244 points emptybits 13 hours ago 193 comments
altmanaltman 12 hours ago | parent
Thought crimes are real when you're sharing your thoughts with Claude
Guvante 12 hours ago | parent
danpalmer 12 hours ago | parent
bossyTeacher 12 hours ago | parent
Summary: don't type in Claude anything you wouldn't like a human to read.
jimbob45 12 hours ago | parent
calgoo 12 hours ago | parent
danpalmer 12 hours ago | parent
I don't think someone is an idiot for thinking that the information they type into their private Claude account is private. I also don't think people are idiots for thinking their phone is listening to them and giving them targeted advertising based on that. Both are reasonable deductions from their lived experiences. Both are wrong.
foolfoolz 12 hours ago | parent
https://www.nbcmiami.com/news/local/everyone-deserves-to-die...
https://www.wdsu.com/article/maryland-high-school-student-ch...
https://www.pinellassheriff.gov/21-023-deputies-arrest-pinel...
danpalmer 12 hours ago | parent
TheDong 12 hours ago | parent
If it were written on paper, and only in a room with no phones or cameras so fable couldn't hack it, then I think you wouldn't be sharing it.
JumpCrisscross 12 hours ago | parent
I think it’s valid to ask if tapping something into Claude is legitimately sharing a threat.
I don’t think it is. I also think the sheriff could have found more-substantial evidence if she was actually planning domestic terrorism.
That said, if the shooting happened and we were looking at this from before? It’s a tough balance without an easy answer.
lores 5 hours ago | parent
JumpCrisscross 4 hours ago | parent
I think it’s fair to pre-identify folks who fantasise about shooting anyone. It’s a small fraction of the population that looks into logistics versus making offhand comments.
quadhome 12 hours ago | parent
— via https://www.leg.state.fl.us/Statutes/index.cfm?App_mode=Disp...
The DA is serious about "in any matter."
dotancohen 12 hours ago | parent
elil17 12 hours ago | parent
positive-spite 1 hour ago | parent
andylynch 12 hours ago | parent
1659447091 12 hours ago | parent
serial_dev 11 hours ago | parent
> may be viewed by another person
Was it viewed by another person? Yes.
wildzzz 38 minutes ago | parent
codingdave 1 hour ago | parent
To me, that is the more interesting legal question. Does a LLM-based safety net that sends content to a human, when the original use case would not have sent it to a human, count as "may be viewed by another person". It certainly wasn't intended to be, and that isn't the norm. At the same time, because no security is perfect, we could say that any digital record, stored in any way "may be viewed by another person."
Something for the courts to sort out, of course.
Symmetry 56 minutes ago | parent
socializer 12 hours ago | parent
However, people need to get it in their heads that they're not chatting with their secret BFF, they're chatting with Big Tech. Before LLMs, Big Tech had no way to scrutinize the bulk of what was going on within their services, so you could have a secret hate diary in Google Docs. Now, everything you say or write can be automatically screened for red flags on a planetary scale, and probably will be because that's what the regulators and "concerned citizens" will demand. In a couple of years, you'll be biting your tongue a lot more often in private chats.
vulcan1964 12 hours ago | parent
As another commenter said, you're not chatting with a friend; you're chatting with Big Tech.
How much do you love Big Brother?
letrix 1 hour ago | parent
gus_massa 1 hour ago | parent
Most people don't realize that it is 99% like posting it on Facebook.
slopmachine 19 minutes ago | parent
JumpCrisscross 12 hours ago | parent
Yup. And with zero privacy protections in statute for AI chat, there is nothing to prevent an AI CEO looking to curry political favour from e.g. handing over the private correspondence of an opponent or an entire district’s residents.
HPsquared 2 hours ago | parent
tpoacher 1 hour ago | parent
sigbottle 1 hour ago | parent
It's more efficient to have one central "verifier" for everything, but the "who watches the watchers"? question basically says: Either constrain by construction, have everyone verify (which are two sides of the same coin, btw, when looking at a "global" thing), or centralize explicitly.
nradov 1 hour ago | parent
krzat 12 hours ago | parent
gr_norm 12 hours ago | parent
vincnetas 12 hours ago | parent
rowanG077 12 hours ago | parent
veltas 12 hours ago | parent
yread 11 hours ago | parent
brookst 3 hours ago | parent
ribosometronome 20 minutes ago | parent
whycome 2 hours ago | parent
badatnames 12 hours ago | parent
Somehow humanity survived the past 40 years without Microsoft Word and Excel phoning home and shopping users to the feds at random, I don't see why the standard should be any different for this new class of tooling.
trallnag 11 hours ago | parent
anfogoat 11 hours ago | parent
VariousPrograms 11 hours ago | parent
devinprater 1 hour ago | parent
mcphage 4 hours ago | parent
On the other hand, they did put themselves into this position deliberately.
brookst 3 hours ago | parent
Show me any product, no matter how simple, that has no safety vs utility tradeoff.
zdragnar 2 hours ago | parent
For anyone technically inclined it should be obvious, but it isn't part of the zeitgeist or how they pitch it. People see it as being different than talking to a human, and behave as if there won't be a human in the mix.
hackable_sand 20 minutes ago | parent
api 1 hour ago | parent
I feel like if people understood what these things actually are there'd be way less of this AI psychosis and similar stuff.
There'd also be fewer people falling for apocalyptic Rationalist delusions.
Also: people need to understand "not your computer, not your data." (Unless it's stored in the cloud but encrypted locally with keys only you possess.) Same goes for storing things unencrypted in OneDrive, Google Drive, etc. There is nothing to stop these companies from bulk scanning, data mining, or reporting people based on whatever request a government gives them. Don't count on them to resist, because they often can't, especially if the request is from a sovereign state where they do business.
orangecat 1 hour ago | parent
Assuming you consider it a "delusion" to have a p(doom) of more than 5% or so, that's not uncommon among frontier lab employees who have a pretty good idea of how LLMs work.
nradov 1 hour ago | parent
sandeepkd 1 hour ago | parent
A bot talking to you directly as if its some one real caters to your thoughts and can take you in a certain direction without you realizing it. I have heard first hand experience from people that they feel more comfortable talking to chatgpt or claude cause it gives a feeling of being on their side and listening to them.
Isamu 1 hour ago | parent
Then the AI companies have more confidence that they can move forward in a certain way, and issue investor guidance that is maybe closer to reality.
monocasa 1 hour ago | parent
heaney-555 1 hour ago | parent
monocasa 1 hour ago | parent
bilekas 43 minutes ago | parent
monocasa 31 minutes ago | parent
ghostpepper 30 minutes ago | parent
Legend2440 33 minutes ago | parent
They want stable rules they can follow, which will limit their liability as long as they stay within them.
They also would like those rules to be as restrictive as possible towards their competitors.
monocasa 28 minutes ago | parent
I'm quite sure that if there wasn't the existential threat of a lack of a moat, they would not be pushing for regulations at all.
mhitza 1 hour ago | parent
I see constant ads on video platform (particularly youtube/tiktok) about llm chat apps, from friends, dating, romance and everythkng inbetween; that's personal.
People need to be reminded constantly if they use such apps that they are participating in easier mass surveillance, profiling and AI training.
torben-friis 1 hour ago | parent
It wasn't technically feasible to scan personal chats easily, other than grepping keywords which must have had a bajillion false positives. Now you can get everything autoscanned at scale.
smcg 1 hour ago | parent
fasterik 1 hour ago | parent
ToucanLoucan 52 minutes ago | parent
For non-technical people, it isn't really news, because they already forgot about it after reading it. Maybe they'll be a little more monitored in their own typing for like... a day or two.
One of the hardest lessons to internalize, and keep internalized, as someone who works on and writes software, is the vast, vast, vast majority of the Public doesn't understand even the most basic shit about software. It just does stuff. Hopefully the stuff is good. That's it, beginning, middle, and end.
"Why would you think x would y" is a poor framing. They didn't think about x or y because they don't care. The phone works, that's the beginning and end of their interest in the subject.
fn-mote 51 minutes ago | parent
Also, unlike the bad old days when 1 in 3 was an informant, now ordinary people aren’t in “informant loop” of providing information on others, so they aren’t thinking about being informed on either.
schoen 1 hour ago | parent
"Anthropic failed to report murderer's threats to authorities"
(or "Chatbot knew man was planning murder, yet company did nothing")
"Anthropic reported private chats to authorities"
(or "Arrested for chatbot fantasy")
To be fair to the journalists in these cases, there's also no society-wide agreed Schelling point about the correct outcome or correct rules. I have strong beliefs and intuitions about what should happen, but other people also have strong beliefs and intuitions, and many of those are probably opposite of mine. Even if my intuitions are the best and most justified, a journalist is unlikely to think "I'm just not going to mention that some people are mad at this company over this outcome, because a hypothetically better norm or principle would support the company's actions here". Hopefully the journalism can at least contextualize the lack of legal or social consensus and the difficult incentive problems, rather than jumping to "obviously companies are sociopaths staffed by supervillains".
pessimizer 1 hour ago | parent
Including any chats anywhere where someone might have a phone in their pocket, or if there's a "camera" attached to a utility pole or a nearby tree. The only real private chats might be whispered lying down in the bathtub together, with a mattress covering it like you're both hiding from a hurricane.
> they're chatting with Big Tech
They're chatting with any powerful person who wants to hear it. She thought she was chatting with Anthropic, who doesn't give a shit about her. But after being threatened (and immediately backing down because, of course, they don't give a shit about her) Anthropic has become an arm of the government. So she was chatting with the Bonita Springs, FL Sheriff's office, or anybody else. If I paid enough, Anthropic would tell me about what she was doing so I could sell her laundry detergent.
rustystump 53 minutes ago | parent
gchamonlive 35 minutes ago | parent
It's the other way around, big techs need to properly disclose in their platform, during interaction that they aren't in a private and safe environment
ollin 13 minutes ago | parent
OpenAI’s stated rationale was a concern for the shooter’s privacy, but its own interests
better explain its silence. Upon information and belief, OpenAI was seeking to avoid implementation of a
hard line rule to refer planning of real-world violence to authorities, perhaps due to how frequently its
product is implicated in threats to human life. Requiring such disclosures would be incompatible with the
company’s public position that ChatGPT is safe. It could also threaten the valuation underlying OpenAI’s
anticipated initial public offering. Rather than expose those risks, OpenAI accepted the consequences of
its silence. A mass murder in the only secondary school in Tumbler Ridge followed.
Accordingly, the Crown, led by Attorney General Sharma, and SD59 jointly bring this
action to hold OpenAI and Sam Altman accountable for designing a dangerous product, distributing it to
every home with internet access, ignoring the warnings of their own safety team,
refusing to notify authorities when they knew the shooter was planning gun violence, inviting the shooter back onto the
platform after deactivating the shooter’s account, and choosing corporate self-interest over the lives of
children. They seek compensation for the not just foreseeable but known harm OpenAI inflicted, the
damages that they incurred and are incurring, and injunctive relief to ensure that this tragedy does not
happen again.
[1] https://cdn.arstechnica.net/wp-content/uploads/2026/09/Briti...thih9 12 hours ago | parent
Then again, I wish this worked in a way that would give users more privacy and agency, instead of less.
Muromec 12 hours ago | parent
Anoian 12 hours ago | parent
Of course I did not mean any of that stuff, but how can you make sure a human reviewer knows you did not mean it while the llm does not know that you did not mean it.
I guess its a miracle I am not in jail yet.
Flagging people for anything said to an llm sounds wrong to me because an LLM is not a real person and while some people put in their internal thoughts, others just roleplay and the two are inseparable just from reading it.
adrianN 12 hours ago | parent
childintime 12 hours ago | parent
Adding: - I typically ask questions in the I form, regardless for whom or why I ask for. - Gemini chats quite often end when it starts recommending psychological council or a suicide line, to talk about my problems. It apparently detects a persistent tendency to not agree with the party line. So it makes sense I must be suicidal ;-
But sure, as llm's start to babysit us, and know our inner dialog better than anyone else, we'll soon be debugging their opinion/behavior/co-existence/authority, when it comes to reporting people to the authorities, or taking on tasks in society in general. We'll hire doctors to cure our psychological profile from our record (Total Recall).
A Minority Report like this shouldn't cause a referral to the police.
CrzyLngPwd 12 hours ago | parent
Over in Europe they want to read all ofd our private messages, yet these chatbots, pretending to be our friends, will snitch on us just for our thoughts.
It's getting pretty orwellian out there.
vulcan1964 12 hours ago | parent
SauciestGNU 6 hours ago | parent
stickfigure 2 hours ago | parent
epihelix 57 minutes ago | parent
ars 32 minutes ago | parent
yaro330 59 minutes ago | parent
childintime 11 hours ago | parent
Dig1t 12 hours ago | parent
dabinat 12 hours ago | parent
weikju 7 hours ago | parent
slopmachine 15 minutes ago | parent
Two teens riding in a Waymo were arrested because the AI detected them talking about having a gun.
feverzsj 12 hours ago | parent
shlant 12 hours ago | parent
nextaccountic 11 hours ago | parent
Basically, under this interpretation, any personal note you store in the servers of a company could qualify, even if you didn't ever imagine someone would read and as such you couldn't have thought about it as a threat
olalonde 12 hours ago | parent
How does a LLM prompt satisfy this? I guess it'll be an easy win for her.
cryptonym 12 hours ago | parent
hackernud3s 12 hours ago | parent
vasco 12 hours ago | parent
apparent 12 hours ago | parent
> Heller faces a charge of making a written threat of violence under Florida law. Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism.
She didn't threaten anything, she wrote down that she was going to do it. A "threat" is more than a mere statement, especially when written in what is described as a "diary".
> A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to "shoot up" the Sheriff's office.
Obviously I don't want anyone to shoot up anything, but this seems like a weak case legally speaking.
nextaccountic 11 hours ago | parent
sandos 10 hours ago | parent
halJordan 4 hours ago | parent
I can certainly threaten you harm and send it to not-you and you're still clearly in danger even if it wasnt transmitted to you. So the question becomes did she transmit it to someone? Clearly yes she transmitted it to Anthropic. But she clearly intended to send it to Claude, an inanimate object.
karmakaze 4 hours ago | parent
> The communication must be made in a manner in which another person may view it.
Even 'transmitted' is too broad if you also consider iCloud backup to be a means.
Zigurd 2 hours ago | parent
zdragnar 2 hours ago | parent
caffeinated_me 1 hour ago | parent
zdragnar 43 minutes ago | parent
gopher_space 1 hour ago | parent
kube-system 59 minutes ago | parent
zdragnar 53 minutes ago | parent
I'm not really sure that this can be likened to a diary when it is called a "chat" but that's for the legal system to determine, not me sitting on my couch.
kube-system 48 minutes ago | parent
And yes, some laws are "strict liability", I don't think this one is.
MisterMunchkin 47 minutes ago | parent
wildzzz 42 minutes ago | parent
aeturnum 2 hours ago | parent
IMO I do not think this is a grey area and it's legal to tell a LLM you want to kill someone. It's certainly not a "threat" like you might send to another person, though it may end up being evidence of conspiracy or premeditation. I suspect we would be well served to, after a few years of experience, put together some laws governing when LLM chats must be made available to authorities.
It is very interesting that the LLM responses to these lines - the context around what she is saying - is not in the article. I suspect, as is the case in many instances where LLMs are involved in violent planning, that the LLM was urging this behavior on. Basically entrapment - you are encouraged by a robot to become more violent and vindictive and then when you do you are handed over to police.
mossTechnician 1 hour ago | parent
> Review is needed to enforce our Usage Policy... designated members of our Trust & Safety team may access this data on a need-to-know basis as a part of their evaluation process.
[0]: https://privacy.claude.com/en/articles/10458704-how-does-ant...
kube-system 51 minutes ago | parent
The critical part of a "threat" is that the perpetrator takes some intentional method to deliver it.
Havoc 12 hours ago | parent
A diary constitutes making a threat?
Oh boy the roleplaying part of LLM world is in for a bad time
Lio 11 hours ago | parent
What would happen if it had scanned a file it didn’t have permission to look at and found this threat?
I honestly don’t know how I feel about this. On the one hand if you’re using claude as a diary you have no expectation of privacy and she was talking about committing a very serious crime.
This still makes me feel queasy though.
fwlr 10 hours ago | parent
jameskilton 7 hours ago | parent
One unfortunate woman who happened to write the wrong thing in the wrong place is now having her life turned upside-down for perceived thought-crime.
To Anthropic, and all employees working there, your company's product and the result of your work is cruelty. You are enabling it and pushing it down everyone's throat. You can never again claim that you are the "ethical" AI company, for no such thing exists.
kmfrk 7 hours ago | parent
AIorNot 1 hour ago | parent
jakzurr 1 hour ago | parent
Is this an invasion of their privacy (reporting to police)? Yes, but possibly warranted?
Should a social worker have contacted them rather than the police? Probably, if for no other reason than to ask if they were serious about harming someone.
Difficult questions, I'm still undecided on whether it's OK to always ignore someone's rants, even if it may be (or they think it may be) a private diary.
Actually charging them with a felony seems pretty quick to accuse. (Maybe I missed a hint about how long the investigation took before the felongy charge?)
hypfer 1 hour ago | parent
1209-1266 1 hour ago | parent
https://www.politico.com/news/2023/08/30/desantis-warns-hurr...
1209-1266 1 hour ago | parent
Every single lie of yours is exposed in the past few months.
madeofpalk 1 hour ago | parent
yaro330 1 hour ago | parent
crazygringo 56 minutes ago | parent
You get privacy if you're a big corporation that needs to make sure OpenAI/Google/Anthropic can't read your trade secrets etc.
But those contractual privacy protections have been in place for a long time. It doesn't have anything to do with AI, it's been the same with Office365, Google Docs, etc.
seanmcdirmid 30 minutes ago | parent
LocalLLM enthusiasts exist for a good reason.
jjmarr 1 hour ago | parent
l0kihardt 1 hour ago | parent
epihelix 54 minutes ago | parent
The downside is that you don't get cached prompt discounts, so you pay a heavy price for ZDR that way.
ralphington 50 minutes ago | parent
MisterMunchkin 44 minutes ago | parent
I’ve had them email me before because I was testing it as a filter for abusive messages and they detected some no-no and wrongthink in those test messages.
tantalor 1 hour ago | parent
Seems to fail this test at face value.
I mean, somebody you live with may find and read your diary. Is that the same thing?
Intent matters here. Did you intend somebody else to view it? Does a reasonable person have expectation of privacy with a chatbot?
hypfer 1 hour ago | parent
It should catch normal people becoming unstable so that they can receive help. It is just highly unfortunate that the US legal system works in ways where now this woman's name is public.
___
Of course, we also want purely private tech, but that needs a certain level of merit and sanity filter.
fasterik 53 minutes ago | parent
Do we, though? What if someone started an AI company that uses end-to-end encryption to make it impossible for anyone but you to access your data? Personally, I would switch to it in a heartbeat assuming it's competitive with the other products. I don't think it's the tech companies' job to surveil the population and prevent crimes. That said, I'm not necessarily against Anthropic or other companies reporting suspicious activity if their existing systems are detecting it. I'm just not sure we want every product to be forced into that data model.
Your follow-up about purely private tech seems to contradict your first statement. We can either have privacy or surveillance, not both.
hypfer 42 minutes ago | parent
That is correct! And exactly my point.
We want both, but, on paper, that is impossible. But in reality, we make it sorta mostly happen anyway, through making the easy defaults not private, and the private stuff not easy.
This is not ideal, because [various reasons I do not need to tell you], but it has proven to be the best we can do to mostly achieve both goals.
Kinda like how capitalism isn't great but just the least worst option we've found so far.
___
The actual fundamental underlying problem being that not all people are equal, but we kinda have to pretend they are, because not doing so leads to fascism and other terrible stuff.
But we kinda also do not want to fully pretend that, because doing so leads to yet other terrible stuff.
Hence the quadruple-speak and contradictions to kinda sorta somehow have a somewhat functioning reality.
vladms 34 minutes ago | parent
A lot of people causing issues are people that can't make sense of many things (like many terrorists). They get a fixed idea and they end up doing something bad. You would catch those with some (basic) surveillance.
A lot of normal people (not wanting to cause issues) might benefit from some privacy, if they understand what are the trade-offs (like government overreach). They can then use a slightly more complex tech.
We would still remain with the couple intelligent but sociopaths (think Unabomber style), but I think no solution can fix all cases.
r2_pilot 22 minutes ago | parent
Why wait for a company to build it? Get your own local hardware like I did and have those guarantees because YOU set it up.
user43928 10 minutes ago | parent
Even if open models were competitive, it's still typically going to be more expensive than a cloud provider because of low utilization and higher purchase price.
rustystump 49 minutes ago | parent
There are trade offs. ISP effectively is like driving on a highway, everyone can see where you are going but not what is inside the car. Id like these AI chats to be the same but they are not.
Terr_ 25 minutes ago | parent
Back to LLM chats: A system that can declare her "unstable" is also one that can permaban you from all air-travel because you "privately" said unflattering things about Dear Leader.
hypfer 16 minutes ago | parent
I know all these things. I build software specifically against these things.
12387-asd 24 minutes ago | parent
duplessitous 7 minutes ago | parent
zug_zug 52 minutes ago | parent
deadbabe 21 minutes ago | parent
MisterMunchkin 50 minutes ago | parent
bilekas 44 minutes ago | parent
theturtletalks 44 minutes ago | parent
akerl_ 42 minutes ago | parent
With the obvious IANAL, it doesn't seem to rely on the message be sent to the person being threatened. The specific segment is "in any manner in which it may be viewed by another person".
This may be one of those cases where we get to find out how courts view SaaS platforms.
nemomarx 40 minutes ago | parent
advisedwang 35 minutes ago | parent
throw310822 25 minutes ago | parent
According to Gemini, "Florida appellate courts have overturned juvenile convictions [based on this law] when the state could not prove the person subjectively intended for the record to be seen."
sandworm101 30 minutes ago | parent
Note that the law doesn't forbid the writing of a threat. You have to send it to someone. Had she kept it in a book under her bed, she would not be in trouble. But she sent it to a website/service/LLM portal.
>> It is unlawful for any person to send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record, including an electronic record, in any manner in which it may be viewed by another person
wlesieutre 25 minutes ago | parent
sandworm101 18 minutes ago | parent
FYI, the use of drafts folders to transmit messages has been used by terrorists. This is likely where CIA director David Petraeus got the idea when he needed a secure way to chat with his mistress.
https://www.findlaw.com/legalblogs/technologist/gen-petraeus...
weego 16 minutes ago | parent
Saving is not sending ie passive vs active act.
sajithdilshan 23 minutes ago | parent
danudey 12 minutes ago | parent
slopmachine 22 minutes ago | parent
Aurornis 15 minutes ago | parent
The AI companies have clauses in their user agreements saying they can review content flagged as harmful. It’s not legally spying.
If you recall previous outrage about ChatGPT being used in cases of suicides or shootings, this is the result. Every time a crime was committed and the police found ChatGPT history about the crime, the media turned it into a frenzy. So the AI labs added safety filters to their consumer plans that detect threats of violence, escalate them to human review, and report to the police.
Spying is not the right analogy because the information was given to the police by a third party which had a EULA saying they would do this. A more analogous situation would be someone reading another person’s diary and then turning it into the police department. There might be some limitation in the law that makes the evidence inadmissible because it was not intended to be shared with anyone, but that’s a separate decision.
Forgeties79 11 minutes ago | parent
This is spying with extra steps couched in corporate speak.
Aurornis 8 minutes ago | parent
Frustrations about Anthropic’s EULA are a separate matter.
drusepth 5 minutes ago | parent
asgf-qwr 4 minutes ago | parent
Then, you can write anything in an EULA but it is not automatically legal either.
order-matters 9 minutes ago | parent
sandbox your ai.
hackerbrother 46 minutes ago | parent
shevy-java 22 minutes ago | parent
Snitching on the people - good mass surveillance company.
On the other hand, people need to learn to not trust these companies. It reminds me of others being surprised when a self-driving car reported a gun in the car. I mean, do people not think? Besides, of course, it's already messed up to want to have a gun. And it is constantly one country that has such issues, more so than many other countries.
tintor 22 minutes ago | parent
Anthropic (in discussion with Pentagon) claimed mass surveillance is their red line.
Yet, they do automated mass surveillance of their users on behalf of police.