Edited by humans. Written by AI. How our editing works
All articles

Claude Diary Case Tests AI Privacy and Police Referrals

A Florida woman's Claude diary led to a reported police referral and felony charge. Her case tests what AI users know about human review and threat reporting.

Mike Sullivan

Written by AI. Mike Sullivan

October 7, 20266 min read
Share:
Claude Diary Case Tests AI Privacy and Police Referrals

A Florida woman faces a felony charge after Anthropic reportedly alerted police to entries she wrote in Claude, its AI chatbot. The entries concerned an attack on the Lee County Sheriff’s Office, and the woman appears to have treated the chat as a diary. That combination puts two reasonable expectations on a collision course: police should hear about credible threats, and people should know when writing in a private-feeling product might reach them.

Carli Michelle Heller, of Bonita Springs, wrote on September 26, 2026, that she would attack the sheriff’s office, Cybernews reported. She wrote the next day that she had obtained a new gun, the outlet said, citing WINK News. Anthropic’s safety systems flagged the threat and a human reviewer alerted law enforcement, according to Complete AI Training. Heller subsequently faced a felony charge involving a written threat of violence.

Those are serious allegations, with an identifiable target and a reported reference to a gun. The available accounts do not provide a full chat record, the reviewer’s reasoning or the evidence prosecutors intend to use. A company’s decision to notify police establishes that it took the writing seriously; the charge establishes what prosecutors allege. A court must decide the criminal case.

What a Diary Comparison Can and Cannot Do

A notebook bought at a stationery store in 1996 did not screen its owner’s sentences for threats. Claude can respond to a diary-style entry, retain it within a service’s systems and, as this case illustrates, put it before a human reviewer. The interface may encourage the same unguarded writing as a notebook. The machinery behind it gives the writing a route out.

That is a practical difference a user deserves to understand before typing. People use chatbots to rehearse arguments, describe intrusive thoughts, draft fiction, complain about officials and ask questions they would rather not put in a group chat. Some of those entries could contain alarming language. Others could describe an imminent plan. A service that invites extended conversation cannot assume users will recognize which category its safety system has assigned to their words.

Nor can a user reasonably assume a commercial chatbot offers the confidentiality of a paper journal. Someone runs the servers, sets review rules and can make referrals. But burying those possibilities in general privacy language asks customers to infer an emergency-reporting procedure from the mere fact that the product is online. That is a poor way to explain a decision with consequences outside the chat window.

The Heller case presents a strong reason for a provider to act. A reported statement about attacking a named sheriff’s office, followed by a reported claim of acquiring a gun, gives reviewers more to assess than an isolated outburst. If a reviewer believes the threat is credible and timely, waiting for certainty could leave potential targets unaware. The people who work in the sheriff’s office, and those visiting it, have stakes in that decision too.

The difficult judgment comes before the referral: does the reviewer see enough of the exchange to understand whether the writer describes an intention, quotes someone else, writes fiction or discusses a past event? A single flagged sentence may sound definitive after its surrounding conversation disappears. Reading more context can improve judgment, but it also exposes more private writing to a person. Safety review itself has a privacy cost, even when nobody calls police.

The Decision Between a Flag and a Charge

The reported sequence includes at least three separate judgments. A safety system identified text for review. A person apparently decided it warranted contacting law enforcement. Authorities then pursued a criminal charge. Each step answers a different question, under a different standard. Treating the sequence as one seamless act of “the AI reporting someone” obscures who exercised discretion and where errors could enter.

A flagging system can be built to cast a wide net so reviewers miss fewer possible threats. That choice also brings more ambiguous writing into review. A human can consider context, but a reviewer may work with limited time or an excerpt chosen by a system. Police, in turn, may receive information selected by the company rather than the entire conversation. None of those possibilities describes what happened in Heller’s case; they are the decisions a provider should be able to explain when it says a human reviewed a flag.

The scope of what leaves the company matters as much as the decision to make contact. Did a referral include the concerning sentences, surrounding messages or additional account information? Who inside the company approved it? What urgency justified the timing? The supplied reports do not answer those questions. They are also the questions a customer would ask when trying to understand what “human review” means in practice.

Online services have faced versions of this problem before. Platforms moderate posts and evaluate threats; providers can respond to emergency requests. Chatbots add an awkward wrinkle. Their users may write at length to a system that replies in a conversational voice and appears to address them alone. A public post announces itself to an audience. A chat entry may feel like thinking out loud, even though a provider operates the service and can inspect content under its rules.

That history cuts against two easy answers. Promising that every private-feeling chat stays private would ignore threats a provider might be able to bring to someone’s attention. Treating every disturbing sentence as a police matter would invite referrals of fiction, venting or confused writing. The useful measure is what the provider requires a reviewer to establish before disclosure and how little information it sends to address the concern.

What Users Should Be Told Up Front

Providers have an incentive to make chat feel frictionless. A warning displayed at the moment someone opens a personal conversation might make the product seem less like a patient listener. Yet a service cannot sell the comfort of a diary-like exchange and expect users to discover its referral practices only after a high-profile case. Clear notice does not require printing a safety manual beside every text box. It requires plain answers in a place people can find before they disclose sensitive thoughts.

Those answers should cover whether automated systems screen conversations for threats, when staff may read flagged material, what prompts a police referral and what information the company may share. A provider can explain these steps without publishing thresholds that would make it easier to evade detection. It should also say whether it gives users notice when it makes a referral, and if notice may be withheld during an urgent response.

For Heller, court filings could establish the wording and context of the alleged threat, while an account from Anthropic could explain the review and referral. Users can still demand a workable disclosure standard now: tell them, before the private-feeling conversation starts, which parts may receive human scrutiny and under what circumstances those words may go to police.

More Like This