On September 26, a woman in Florida typed into Claude that she would "shoot up" the Lee County Sheriff's Office. She later told deputies she used the AI "like a diary". A scanner flagged the phrase, a human review team at Anthropic read the conversation, and the company called the sheriff. She was arrested at home and charged with a felony on September 30.
I am not going to argue she should have been left alone. I am going to argue about the pipeline that caught her, because you are in it too. Every sentence you send to a cloud model goes through the same scanner, the same review queue, and the same retention rules. The threshold is the vendor's to set, and it has moved twice this year.
A scanner, a review team, a sheriff
Four cases in seven months, all from local police reports and court filings:
- March 2026, Florida. A man wrote to ChatGPT about killing his ex-girlfriend. OpenAI reported him to the FBI. He pleaded guilty in August to written threats to kill and got eight years of probation.
- August 11, 2026, San Antonio. A 22-year-old asked Claude about shooting at a nearby elementary school. Anthropic went to the FBI, the FBI went to the police, and he was arrested on a felony terroristic-threat charge.
- August 14, 2026, San Francisco. A user threatened Anthropic's CEO in a chat and said he had bought an AR-15. The company notified police. No arrest, no charge.
- September 30, 2026, Florida. The diary case above. Anthropic's privacy policy, in force since September 10, allows sharing your data with police when it believes in good faith that this is "reasonably necessary to prevent serious harm".
The counter-example is just as telling. In 2025, OpenAI's monitoring flagged the account of the person who later shot up Tumbler Ridge, British Columbia. Staff debated calling the RCMP and decided the chats did not meet their criteria. After the shooting, the CEO apologized. Same scanner, same review team, opposite decision. The rule is whatever the vendor decides it is this quarter.
What the vendor does with the rest
Most chats are never flagged. They are kept. Since September 28, 2025, conversations on Claude's consumer plans and Claude Code sessions are used to train future models unless you find the toggle and turn it off, and they are retained for up to five years if you do not. ChatGPT works the same way: training on by default, off only if you opt out. The paid API and enterprise plans are excluded, which tells you the vendors know perfectly well which data is worth money.
What does a model do with everyone else's text? Anthropic showed us on September 23. Its new biology lab announced that Claude had found "ART", an enzyme system in virus DNA "reminiscent of CRISPR". The numbers in the press release are impressive:
That last number is the one to keep. The reverse transcriptase at the centre of the announcement was described in 2021, in a study of three large viruses that infect Staphylococcus aureus. Anthropic's own write-up concedes it: "Claude did not discover the reverse transcriptase itself." The CEO added that a Stanford team had already found "a system that is in some ways similar", and that the result was obtained "mostly, though not entirely, by Claude". What is new is the arrangement around a known enzyme: a repeat array and an accessory protein next to it, spotted by reading databases other people filled. The paper is a preprint, no one has shown the enzyme is active, and a Harvard biochemist called it "not what we would describe as a breakthrough".
So did Claude discover something, or did it re-read the literature very fast? Mostly the second, with a genuinely interesting footnote. Either way, the business model is on display: the model reads everything it can, and what comes out is announced as the machine's own. The data you paste into a chat today is the corpus it reads tomorrow.
Loi 25 in one paragraph
If you run a business in Québec, this is not only a matter of taste. Loi 25 rewrote the private-sector privacy act in three waves, September 2022, 2023 and 2024, and it has two sections that apply to a chatbot. Section 17: before communicating personal information outside Québec, you must carry out a privacy impact assessment (an EFVP) covering the sensitivity of the data, the purpose, the protection measures and the legal regime where it is going, and the transfer must rest on a written agreement. Section 12.1: a decision based exclusively on automated processing must be disclosed to the person, who can ask what information was used and have it corrected. The Commission d'accès à l'information can impose administrative penalties of up to $10 million or 2 % of worldwide turnover, and penal fines of up to $25 million or 4 %.
Pasting a client's email, a contract, a patient note or a payroll question into a US chatbot is a communication of personal information outside Québec. Try answering the assessment for it: where is the text stored, who can read it, for how long, under which law? With a cloud vendor the honest answers are "in the United States", "a scanner and a review team", "up to five years" and "the vendor's terms, which changed twice this year".
| Question the EFVP asks | Cloud chatbot | Model on your own machine |
|---|---|---|
| Where does the text go? | US data centres | A box in your office |
| Who can read it? | A scanner, a review team, whoever subpoenas the vendor | You |
| How long is it kept? | 30 days to 5 years, vendor's choice | As long as you decide |
| Is it used for training? | Yes, unless you opt out | No |
| Communication outside Québec? | Yes; EFVP and written agreement required | No |
| Who decides to call the police? | The vendor | Nobody; there is no one in the loop |
What a local model changes
A local model runs on hardware you own, on your network, with no account at a vendor. Nothing leaves the building. There is no scanner because there is no one to scan for, no review team, no training set, no five-year retention, and no company to subpoena. The assessment under section 17 becomes a one-liner: the information is not communicated outside Québec.
This is not theoretical. The mail-triage agent I built (the build log is linked below) runs on a $1,199 CAD Mac mini on a shelf, reads a small business's inbox all day, decides what needs a human, and has a monthly API bill of zero. The October update made it three times faster. Client names, invoices and complaints pass through it every day, and none of it has ever left the office.
Be honest about the limits. A model that fits on a desktop is smaller than the cloud flagships; it is excellent at triage, drafting, extraction, search over your own documents, and worse at the hardest reasoning. You own the box, so you own its backups and updates. And it does not make you compliant by itself: the data on that machine is still personal information, and the rest of Loi 25 still applies. What it removes is the part you cannot control: the vendor.
What this means for an SME
- Decide what never goes into a cloud chat. Client files, employee data, health and financial information, anything you would not email to a stranger. Write it down; staff are pasting these into chatbots today.
- Put the daily work on a local model. Sorting mail, drafting replies, summarizing documents, answering questions from your own files. These are the jobs that touch personal information the most, and a desktop-class model does them well.
- Keep the cloud for what it is good at. Hard reasoning, code, research on public information. If no personal data goes in, the scanner and the training set are someone else's problem.
The vendors are not villains in this story; they are companies doing what their terms allow. The mistake is treating a chat window like a notebook. A notebook does not read itself, does not phone the sheriff, and does not publish what it learned from you as its own discovery.
Sources
- Florida woman arrested after Anthropic reported her Claude chat to police, The Next Web, with the San Antonio and San Francisco cases
- OpenAI debated calling police about suspected Canadian shooter's chats, TechCrunch
- Anthropic says its biology lab has already found something big, TechCrunch
- Claude spotted a CRISPR-like DNA pattern. Can it be reproduced?, The Neuron, on the 2021 paper
- Anthropic privacy policy and OpenAI privacy policy: training defaults, retention and disclosure to authorities
- Act respecting the protection of personal information in the private sector, sections 12.1 and 17, and the penalty ceilings published by the Commission d'accès à l'information