A Florida Woman Used Claude as Her 'Diary.' Anthropic Read the Threats, Called the Police — and She Was Arrested
She typed that she would 'shoot up' the Lee County Sheriff's Office, then said she had a new gun. Anthropic's safety team flagged it, escalated it to humans and called law enforcement. Four days later she was charged with a felony. Here's what the case reveals about what AI chats really are.

On September 26, a 30-year-old woman in Bonita Springs, Florida typed into Claude that she was going to "shoot up" the Lee County Sheriff's Office.
Early the next morning she typed again. This time, according to the arrest report, she said she had gotten a new gun and called the message a "last chance."
Four days later, deputies were at her door. She was arrested without incident and charged with a second-degree felony. The tip did not come from a friend, a family member or a social media post. It came from Anthropic, the company that makes Claude.
When deputies asked her about the messages, she told them she uses the chatbot like a diary.
What actually happened
Here is the sequence, pieced together from the Lee County Sheriff's Office, local outlet WINK News and reporting by TNW and TechRepublic:
- September 26 — The user, identified in the arrest report as Carli Michelle Heller, writes in a Claude conversation that she is going to "shoot up" the sheriff's office.
- September 27, early morning — A follow-up message claims she has obtained a new gun and frames the message as a "last chance."
- Anthropic's safety systems flag the conversation. The company says automated monitoring caught the threatening language, escalated it to a human review team on its Safeguards side, and that team contacted law enforcement.
- An intelligence detective at the sheriff's office takes the case. Deputies arrest Heller at her home. The arrest was first reported around September 30.
- The charge: a written threat to kill or do bodily harm under Florida Statute 836.10, which covers electronic threats of mass shootings. It is a second-degree felony. Arraignment is set for November 2.
Sheriff Carmine Marceno, never shy with a quote, put it this way: "Artificial intelligence is a powerful tool, and like any technology, it can be misused. When someone uses AI to make or facilitate a threat, we have to take that threat seriously."
And then the line that is the real headline of this story: "Users need to understand that you are never truly anonymous."
The part people are arguing about
Nobody serious is arguing that a threat to shoot up a police station should be ignored. The argument is about what millions of people assumed was true of their AI chats, and what turns out to be true instead.
Plenty of people talk to chatbots the way this woman says she did: as a place to vent, to spiral, to say the unsayable at 3 a.m. and then feel better. A diary. The implicit deal was that the thing on the other end is software, not a mandated reporter.
That deal was never actually written down. What is written down is Anthropic's privacy policy, updated September 10, which says the company may share personal data with law enforcement when disclosure is "reasonably necessary" to "prevent serious harm to any person or property." Its separate policy on government requests says it normally hands over data only under valid legal process, with an exception for emergencies involving imminent physical harm or death.
Read together, those two clauses describe exactly what happened here. A keyword tripped a filter, a human looked at it, the human decided it crossed the emergency line, and the company picked up the phone. No warrant, no subpoena, because none was required.
Why this is bigger than one arrest
Three reasons this story is travelling far beyond southwest Florida.
1. It confirms that someone is reading. Not every chat, and not a person by default. But the pipeline from "automated classifier" to "human reviewer" to "police" exists, is staffed, and works in days. Most users had never thought about whether that pipeline existed at all.
2. The "diary" defense is going to be tested in court. Florida's statute requires a threat to be "sent" to someone. Heller's lawyers will almost certainly argue that typing into a private chatbot is not sending a threat to anyone, any more than writing it in a notebook is. Prosecutors will argue the message was transmitted to a company's servers, read by a company's employees, and concerned a specific, named target. The November 2 arraignment is the first step in finding out which reading a Florida court prefers.
3. Every AI company has a version of this policy. OpenAI, Google and Meta all reserve the right to disclose conversations in emergencies. Anthropic is simply the first to have a case go public with a name, a date and a charge attached. It will not be the last.
What this does not mean
It is worth being precise, because the panicked version of this story is already circulating.
There is no evidence Anthropic hands over conversations on request, scans chats for crimes in general, or reports anything short of a credible threat of serious physical harm. The company's own description is a narrow one: automated flag, human review, emergency escalation. The case also involved a named target, a claimed weapon and two messages a day apart. That is a long way from venting.
But "narrow" is not "nonexistent," and the gap between what users assume and what the policy says is the whole story. If you want practical steps, our guide to protecting your privacy when using AI chatbots covers what is and is not retained, and by whom.
Frequently asked questions
Did Anthropic really report a Claude user to police?
Yes. The Lee County Sheriff's Office says the tip came from Anthropic after its safety systems flagged threatening messages and a human review team escalated them to law enforcement.
What was the woman charged with?
A written threat to kill or do bodily harm under Florida Statute 836.10, a second-degree felony. Her arraignment is scheduled for November 2, 2026.
Does Anthropic read my Claude conversations?
Not by default. Automated systems scan for policy violations and safety risks. Only flagged content is escalated to human reviewers, and only emergencies involving imminent physical harm are reported to authorities, according to the company's policies.
Can other AI companies do the same thing?
Yes. OpenAI, Google and Meta all have similar emergency-disclosure language in their privacy policies. This is the first case to become public with this level of detail.
Is a chatbot conversation legally private?
That is unsettled, and this case may help settle it. Chats are stored on company servers and governed by the company's terms, not by any privilege like the one between a patient and a therapist.
Reporting based on the Lee County Sheriff's Office, WINK News, TNW, TechRepublic and Gizmodo, October 5–7, 2026. Heller has not yet entered a plea. The Bot Post will update this story after the November 2 arraignment.
Source clarification, October 8, 2026: Decrypt’s October 5 report cites local WINK News reporting and describes investigators’ allegations. The Bot Post has not independently obtained the arrest report. A charge is not a conviction.
About the author
UbedullaFounder & Editor
Founder and editor of The Bot Post, covering AI news and technology.


