A threat written to Claude as a diary was reported by Anthropic: terms checked
A Florida woman was arrested over an attack threat she wrote to Claude as a diary. I check how it was reported, plus Anthropic's terms, privacy policy and retention.
TL;DR
- A Florida woman was arrested on September 30, 2026 on a felony charge over a threat to attack a sheriff's office that she wrote to Claude. According to the arrest report, Anthropic's detection system flagged it and a human reviewer reported it to law enforcement
- Anthropic's consumer terms of service reserve the right, at its discretion, to report inputs, outputs and actions to law enforcement. The privacy policy also allows disclosure when it believes it is necessary to prevent serious harm
- Chats flagged as violating the terms can be kept for up to 2 years for inputs and outputs, and up to 7 years for classification records. This retention can continue even if the user deletes the conversation
- A court date is set for November, and guilt has not been decided. This article covers only facts as reported
Contents
A woman in Bonita Springs, Florida was arrested on a felony charge after writing a message to Claude threatening an attack on a sheriff’s office. According to the reported sequence of events, Anthropic made the report. She is said to have told reporters she was using Claude like a diary.
Plenty of people use Claude to write things they don’t plan to show anyone. So I checked three things against the text of the terms and Anthropic’s official help pages: how the case unfolded, what Anthropic relies on to make a report, and how conversations that aren’t reported are stored.
The reported sequence of events
According to Decrypt’s article, which cites local station WINK News, and Daily Caller’s article, the sequence was as follows.
- On September 26, the woman wrote text in a conversation with Claude to the effect that she would attack the Lee County Sheriff’s Office
- The next day, the 27th, she wrote text to the effect that she had obtained a new gun
- Anthropic’s detection system picked up the messages and sent them to a human reviewer. According to the arrest report, the reviewer judged the content serious and reported it to law enforcement
- Sheriff’s office staff identified the woman and took her into custody at her home. She reportedly did not resist
- The arrest was on September 30, on a charge of “written threats to kill or do bodily harm”. A court date is set for November
According to TechSpot’s article, the woman says she uses Claude like a diary. Guilt has not been decided. Here I stick to the facts as reported.
Why a “diary” can still be a crime
The charge rests on Florida Statute 836.10. The statute makes it unlawful to send, post or transmit, in writing or an electronic record, a threat to kill or harm another person, or to carry out a mass shooting or terrorism, “in a manner whereby the message may be viewed by another person”. It is a second-degree felony.
How to read “may be viewed by another person” looks likely to be the point of dispute. Unlike writing in a paper diary, input to Claude is sent to the provider’s servers, and the provider’s staff may read it. Whether that meets the statute’s requirement is for the court to decide. I only set the reported facts next to the statute and draw no conclusion.
What Anthropic’s terms allow
The terms of service for the consumer services (Free, Pro and Max) contain provisions to this effect.
- The company may respond to requests or demands from governments, courts and law enforcement
- It reserves the right, at its discretion, to report information about users, including inputs, outputs and actions, to law enforcement
The privacy policy also says that where it believes in good faith that it is necessary, it may share personal data with government agencies, law enforcement and others. The cases it lists are responding to laws and legal process, preventing serious harm to people or property, addressing fraud and other unlawful activity, and enforcing the terms and protecting the safety of users and others.
In other words, the structure is that even without a warrant or a formal request, the company can report if it judges it necessary to prevent serious harm. A process like this one, where a human reviewer reads the content and decides, falls within the terms.
How conversations that aren’t reported are stored
Conversations that aren’t reported also raise a storage question. Anthropic’s Privacy Center describes retention for the consumer services as follows.
- When a user deletes a conversation, it disappears from their history immediately and is deleted from backend storage within 30 days
- If the user has allowed their data to be used to improve models, it may be kept in de-identified form in training pipelines for up to 5 years
- If a conversation is automatically flagged as violating the usage policy, inputs and outputs may be kept for up to 2 years, and trust-and-safety classification scores for up to 7 years
- Conversations may also be kept to comply with legal requirements or to resolve disputes
The last two points are the ones relevant to this case. The help page says data is kept when necessary to meet legal requirements or deal with usage policy violations, which suggests a flagged conversation can remain even after it is deleted.
These are the terms for the consumer services. Business products such as Claude for Work and the API are under separate terms.
This is not the first report
Decrypt also mentions another case. According to The San Francisco Standard’s article of September 4, a user wrote in a chat with Claude that they had bought an AR-15 and were targeting the company’s CEO, and Anthropic reported it to the San Francisco Police Department.
An Anthropic spokesperson told the paper the “safeguards process worked as intended” and said the account was suspended. The user told the paper they were only joking. As of the article, no one had been arrested or charged.
Decrypt also writes that OpenAI’s policy since August 2025 likewise routes threats against others to human reviewers and may report them to law enforcement. This is practice across AI providers, not one company’s alone.
From detection to report
Anthropic’s official explainer describes monitoring after release as a mix of automated and human review. Classifiers (Claude models) tuned to detect specific violations assess conversations, and human review is added. The path the arrest report describes is detection of key phrases, escalation to human review based on how serious the content is, and then a report. The official description and the report broadly agree.
Which words or context the classifiers react to, and at what point human review decides to report, is not public.
What readers should take from this
Discussion of the case is heading toward whether the standard for reporting is appropriate. For everyday use, three points can be confirmed.
- A consumer chat is a place where the provider’s staff may read what you write. The terms allow reporting, and longer retention when something is flagged
- Even if you mean it as a “diary”, “draft” or “talking to myself”, text that amounts to harm or threats against others can be flagged and reported. If you want to write out your feelings, a paper notebook that doesn’t pass through a provider’s servers avoids the chance of a report
- For work, check the terms and data handling of business products separately from the consumer ones. Don’t write internal company information into a personal account
The reporting standard itself is not written in the public documents I could find, or in the coverage of this case.
The next check is the November court date
Both reported cases are ones where Anthropic reported to the police. In one of them, the user says they were joking. Because the standard for reporting isn’t public, users can’t see where the line falls between a real threat and a joke or venting. How the statute’s “may be viewed by another person” is interpreted at the November court date is the next thing to watch.