← Back to Blog
He Told ChatGPT His Most Dangerous Secret. Two Months Later, the FBI Found Him.

He Told ChatGPT His Most Dangerous Secret. Two Months Later, the FBI Found Him.

In March 2026, 25-year-old Darren Zhou was reeling from the end of a six-month relationship. He lived in Florida, worked as a financial analyst at Goldman Sachs, had graduated near the top of his class, and had no criminal record. From the outside, he still had the kind of life people spend years building. After his girlfriend left, however, he began opening ChatGPT again and again to talk about his jealousy, his anger, and how he might win her back.

At first, the conversations looked like the kind of late-night unloading many people do after a breakup. He told ChatGPT what his ex-girlfriend liked, where she spent her time, which men made him jealous, and whether she might already be seeing someone else. Friends get tired, family members judge, and therapy can be expensive. An AI is always there and never looks shocked, so it is easy to forget that we are using a tool and start talking as if we are confiding in someone we trust.

What Zhou said next was no ordinary emotional spiral. According to court records obtained by The Palm Beach Post, he told ChatGPT that he intended to kill his ex-girlfriend by the end of the month. He described weapons, locations, and possible steps. Over weeks of conversations, he repeatedly rehearsed scenarios involving kidnapping, rape, murder, and suicide, eventually extending his threats to members of her family.

His behavior outside ChatGPT had also moved beyond fantasy. His ex-girlfriend ended the relationship because of his jealousy, controlling behavior, and instability, and she was too frightened to do it in person. When she blocked his phone number and social accounts, he used new numbers to keep contacting her with harassment, sexual humiliation, and threats. At one point, while she was at a gym, she received a message containing only the gym's name. He knew where she was, and he wanted her to know that he was watching.

OpenAI's systems detected the conversations and escalated them for human review. The company reported Zhou to the FBI, which passed roughly two months of chat logs to local law enforcement. A deputy concluded that the messages showed an ongoing pattern of planning and rehearsal, not a single outburst made in anger. Police checked on the victim, opened an investigation using both the ChatGPT logs and the messages she had saved, and arrested Zhou in May. He later pleaded guilty to aggravated stalking, written threats to kill, and unlawful use of a communications device. He received eight years of probation, including electronic monitoring for the first two years.

If the story ended there, it would be an easy piece of technology news: an AI system detected a danger, a company called the authorities, and a young woman may have escaped serious harm. I do not believe privacy should require her to gamble with her life, and she had no obligation to assume that her stalker was "just talking." In this particular case, OpenAI probably made the right call.

The harder question begins after the right call has been made. When we all approve because the system caught an obvious threat, are we also accepting that a private company may inspect billions of conversations, decide who has crossed an invisible line, and pass that person's identity and words to the state? A good outcome does not automatically make a power legitimate. The most dangerous surveillance systems often begin with a case that no decent person wants to defend.

How a Chat Box Becomes an Alarm System

In my previous article, I wrote about another AI user's material ending up in the hands of the FBI. A businessman accused of siphoning more than $150 million from a public company had used Claude to create roughly 31 defense documents. Many readers assumed Anthropic had reported him. In fact, the FBI found the files while searching his devices. Nobody needed to betray him because he had already stored the material on his own computer.

The Zhou case is the mirror image. Law enforcement did not begin with a search warrant and later discover AI content on a device. OpenAI identified the conversation, assessed the risk, and sent information to the FBI on its own initiative. Both paths can end with chat records in an investigation, but the second turns the platform into more than a warehouse that holds data. It gives the platform the role of an early-warning institution.

OpenAI has described this process publicly. The first layer is automated monitoring. Classifiers, reasoning models, hash matching, blocklists, and other tools search activity at scale for signals of possible real-world harm. The second layer is human review. Trained staff can examine flagged content, the surrounding conversation, and patterns of behavior over time. When the company concludes that someone may pose an imminent and credible threat of harm to another person, it notifies law enforcement.

That is far more careful than having a model automatically call the police whenever it sees a disturbing sentence. It still depends, however, on a judgment that technology cannot settle: what counts as imminent, and what makes a threat credible? The same words might be part of a criminal rehearsal, a novel, case research, role-play, a quotation of someone else's threat, or a mental health crisis with no intent to act. OpenAI has said that it may refer a case even when a user has not clearly stated the target, means, and timing, as long as other signals suggest a credible and imminent danger.

Automated detection faces an unavoidable tradeoff. Set the threshold too high and the system misses people who are preparing to act. Lower it to catch more genuine threats and more innocent conversations enter the review queue. Human reviewers then need more context, longer chat histories, and more account activity to avoid mistakes. A system that sees too little will misjudge people, but the way it tries to make fewer mistakes is by seeing more.

Want more practical breakdowns?

AI, engineering, and experiments. One or two useful emails a month.

No spam. Unsubscribe anytime.

Accuracy is only part of the problem. The same company detects the signal, interprets it, and decides whether to report it. Users generally do not know when their conversations enter human review, how much of their account a reviewer can see, or what the platform ultimately disclosed. The public does not know how many chats are flagged each year, how many users are referred, or how many reports lead nowhere. OpenAI's privacy policy also leaves the company broad discretion to monitor content and share user data with governments or other parties to enforce its policies, prevent illegal activity, protect safety, or limit legal liability.

Clicking "Agree" when opening an account does not settle whether this power is legitimate. Nobody negotiates privacy terms with a company that controls the infrastructure, and nobody rereads those terms before opening up at two in the morning. The real arrangement is simpler: a software company has become investigator, adjudicator, and informant. When it gets the judgment wrong, the person on the other side of the screen pays the price.

What Happens the First Time the System Gets It Wrong

We do not have to imagine what a false alarm can do. Google has already given us a closely related case, and its system began with an equally unobjectionable goal: finding child sexual abuse material and protecting children who are being harmed.

In 2021, a father identified in the press as Mark noticed severe swelling in his toddler's groin. During the pandemic, a telehealth provider asked him to photograph the affected area so a doctor could evaluate it. The doctor reviewed the images, prescribed antibiotics, and the child quickly recovered. The photos also synced automatically to Google Photos, where they entered a review process Mark barely knew existed.

Google uses hashes of confirmed illegal material to identify identical or similar files, along with artificial intelligence to detect previously unseen material, followed by human review. U.S. law requires providers that become aware of apparent child sexual abuse material to report it to the National Center for Missing & Exploited Children. The problem was not the goal. The system could see an image of a child's body, but it could not see the clinician's request, the father's fear, or the infection being treated.

Google classified the photos as suspected child sexual abuse material, disabled Mark's Gmail, Google Photos, Google Fi, and other connected services, and triggered a San Francisco police investigation. He lost years of email, contacts, family photographs, and his phone number. Police later reviewed the evidence and found no crime, yet Google still refused to restore his account.

Google says its false-positive rate is extremely low and that human review plays a critical role. In the first half of 2022 alone, the company submitted more than one million reports and suspended about 270,000 accounts. Those numbers suggest that the system can uncover a great deal of genuine abuse. They also show how many lives can be affected by an internal decision. A low error rate offers little comfort to the innocent parent who has already been investigated as a criminal.

This does not mean Google should stop fighting child abuse, or that OpenAI should ignore a concrete murder plan. It means that a righteous goal does not make a monitoring system infallible, and it does not give the company operating that system unlimited moral authority. Today the easy case is a man who is already stalking a woman in real life while repeatedly describing how he might kill her. Tomorrow's review queue may contain a crime novelist, a journalist investigating an extremist group, a domestic abuse survivor discussing self-defense, or someone who writes something frightening during a breakdown but has no intention of acting.

The stakes become even higher when the same AI service operates around the world. In Florida, a detailed plan to kill a specific person is easy to recognize as a public-safety threat. Elsewhere, a government may use the word "dangerous" for a protest, evidence of police abuse, abortion advice, a person's sexual orientation, or criticism of the ruling party. Once the infrastructure exists to monitor conversations, identify users, retain records, and transfer data, expanding its use may not require a new system. It may take only a policy change, a new law, or pressure from a government.

Taking Back the Choice

My objection is not that someone protected Zhou's former girlfriend. It is that private companies should not acquire a general power to monitor intimate conversations according to internal rules, without clear limits or outside scrutiny. If society wants an emergency exception for imminent threats to life, that line should be drawn in public. Reports should require human review, disclose only the minimum data needed to prevent harm, and face independent audits. Platforms should also publish anonymized figures on automated flags, human reviews, law-enforcement referrals, and false alarms, so the public can see how this power is being used.

Until those safeguards exist, we can change how we use AI. Everyday writing, translation, and general questions can remain in the cloud, but company secrets, medical records, legal problems, intimate relationships, and political activity should not be uploaded intact. Remove names, addresses, employers, and project identifiers. Give the model only the information it actually needs. A feature called "temporary chat" may reduce some forms of retention, but it does not mean the conversation never passed through the platform's safety systems.

If disclosure could change your career, freedom, or family, the safest option remains an open-weight model running locally. The model and chat interface should operate on a device you control, with logs, telemetry, crash uploads, and automatic cloud backups turned off, and with the device and local database encrypted. Otherwise the model may be local while the conversation quietly syncs to iCloud, Google Drive, or OneDrive. The secret has not stayed private; it has merely moved to a different server.

Self-hosting is also more than choosing where the model runs. Put a model on a rented cloud server and the cloud provider still controls the hardware and network. The chat interface, vector database, monitoring tools, and backup system may all retain copies. Genuine self-hosting means controlling the full data path: who controls the compute, who can read the logs, whether data leaves the device, where backups live, and what remains after the system is shut down.

I also want to make one recommendation unambiguous. If you are worried about censorship, investigation, or political risk in your own country, do not use an AI provider under that country's direct jurisdiction for sensitive material. Choose a service with legal distance from the state you are worried about, so local authorities cannot simply issue an order and quickly obtain your identity and full conversation history. Do not judge this only by the flag on the company's website. Look at the entity named in your contract, where the servers are located, and whether the provider has employees, subsidiaries, or assets your government can compel.

A foreign provider does not guarantee secrecy. It answers to the laws where it operates, governments cooperate across borders, and your own devices may still be searched through lawful process. Legal distance creates friction and spreads risk; it does not provide immunity. Still, forcing a data request to cross another legal system is a meaningful layer of protection. Run sensitive work locally whenever possible. When you must use the cloud, do not concentrate your most private information in a domestic provider, a single company, or one jurisdiction.

None of this is advice for people trying to hide plans to hurt someone. Most people who need privacy are not planning crimes. They are building a company, facing an illness, navigating a relationship, seeking legal help, or living somewhere that punishes honest speech. Protecting privacy is not the same as protecting crime. It protects an ordinary person's ability to think, ask, and work without first submitting every private thought to a company's risk system.

The Darren Zhou case shows AI monitoring at its best: it may have protected someone before a threat became an act. Mark's experience shows the part we prefer not to see: the same well-intentioned logic can push an innocent person into a police investigation when the system lacks context. We do not have to abandon the first lesson because we fear the second, but we should not celebrate the first so loudly that we stop asking where the power ends.

The future of AI should not force us to choose between extraordinary capability and a private inner life. Open weights, local inference, enforceable data minimization, and the freedom to choose across jurisdictions make another future possible. We can still ask AI for help without surrendering our entire lives in return. An AI worthy of trust will be powerful enough to help us and restrained enough to leave its memory, its boundaries, and the final decision in our hands.

New ideas, straight to your inbox.

AI, engineering, and experiments. One or two useful emails a month.

No spam. Unsubscribe anytime.