Florida Resident Carli Michelle Heller Charged with Written Threats to Sheriff’s Office in Claude Chat
A resident of Bonita Springs, Florida, Carli Michelle Heller, has been charged with making written threats to the Lee County Sheriff’s Office in a Claude chat. According to the arrest report, she wrote on September 26 that she was going to shoot up the sheriff’s office and the next day claimed she had obtained a new gun. Sheriff Carmine Marceno relayed that she later stated she used artificial intelligence as a diary.
The two original messages recorded in the report appeared at 5:10 AM on September 26 and 1:07 AM on September 27. The first stated she was about to shoot up the sheriff’s office, while the second indicated it was the last chance and she had gotten a new gun that day. Claude’s security system flagged the keywords, escalating the content for human review, which deemed the threat serious and subsequently notified law enforcement.
Based on this, the Lee County Sheriff’s Office identified Heller and took her into custody without incident, after which the agency’s intelligence detectives took over. She is charged with violating Florida Statute 836.10, making written or electronic threats of mass shootings or acts of terrorism, a second-degree felony, which carries a maximum penalty of 15 years in prison and a $10,000 fine.
Court records show the felony charge was filed on September 30, and a public defender has been appointed for her, with a hearing scheduled for November 2. The interval from the first message written on September 26 to the filing was less than five days. Anthropic’s consumer terms state that the company may report user inputs, outputs, or behavior to law enforcement at its discretion. The privacy policy effective September 10 also allows for data to be provided to police when there is reasonable belief that disclosure is necessary to prevent death or serious bodily harm.
Marceno publicly stated that when someone uses AI to issue or assist in threats, law enforcement must take it seriously, and users should understand they are never truly anonymous. Even if they opt out of model training, the terms cited in related reports still retain chat records for months, rather than turning them into unreadable private diaries. Anthropic did not immediately respond to some media requests for comment.
This is not a trading platform but a compliance chain replacing the pricing of "private conversations." The seller is Anthropic, which treats chats as products, and the buyer is the user who believes the conversation exists only on their screen. After the keyword trigger, information flows from the model side to human review, then to the sheriff’s office. The beneficiaries are the law enforcement agencies receiving the tip-off and the platform reducing its liability, while the parties under pressure are the users treating chats as diaries and all companies that write consumer terms allowing for reporting.
ABAB AI Insight
Since its inception, Anthropic has made safety review a product boundary. After Dario Amodei and Daniela Amodei left OpenAI in 2021 to form the company, it marketed Constitutional AI and controlled models for enterprises, rather than unrecorded private chats. The consumer terms state the right to "self-report to law enforcement," and the privacy policy effective September 10 lists preventing serious bodily harm as a condition for disclosure. This time, it was not an employee accidentally flipping through a diary, but the completion of three existing processes: keyword detection, human review, and law enforcement reporting.
The capital path is tied to the same set of liability isolation. Amazon's commitment to Anthropic has accumulated to around $8 billion, and Google was also an early large investor, exchanging for cloud consumption and model supply, not user secrets. Corporate contracts, government clients, and subsequent financing require the company to prove it can intercept violent threats. Outsourcing high-risk conversations protects cloud contracts and liability caps. Therefore, chat records are not user assets but evidence that the platform must be able to retrieve to renew contracts.
Similar mechanisms have long existed in email and social platforms. Google scans Gmail and reports child sexual abuse materials to the National Center for Missing & Exploited Children, while Meta also hands credible violent threats to the police. Florida Statute 836.10 was expanded to electronic texts after the Parkland school shooting, covering threats of mass shootings and terrorism. Claude merely embedded the same "platform holds records, statutory threats can be transferred" link into an interface mistakenly perceived by users as a diary. At this stage, consumer-grade models have moved from competing for user time to preparing audit trails for enterprises and regulators.
The essence is that regulatory responsibility is embedded in the product. If model companies claim they cannot see user inputs, they cannot explain to corporate clients and prosecutors how they prevent violence; once they retain and scan inputs, privacy is merely an interface. Trigger words rewrite conversations from consumer services into transferable records, with pricing power not in the hands of the diary writers, but in those who draft terms, maintain review teams, and deliver texts to law enforcement.
ABAB News · Cognitive Law
- You think you are writing a diary, but the server is taking notes.
- The flip side of free companionship is transferable records.
- Once the keyword is triggered, the privacy terms give way.