of course they can’t afford to have a Flock-style user revolt.
This kind of thing will get worse with humanoid robots because they have cameras and microphones. Will they be programmed to tell on you if you break any kind of rule in front of them because their owners are terrified of being sued?
this feels very thought-crimey to me, but I think I'd have to actually see that chats to really decide. Like is she making plans/asking for advice? is she just talking about her feelings exactly as if it's a diary?
> The communication must be made in a manner in which another person may view it.
How does a LLM prompt satisfy this? I guess it'll be an easy win for her.
If it's going to be this binary. Then there has to be a shift in the way this is handled. It shouldn't be "You wrote these terrible things to a computer, you're now accused of doing them" to maybe "We where notified you wrote these terrible things, and the a psychiatric evaluation is being mandated by the state in which has a law about this sort of thing"
Obviously, as others have pointed out if they don't act and she does the crime it raises the damned if you do damned if you don't. But I've also had the AI's go haywire saying I'm doing all sorts of nefarious things when literally doing math proofs.
So no one size fits all. But going the extreme first is probably not ideal.
I hope this highlights that many (most?) non teach people don't consider or know that their use of AI services is not private.
If only the woman hosted open-weight model in her house.
Where are the people now who claimed that LLM chats are really private and not monitored?
Every single lie of yours is exposed in the past few months.
In Florida. Where DeSantis said "You loot, we shoot":
https://www.politico.com/news/2023/08/30/desantis-warns-hurr...
Knowing anthropic, im sure these keywords are hardcoded in a long list and regex get them for further reviews.
Does anyone else remember when the tech-savvy crowd was wary of software "phoning home" or spying on users, or listening, or whether Gmail scanned and read your emails, and whatnot?
And here we all are, happily typing our stuff into these spy chatbots. "AI" happily made our fears go away. Hopefully we're not planning anything criminal like this woman, but still.
After people getting pilloried for social media posts from twenty years ago, I really hope (sensible) people will have the wherewithal to think twice about what they hand over to their chatbots.
> The communication must be made in a manner in which another person may view it.
Seems to fail this test at face value.
I mean, somebody you live with may find and read your diary. Is that the same thing?
Intent matters here. Did you intend somebody else to view it? Does a reasonable person have expectation of privacy with a chatbot?
AI snitches don't get stitches.
"Assume people can see everything you post on the internet" still applies when using AI. It's not as newsworthy when you put it that way.
We are officially in the era of Thought Crimes.
Can the public also immediately get alerted when a cop or politician does some bad shit, though?
Writing in a diary is protected by the first amendment. Or at least should be.
Pool together with some friends and buy an H200 or two to run unquantized open source models with abliteration/heretic transformations.
You need to be able to use these models for the real world and not for some imaginary world where everything is safe and nice and happy all the time, while at the same time intensely surveilled in the name of CYA and the latest panic about whether speech THAT ISN'T EVEN BETWEEN TWO PARTIES is considered "wrong".
I'm a free speech fan that acknowledges there are lots of boundaries of free speech (fraud, perjury, blackmail, defamation), but the one thing that all of the boundaries have in common is that a second party must be involved for them to make any sense at all.
Maybe the courts will uphold this, maybe they won't, but don't take the risk!