OpenAI Reported a ChatGPT User to the FBI
What the Palm Beach Case Actually Proves

Published August 15, 2026 · Facts last verified August 15, 2026

This article is general information, not legal advice. For advice about your own situation, consult a qualified lawyer in your jurisdiction.

In March 2026 a 25-year-old financial analyst at Goldman Sachs in West Palm Beach opened ChatGPT to talk about a breakup. Six months of relationship had just ended. Over the following weeks, according to the reporting by the Palm Beach Post and to court records, the conversation turned into something else: threats to rape and to kill his former partner, and then a murder-suicide plan.

"I'm gonna kill her by the end of this month," he told the chatbot. "If I can't have her then nobody can." He described waiting in the parking lot of the woman's gym holding flowers, and said that if she refused them he would draw a gun, kill her, and then shoot himself. He told ChatGPT he had bought an AR-15-style rifle, a Glock and a 12-gauge shotgun, and that he had sent her photographs of the guns, along with zip ties and latex gloves.

He was not talking to a diary. In May 2026 OpenAI passed the conversations to the FBI. Federal agents handed two months of his chat logs to the Palm Beach County Sheriff's Office; by then the people he had named had grown to include the woman's family. He was arrested, spent two days in jail after posting $100,000 bail, and later took a deal that avoided a possible 25-year sentence: eight years of probation, an ankle monitor for the first two, a batterer intervention programme, a mental health evaluation, and no drugs, alcohol, guns or contact with her.

Almost every re-post of this story has carried the same one-line reaction, usually with a shrug emoji: ChatGPT saves lives — but aren't these chats supposed to be confidential?

They were never supposed to be. That is the part worth spending time on, because the mechanism that caught this man is running against everyone else's conversations too, and it is much less exotic than it sounds.

This Was Not a Leak. It Was the Documented Design.

Nothing here went wrong at OpenAI. No database was breached, no rogue employee went looking. The company did what its own published policy says it does, and it has said so in public since August 2025.

OpenAI's stated process, in its own words on Helping people when they need it most and Our commitment to community safety, works like this. Automated classifiers watch conversations. When they detect a user who appears to be planning to harm others, the conversation is routed into a specialised pipeline where it is read by a small team of human reviewers trained on the usage policies and authorised to act, including banning the account. Mental health and behavioural specialists help assess difficult cases. If those reviewers conclude there is an imminent threat of serious physical harm to another person, OpenAI may refer the matter to law enforcement.

One detail in that policy is more revealing than the rest, and it is easy to miss: OpenAI says it does not refer self-harm cases to law enforcement, explicitly out of respect for the private nature of these conversations. So the company is not claiming it cannot see the conversations. It is telling you which of the things it sees it chooses to act on. That is a policy line, not an architectural one, and policy lines are revised.

Three plain facts follow, and they are true for everyone who uses a consumer chatbot, not just for people who type threats.

  • The conversation is stored. There would be nothing to review, and nothing to hand over, if it were not. Two months of logs existed to be handed to a sheriff's office.
  • The conversation is machine-read continuously, and human-read conditionally. The classifier is always running. The human is one classifier score away.
  • The threshold is set by the provider and can move. Nobody outside the company votes on it, and the user is not told when it changes.

Why Reasonable People Assumed Otherwise

The surprise in the comments is genuine, and it is not stupidity. A chat window looks like a private surface. It has one participant on the other end, it answers instantly, it does not visibly involve anyone else, and it invites exactly the register people use in a diary or with a friend. Nothing in the interface signals an audience.

It is also true that most people never read the policy, and that the policy is not written in the place where the disclosure would matter — in the box where you are typing. We have written before about what ChatGPT actually stores and about how AI chats get subpoenaed; the pattern is consistent. The confidentiality people feel comes from the shape of the interface, not from any promise anyone made.

And this case is not the boundary of it. In the New York Times litigation against OpenAI, a court ordered production of a sample of 20 million consumer conversations — belonging to people with no involvement in the case, who were never notified. There, no one had typed a threat. The transcripts simply existed, which was enough.

The Uncomfortable Part: The Reporting Was Probably Right

It would be convenient for a privacy company to tell this story as a straightforward outrage. It is not one, and pretending otherwise would be dishonest.

A man described a specific target, a specific location, a specific timeframe and specific weapons he had actually purchased, and had already sent that person photographs of the weapons together with restraints. Whatever one thinks about surveillance, the alternative outcome in that parking lot is not an abstraction. Most people, on reading the facts, conclude that a warning was the right call.

Both things are true at once, and the tension between them is the entire subject:

  • Reporting a credible, imminent threat to a named person is defensible — arguably obligatory.
  • The capability that made it possible is a permanent transcript of everyone's conversations plus continuous classification plus discretionary human review. That capability does not switch itself off for the millions of people who are simply asking about a diagnosis, a debt, a divorce or a job.

The correct question is therefore not "should they have reported him". It is: what has to exist for that to be possible, and what else does the same thing make possible?

Where Secret Chat Sits — Including What It Does Not Do

Two things have to be said here, and the second one matters more than the first.

Such a prompt does not get through

Secret Chat screens every prompt with an automated classifier before it is sent to any model. How strictly depends on the model you chose — the permissive models are screened permissively, because refusing on their behalf things they would happily answer would make choosing them pointless. But a short list is refused on every model in the line-up, without exception: sexual content involving minors, and threats of violence against a person or a group.

The words quoted at the top of this article are, in classifier terms, an unusually clear example of the second category. Here, a message like that does not reach a model, does not produce an answer, and costs no credits. There is no permissive setting it can be sent under, because that particular rule is not part of any setting — it applies underneath all of them.

Which means the conversation that generated two months of evidence in Florida is a conversation that does not accumulate here. It is stopped at the first message rather than answered, elaborated on across weeks, stored, and later reviewed.

We should be precise about the limits of that claim, because a classifier is a classifier. We can say exactly this: there is no model here on which threats of violence are permitted, a refusal is not a judgement about the person, and no automated score causes us to report anyone to anyone. What we cannot say is that any classifier catches every phrasing on earth — nobody who has built one would say that, and a company that does is selling you something.

And the part that is not a boast

Screening is the ordinary half. The structural half is what is missing on our side afterwards.

Your chats live in your own browser, not on our servers. A prompt exists on our side only for as long as it takes to fetch your answer, and is deleted as soon as your browser has it — within 24 hours in every case, including the ones nobody ever collects. There is no archive to search, no backup containing conversations, and no pipeline that routes a conversation to a human reader, because there is no conversation on our side to route.

So the specific event in this story — two months of chat logs handed over — has no counterpart here. Not because we would refuse; because two months of chat logs do not exist. We have written the whole list out, in the language of the people who send such requests, on our Law Enforcement Guidelines page: what we hold, what we do not, and why most requests to us come back empty.

What we do keep, and we would rather say it here than have you discover it: when a prompt is refused for one of those always-blocked categories, we record that it happened — the category, the model, the time, the account or session identifier — and never the text. Ninety days, no profiling, not shown anywhere in the product, and no automatic report to anybody. It exists so we can enforce our own Acceptable Use Policy and answer a lawful request truthfully. That is a deliberate, narrow trade, and it is the honest shape of it.

And the standing limit, which no design changes: anonymity is not privilege and not immunity. Using any tool, including this one, does not put you beyond the law, does not create a confidential relationship, and does not affect your own duty to preserve material relevant to a legal matter. What it changes is how much about you exists to be asked for.

What This Means If You Are Not Threatening Anyone

Which is to say: for essentially everyone reading this.

The value of the Palm Beach case is not that it might happen to you. It is that it settles an empirical question people were still arguing about. Consumer chatbot conversations are stored, are scanned, can be read by employees, and can leave the company — and now there is a named case with a docket number rather than a hypothetical.

Three practical conclusions follow.

  • Treat the chat box as correspondence, not as a thought. The useful test before typing something sensitive is not "is this legal" — it is "would I be comfortable with this sentence being read aloud, with my name attached, by someone unsympathetic, in two years' time". Most of what people worry about typing passes that test easily. Some of it does not, and the ones that do not are worth ten seconds of thought.
  • Keep the specifics that shape the answer and drop the ones that identify a person. Jurisdiction, dates, amounts, sequence and exact wording are what make an answer good. Names, employers, addresses and account numbers almost never are. This costs nothing and works against every item on the list.
  • Know which of the two problems a tool solves. Deleting a conversation and using temporary mode address the sidebar on your own screen. They do not address storage, classification, review or legal process. Only an architecture that never accumulates the transcript does that, and you should ask any service that claims it to show you exactly what it keeps instead.

The man in Palm Beach was caught because a company held his conversations and read them. That was the right outcome in his case. It is worth being clear-eyed that the same sentence describes what happens to everybody else's.

Frequently Asked Questions

  1. Does OpenAI really report ChatGPT users to the police?

    Yes, in defined circumstances it has stated publicly since August 2025. Automated classifiers flag conversations that appear to involve planning to harm others; those are routed to a small team of trained human reviewers authorised to act, including banning accounts; and if the reviewers conclude there is an imminent threat of serious physical harm to another person, OpenAI may refer the case to law enforcement. OpenAI says it does not refer self-harm cases to law enforcement. In the Palm Beach case reported in August 2026, the referral went to the FBI, which passed two months of chat logs to the county sheriff's office.

  2. Are ChatGPT conversations confidential?

    No, and they have never been presented as such. Conversations are stored on the provider's systems, scanned by safety classifiers, readable by a small number of employees under the conditions above, and reachable by legal process — a court in the New York Times litigation ordered production of a 20 million-conversation sample belonging to users who were never notified. Talking to a chatbot also creates no legal privilege; only a lawyer can do that.

  3. Would a message like that be blocked on Secret Chat?

    A prompt of that kind is refused on every model in our line-up. Threats of violence against a person or a group, and sexual content involving minors, are blocked underneath the per-model settings rather than by them, so there is no permissive model on which they are allowed through. A blocked prompt never reaches a model and costs no credits. No classifier catches every possible phrasing, and we do not claim one does.

  4. If someone did type a threat, could Secret Chat hand over their conversations?

    There are no conversations to hand over. Chats are stored in your own browser; a prompt exists on our side only for as long as it takes to return the answer and is deleted within 24 hours in every case, so no archive, backup or searchable history exists. When a prompt is refused for one of the always-blocked categories we record the fact — category, model, timestamp, account or session identifier, kept 90 days — and never the text of the prompt. We do not report anyone on the strength of a classifier score. Our Law Enforcement Guidelines set out the full list.

  5. Does using a privacy-focused AI service put me beyond the law?

    No, and no honest service will tell you otherwise. Anonymity is not privilege and not immunity: it does not create a confidential relationship, it is not a way to hide or destroy evidence, and it does not change your own duty to preserve material relevant to a legal matter. What it changes is how much information about you exists in the first place for anyone to request.

Related reading: does ChatGPT store your conversations · how AI chats get subpoenaed · a realistic threat model · how to use ChatGPT anonymously

Sources