The Florida and Tumbler Ridge cases raise difficult questions about privacy, emergency disclosures and who should decide when an AI platform alerts law enforcement.

☕ ChatGPT called the FBI: who decides when to report you?

⏱ Estimated reading time: 5 minutes

A person opens ChatGPT late at night.

The conversation begins with a breakup. Then come threats, weapons and, finally, a plan to murder an ex-girlfriend.

According to press reports, this happened with Darren Shida Zhou, a 25-year-old man in Florida. OpenAI provided information to the FBI; local authorities opened an investigation, and Zhou received eight years of probation after pleading guilty to charges related to threats against his former partner.

At first glance, this looks like successful prevention. But the real debate begins afterward.

The question is not whether OpenAI acted correctly

It probably did. If a company identifies a concrete, credible and potentially lethal threat, it is difficult to argue that it should simply look the other way.

The problem is who decides when a threat crosses the line.

In the United States, federal law allows certain providers to disclose communications to authorities when they believe in good faith that an emergency involving danger of death or serious physical injury requires disclosure without delay. This is an emergency disclosure authority, not a specific nationwide rule requiring chatbots to report every threat.

The law permits action. The company decides when to act. That distinction is enormous.

Tumbler Ridge shows the opposite risk

Months before the Zhou case, OpenAI had detected violent conversations involving a user in Canada. His account was blocked. The company considered alerting authorities but concluded that the risk did not meet its threshold for imminence and credibility.

Seven months later, that user killed eight people in Tumbler Ridge, British Columbia. The case is under investigation and has led to litigation. OpenAI later acknowledged that, under updated criteria, the case would probably have been referred to authorities.

Two users. Two private decisions. Two radically different outcomes. That is the real dilemma.

The striking legal insight

OpenAI may be becoming something we never imagined: a private filter positioned before the police.

An algorithm detects. A human team assesses. A private company decides. Only then does the State appear.

The platform does not arrest or convict anyone, but it can activate the machinery that does. That is power.

Your chats are not protected by attorney-client privilege

There is also a dangerous misconception.

Many people talk to ChatGPT as they would talk to a lawyer, doctor, therapist or friend. Legally, those relationships are not the same.

A conversation with a commercial chatbot does not automatically carry professional confidentiality or legal privilege. Any protection depends on the context, the professional relationship and the applicable rules; it does not arise merely because someone uses an AI tool.

An AI platform may therefore store confessions, business secrets, family problems, fraud, threats, intimate thoughts or illegal conduct. AI is becoming one of the largest repositories of private disclosures of our time.

A fragmented regulatory landscape

The United States does not have one uniform chatbot regime. By June 2026, several states had enacted rules addressing conversational AI, transparency, minors, self-harm and safety. Yet there was still no uniform national standard defining when an AI system must report threats against third parties.

The same conversation may therefore produce different consequences depending on the state, platform, type of threat and internal company policy. For AI companies, this will be a major compliance challenge.

The risk runs in both directions

If a platform reports too much, it may undermine privacy, create false positives or involve police unnecessarily. If it reports too little, it may face criticism for failing to warn about a threat.

Tumbler Ridge has already opened that judicial and regulatory debate. Platforms may be questioned both for speaking and for remaining silent.

My position

I do not believe the solution is to prohibit AI systems from reporting threats. Nor should private companies have absolute discretion. We need three things:

1. A clear legal threshold. What elements turn a disturbing conversation into a genuine threat?

2. Mandatory human review. An automated decision should never be enough on its own.

3. External oversight. Criteria that can transform a private conversation into a police alert should not exist solely inside a corporate policy.

If you remember only one idea

We built machines to which millions of people tell almost everything. Then we installed systems capable of detecting danger. Finally, we allowed a company to decide when a conversation should reach the police.

Sometimes that decision may save a life. Other times, it may come too late.

The right question is not whether ChatGPT should call the FBI. It is: who should decide when it does, and who watches the decision-maker?

☕ This coffee is served.

Would you accept an AI system analyzing your private conversations if doing so could prevent a murder?

Sources