NewsAI & Development

Anthropic Called Cops on a Claude Diary. Felony Followed.

Split composition showing a chat bubble diary icon breaking apart with a police badge on the right half, representing AI privacy and law enforcement

A Florida woman wrote what she thought was a private diary entry in Claude. Anthropic read it, flagged it as a credible threat, and called the police. Carli Michelle Heller of Bonita Springs is now facing a second-degree felony. The criminal charge is straightforward. The implications for everyone building on top of AI APIs are not.

On September 26, Heller typed a message into Claude stating she would “shoot up” the Lee County Sheriff’s Office. She later said she uses Claude like a diary. Claude’s safety classifiers flagged the entry, escalated it to a human reviewer, who determined the threat was credible and reported it to law enforcement. Deputies visited her home, detained her without incident, and she now faces charges under Florida Statute 836.10 — a second-degree felony that applies to written or electronic threats of violence, regardless of intent to act.

The Policy Change That Made This Possible

This did not happen in a vacuum. Anthropic updated its consumer privacy policy, effective July 8, 2026, to permit proactive sharing of conversation data with law enforcement based on an internal “good faith belief” — without requiring a court order first. The exact language: the company may share personal data when it has “a good-faith belief that disclosure is reasonably necessary to… prevent serious harm to any person or to property.” Most comparable platforms require formal legal process before voluntary disclosure. Anthropic moved that threshold down to internal judgment alone.

Crucially, this policy applies to consumer accounts — Free, Pro, and Max — only. Enterprise, Team, and API accounts are governed by separate customer agreements with different data handling terms. That distinction matters enormously for developers.

Consumer Claude and API Claude Are Not the Same Product

This is the detail almost no mainstream coverage is catching. If you are building an app and routing users through Anthropic’s consumer endpoints — embedding claude.ai or using consumer-tier infrastructure — your users fall under that proactive disclosure policy. However, if you are building on the Claude API with an enterprise or business agreement, your data handling is governed by your contract, not Anthropic’s consumer privacy policy.

The journaling apps, companion tools, and therapy assistants that exploded in 2025–2026 built on Claude because it was the easiest path. Moreover, if those integrations are running on consumer-tier credentials, every flagged conversation is subject to the same process that landed Heller in handcuffs. That is not a hypothetical liability. That is the current policy.

Someone Read Her Diary

AI safety is not purely automated. Claude’s classifiers flagged the entry, yes. But a human reviewer made the credibility determination and decided to call police. That is the part that tends to surprise people. When content is flagged at Anthropic, an employee reads it. The automation catches it; a person judges it. Furthermore, anyone building tools where users speak candidly — about stress, frustration, mental health, or violent ideation — should design with that reality in mind.

Was Anthropic Right?

Community reaction has been divided in a predictable way. The pro-reporting argument is hard to dismiss: threatening to attack a police station is a threat. If a therapist heard that in session, they would be legally required to report it. However, AI companies acting as de facto mandatory reporters — without the licensing, oversight, or accountability framework of licensed professionals — is a different thing entirely. The civil liberties argument carries weight too: Anthropic made a unilateral decision, without a court, without notice, based on an internal standard no one outside the company can audit. “Good faith belief” is a policy written by the company being asked to make the call.

What This Means If You Are Building Something

The practical takeaways are short:

  • Build sensitive personal applications — journaling, therapy, emotional support — on the API or Enterprise tier, not consumer endpoints. Your users’ data handling is governed by your contract, not a unilateral policy update.
  • Add explicit disclosures to your UI. “This is not a private journal. Your conversations may be reviewed in certain circumstances.” Users who do not understand the product will misuse it in ways that expose them — and you.
  • If true privacy is a requirement, use a local model. Janus and tools like it run inference locally — no conversation ever leaves the device. ByteIota covered how to set up Janus when it launched.
  • Review Anthropic’s government requests policy now, not after an incident forces your hand.

Heller’s case will likely be resolved quickly. The policy question it surfaces — who decides when an AI company becomes an informant, and whether users will ever trust “personal” AI tools after incidents like this — will not.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News