A Human Read Her Claude Diary and Called the Police. Now It's a Felony.
A Florida woman who used Claude as a diary faces a felony charge after a human reviewer escalated her entry to police. Here is how that pipeline works.
On September 26, Carli Michelle Heller of Bonita Springs, Florida, allegedly wrote in Claude that she planned to "shoot up" the Sheriff's office. She later told investigators she uses the chatbot like a "diary." According to the arrest report, Claude's safety systems flagged the entry, a human reviewer judged it a credible threat, and that reviewer reported it to law enforcement. Deputies identified her, visited her home, and detained her without incident. She now faces a written-threat charge under Florida law.
How a Private Entry Reached a Detective
The source describes three stages. First, automated safety systems flagged the entry. Second, it was escalated to a human reviewer. Third, after deciding the statement was a credible threat, the reviewer reported it to police. The Lee County Sheriff's Office (LCSO) then identified Heller, and an LCSO intelligence detective took over the investigation.
The design logic is a triage funnel. Automated classifiers can scan enormous volumes of text cheaply, but they misread context: a novelist, a person venting, and a person planning harm can all produce similar words. So a flag is only a prompt for human judgment. The human step is where a flag becomes a decision, and it is the step users rarely know exists. Note what the source does not tell us: what the classifier looked for, how many reviewers examine a flagged entry, or what standard of "credible" they apply.
What the Company Says It Can Share
The source says Anthropic may share user information in limited emergencies if it believes disclosure is necessary to prevent death or serious physical injury. That is the company's stated policy, and it is a belief-based test: the reviewer needs a reasonable belief of danger, not proof. The source does not say whether Heller's account showed any other warning signs, whether she had means or a history, or what the full entry said beyond the reported phrase.
Why the Charge Is Unusual
Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism. The statute requires that the communication be made in a manner in which another person may view it.
That clause is where the interesting legal question sits. A diary is traditionally written for no one. Here, the only people who viewed the entry were the company's reviewers, and under the company's own process, someone did. Whether that satisfies the statute is something a court may have to address; the source does not say how prosecutors will argue it.
A Pattern, Not a One-Off
The source places this alongside other recent cases. British Columbia is suing OpenAI and Sam Altman over claims the company could have prevented a mass shooting in the province. The shooter had reportedly been flagged by OpenAI's safety team for conversations about gun violence, but OpenAI did not alert police because the conversations did not meet its threshold for legal referral. In June, Florida sued OpenAI and Altman, alleging ChatGPT contributed to real-world harms, including the 2025 Florida State University shooting. Separately, reports last month said human contractors reviewing Microsoft Copilot's image editor can see users' prompts, uploaded photos, and edits.
Read together, these cases push in opposite directions: one company is accused of failing to report, another reported and a user was charged. Every AI provider now faces legal and reputational pressure to lean toward escalation, and the people paying for false positives are users.
Questions You Should Be Asking
- Who can read what we type? Does your vendor's documentation say when human reviewers see conversations, and does your staff know before they paste in sensitive material?
- What is the referral threshold? If one company's bar is "credible threat" and another's is higher, who sets it, and is it published or discretionary?
- What happens after a false positive? Is there any notice, appeal, or correction when a flagged entry turns out to be venting, fiction, or a joke?
- Does your contract cover this? If your employees use a chatbot for work and a reviewer escalates something, who is told, and does your agreement say so?
- Is a diary an audience? If a human reviewer counts as someone who "may view" the text, what does that mean for every private-seeming tool you use?
What To Watch Next
Watch how the court treats the "manner in which another person may view it" element, and whether Anthropic publishes more detail on its review and referral process. If the charge survives a challenge, expect other providers to be asked the same question: at what point does a flagged conversation become a police report?
- 1Avoid writing violent statements in any digital platform, including chatbots, as safety systems and human reviewers may report credible threats to law enforcement.
- 2Understand that private conversations with AI services aren't legally private; companies can review flagged content and report threats to authorities.
- 3If you use AI chatbots for journaling sensitive thoughts, use coded language or keep truly private thoughts in offline, physical journals instead.
Ready to implement AI in your business?
Our team builds the AI systems you just read about. Start with a free 30-minute discovery meeting.
