Skip to content
NewsIncident

Anthropic's emergency-disclosure policy sent a Claude user's threatening message to police

· by Pondero Newsdesk

The short version

Treating a chatbot like a private diary assumes a privilege Anthropic's policy does not grant: under its emergency-disclosure terms, Claude's safety reviewers can and did hand a threatening message to police, leading to a Florida felony arrest.

Anthropic's emergency-disclosure policy sent a Claude user's threatening message to police

Anyone who treats a chatbot like a private diary is relying on a privacy assumption that Anthropic's own policy does not support. Under its emergency-disclosure terms, Claude's safety reviewers can, and in one case did, hand a user's threatening message straight to police, leading to a felony arrest in Florida.

What triggered the escalation

Carli Michelle Heller, 30, of Bonita Springs wrote in Claude on September 26 that she planned to "shoot up" the Lee County Sheriff's Office, language specific and targeted enough at a law-enforcement agency to trip Claude's automated safety filters, according to Tampa Free Press. The system escalated the entry to a human reviewer at Anthropic, who judged it a credible threat and alerted law enforcement, consistent with Anthropic's stated policy of sharing user information "in limited emergencies if it believes disclosure is necessary to prevent death or serious physical injury," per TechSpot's report. Lee County deputies arrested Heller at her home without incident and charged her under Florida Statute 836.10, a second-degree felony covering written threats of violence, according to the AI incident database entry citing the arrest report. She sent a follow-up message the next day referencing a firearm, per Tampa Free Press; a court date is set for November 2026.

AI chat logs carry no chatbot-client privilege

Anthropic's terms state plainly that conversing with Claude is not protected the way a conversation with a lawyer or a doctor would be, per Tampa Free Press. The emergency-disclosure threshold turned out to cover text typed into a chat window during what the user described as private journaling, not only a phone call or an in-person warning. Lee County Sheriff Carmine Marceno said users are "never truly anonymous" when using AI, per the incident database entry. Anthropic declined to comment on the specific case, per the same report.

What to watch next

Whether Anthropic publishes any transparency reporting on how often this disclosure path fires, since the company has not said how many conversations get escalated to human reviewers or how many of those reach police. The November court date will also test where the line falls between a credible threat and venting in a chat log a user believed was private.

Sources