A Florida woman called Claude her diary. Anthropic's monitors called the police
A Florida woman called Claude her diary. Anthropic's monitors flagged the messages, a human signed off, and police made a felony arrest. The gap is policy.

Carli Michelle Heller, 30, of Bonita Springs, Florida, is facing a second-degree felony after messages she wrote to Anthropic's Claude were flagged by the company's automated safety monitors and passed to a human review team, which reported them to the Lee County Sheriff's Office. Deputies took her into custody at her home without incident. Sheriff Carmine Marceno told WINK News that Heller explained she uses Claude like a "diary."
That detail is the story, and it is not that a chatbot went to the police. It is that a user treated a general-purpose AI service as a private confessional while the company's own published policy never promised her one.
What the arrest report says
The arrest report, first relayed by local outlets and picked up by Gizmodo, describes two messages. On September 26 at 5:10 AM the user allegedly wrote:
"I'm going to shoot up the sheriff's right the [expletive] now."
A follow-up arrived the next morning, September 27 at 1:07 AM:
"This is 100% last chance I'm done. I got a new [expletive] gun today. [Expletive] you."
Investigators wrote that Anthropic's platform uses safety and security measures to monitor for key phrases and potentially threatening content, and that because of the severity of the statements the information was escalated to a human review team, which then reported the messages to law enforcement. Heller was charged with written threats of violence, a second-degree felony in Florida under Fla. Stat. 836.10 that carries up to 15 years in prison and up to a $10,000 fine. WINK News reports she has a court date in November.
What Anthropic's policy actually says
Anthropic's published position on government requests is narrower and more conditional than a user might assume. The company's own support documentation states that it "does not disclose information about customers or end users of our services in response to government requests except in accordance with valid legal process," and then names the exception it applies: "if we believe there is an emergency that may result in imminent physical harm or death, and providing such information without delay may avert that emergency." The same page adds that Anthropic will normally give users notice when their data is requested, unless it believes it is legally barred or a rare exception applies.
The company did not respond to Gizmodo's request for comment, and did not tell WINK News how its safeguards treat threats or when data is shared. Nothing in the policy is unusual among technology companies. Reporting threats of violence, child sexual abuse material and self-harm intent to law enforcement is standard practice across the industry. The emergency carve-out is what makes a referral like this possible without a subpoena, and it is written broadly enough to cover a judgment call rather than a fixed test.
The gap between a diary and a database
Two people WINK News interviewed put the mismatch plainly. Ian Marlow, chief executive of FITECH, said the conversational feel of an AI chat leads people to read it as private: "Something that feels that it is conversational in nature doesn't immediately feel like, 'Oh, this is something that is being recorded,' because they're just having a conversation." Dr. Chrissann Ruehle, an assistant professor of AI and management at Florida Gulf Coast University, described the same pull, the sense that a machine will not judge you, and added the correction: "AI is not your best friend. We need to keep in mind this is a technology."
Marceno's summary was blunter. Users, he said, are "never truly anonymous" when they use AI chat or search, and he framed the referral as ordinary police work: "AI may be changing the way threats are created, but our commitment to protecting the people of Lee County has not changed."
This is not the first case
Tom's Hardware notes this is at least the third Claude conversation to reach police since August 2026, which makes the Florida arrest less an aberration than a pattern: automated triage, human sign-off, a call to local law enforcement. The mechanics repeat every time. A model is tuned to surface messages that look like credible threats, a person decides whether the signal clears the bar, and the company hands the result to police. Anthropic has built that monitoring machinery deliberately, and its own threat-intelligence reporting, covered here in September, shows how far the company will go in describing what it catches. What changes case to case is how clear the threat looks and whether the user believed, as Heller reportedly did, that they were writing for no one.
What the case does not establish
The public record here is thin, and most of it runs through one document. The details of the messages come from an arrest report relayed by local outlets. The "diary" line is the sheriff's paraphrase of what Heller told deputies, not a statement from Anthropic and not something the company has confirmed. Anthropic has not said how it assessed the messages, what threshold they crossed, or whether it notified Heller before contacting police. A referral under an emergency exception can be the right call and still leave no trace the public can audit; here the only account of it is the police version.
There is a separate thread worth keeping apart from the facts. Cybernews notes that Anthropic has drawn criticism over a job listing that classified activism as a "global threat," a dispute about the company's monitoring posture that predates this arrest and does not bear on it. The same company has meanwhile argued publicly that AI systems may have morally relevant inner lives, a case its cofounder took to the Vatican in October. Treating those threads as one story would be a mistake.
What would settle it
A few disclosures would turn this from an anecdote into something a user could reason about. Anthropic could publish how many such referrals it makes and under what standard, the way some platforms report emergency and government requests in annual transparency figures. It could put plain, in-product language in front of users about what triggers human review and when a conversation can reach law enforcement, the notice that a person treating Claude as a diary most needs and currently does not get. It could attach an auditable threshold to the emergency exception rather than leaving it a judgment the company makes alone.
The courts may supply part of the rest. Retired FBI special agent Richard Kolko told WINK News that law enforcement and judges "are still figuring it out," with no settled precedent for threats that surface through a chatbot. Heller's November court date is the next data point, and so is whether Anthropic says anything at all before it arrives.


