The AI companies have clauses in their user agreements saying they can review content flagged as harmful. It’s not legally spying.
If you recall previous outrage about ChatGPT being used in cases of suicides or shootings, this is the result. Every time a crime was committed and the police found ChatGPT history about the crime, the media turned it into a frenzy. So the AI labs added safety filters to their consumer plans that detect threats of violence, escalate them to human review, and report to the police.
Spying is not the right analogy because the information was given to the police by a third party which had a EULA saying they would do this. A more analogous situation would be someone reading another person’s diary and then turning it into the police department. There might be some limitation in the law that makes the evidence inadmissible because it was not intended to be shared with anyone, but that’s a separate decision.
So don't run for office or anything like that. Someone, somewhere will have a contact that will get that.
This is spying with extra steps couched in corporate speak.
Frustrations about Anthropic’s EULA are a separate matter.
Presumably, Anthropic did the spying and the reporting.
You argued that it is not spying, since the spying may have been made sufficiently explicit in the ToS/EULA.
This raises the question: Does announcing a spying operation mean that it is no longer spying? I've never heard that perspective before.
Well, kind of, yeah; the dictionary definition of spying requires secrecy and lack of consent.
> to secretly collect and report information about the activities of another country or organization[0]
The only real debate is whether or not having a clause tucked away in a EULA that few people read makes it a secret. If Anthropic had a big flashing red banner that said "FYI we automatically flag and review any conversations about illegal things!!" on the front page nobody would call it spying.
[0] https://dictionary.cambridge.org/dictionary/english/spying
A less central case would be when you clearly do know about the activity but you can't quite see the details, like with behavioral ad targeting or something. It feels pretty normal to me to call that spying even if it's disclosed to everyone and certainly happens to everyone, but it's also a less central example of the concept.
You can call it anything you like, but only the legal definitions matter for the legal case.
If you change the situation then yes you can in fact change our responses. The problem is you then are no longer talking about the original situation.
It also bears mentioning that providing a dictionary link to “spying” is pretty patronizing/passive aggressive. On par with sending a basic Wikipedia page. You didn’t even bother to post the definition you want to apply.
The initial comment instead questioned how someone could be accused of making a threat if they did not realize anyone would read their private content. You probably also can not insult someone with a statement you never expected anyone but you will ever read.
You don’t need to presume. Anthropic reported it.
“Spying” as a legal concept has a definition that does not apply here. You could say they were “spying” in the sense that they read someone’s input, but that’s literally what they said they were going to do in the agreement when the person signed up.
So I responded to the question about the case being thrown out for “spying” by trying to show that the word doesn’t apply in the legal sense. If you sign up for a service that says “Hey we’re going to monitor your chats and might report things to the authorities” and then they monitor your chats and report things to the authorities, you should not expect the case to be thrown out for “spying”.
Calling something names doesn't invalidate it. It only invalidates what point you're trying to make.
They get friendly and loose-lipped with the bartender over the span of months. Eventually they let slip that they plan on killing their spouse for a life insurance payout. At first the bartender thinks they're joking, but it becomes evident that there's an actual plan being acted upon and someone's life is very likely in imminent danger.
Does the bartender have a responsibility to go to the police?
Then, you can write anything in an EULA but it is not automatically legal either.
With the obvious IANAL, it doesn't seem to rely on the message be sent to the person being threatened. The specific segment is "in any manner in which it may be viewed by another person".
This may be one of those cases where we get to find out how courts view SaaS platforms.
According to Gemini, "Florida appellate courts have overturned juvenile convictions [based on this law] when the state could not prove the person subjectively intended for the record to be seen."
The prosecutors likely know this and expect it. But there's enough gray area here for them to make the argument, and it's hard to prove malicious prosecution, so they know they'll get away with it. It's just about sending a message to the public - they don't care whether a conviction sticks. Just politics.
Hopefully more of these stories push people towards local models :)
sandbox your ai.
this is exactly what I meant. I am presuming the danger is AI reacting to personal notes that it reads on your computer, like a diary, and you should not allow the tools to have access to those documents.
Any failure to understand what it can access or what it has permission to see from the user's end is presumably not their problem. Regardless of what the user specifically asks of the tool.
Note that the law doesn't forbid the writing of a threat. You have to send it to someone. Had she kept it in a book under her bed, she would not be in trouble. But she sent it to a website/service/LLM portal.
>> It is unlawful for any person to send, post, or transmit, or procure the sending, posting, or transmission of, a writing or other record, including an electronic record, in any manner in which it may be viewed by another person
This is a huge privacy problem that is only going to get worse.
FYI, the use of drafts folders to transmit messages has been used by terrorists. This is likely where CIA director David Petraeus got the idea when he needed a secure way to chat with his mistress.
https://www.findlaw.com/legalblogs/technologist/gen-petraeus...
What if she put it in a locked box before shipping it to herself UPS, and she has the only key?
What if instead of UPS, she hired a moving company to move the locked box?
What if she wrote it electronically in diary.txt, but it was backed up to a cloud provider?
--
I'm guessing there's some sort of "reasonable expectation of privacy" for certain activities. We're going to find out what Florida courts think about this new medium.
Saving is not sending ie passive vs active act.
Does the person have to know (or at least believe) that it will be viewed by another person?
She likely didn't think anyone would view it. Honestly, even as a career software developer I don't think it is unreasonable to think know would would see what she wrote to an AI. I assume most of what I write to an AI is not viewed by any other human, based simply on the quantity of messages sent back and forth to AIs, I would assume a vast majority are not read by another human.
What if she had written this into google docs, and she kept a diary there? That also crosses state lines, and is transmitted to another location.
You can argue from technicalities but they would need to prove intent.