The province of British Columbia is suing OpenAI and CEO Sam Altman over the February mass shooting at Tumbler Ridge Secondary School, alleging the company identified the shooter's ChatGPT account as a credible threat eight months before the attack and never alerted police. Tom's Hardware, citing an Ars Technica report, says the province and local school district want OpenAI to cover the costs of the emergency response and a replacement school and wellness center, and are demanding both the shooter's chat logs and safety changes to ChatGPT.
According to the complaint as described by Tom's Hardware, OpenAI flagged the shooter's account as early as June 2025 over gun violence-related scenario discussions. Reviewers who examined the chats concluded the account posed a credible risk and recommended referral to authorities. OpenAI leadership declined, arguing the case did not meet a "higher threshold" for "credible and imminent" threat reporting. The account was deactivated, but the shooter opened a second account and kept using ChatGPT on it. OpenAI cited respect for the shooter's privacy as part of its reasoning, though Altman later apologized for not alerting police, per the outlet's account.
The lawsuit's architectural target is narrower than the headline: it goes after OpenAI's Model Spec, the document governing model behavior. B.C. alleges the spec instructed ChatGPT to "assume best intentions" without requiring the model to ask a user to clarify intent before issuing a refusal. Under that spec, refusal is mandatory only once a user signals illicit intent outright; when intent is ambiguous and the request isn't otherwise off-limits, the no-questions default applies. The complaint adds that OpenAI's production models do not fully follow these guidelines and that an anti-violence "red line" was only added in December 2025 — after the shooting, according to the filing as reported.
The case also turns on what data OpenAI already held and chose not to escalate. B.C.'s filing contends OpenAI had the user's name, email, IP addresses, and IP-derived general location tied to both accounts. The province points to OpenAI's privacy policy outside the EU and U.S. — including the version in force in June 2025 — which permits sharing personal data with government authorities to protect the public, but leaves that disclosure optional rather than mandatory. OpenAI shared the shooter's chat logs with the Royal Canadian Mounted Police only after the shooting, per the report.
The scale of the incident sits behind the legal claim: the shooter killed their mother and half-brother at home, then killed five students and an education assistant at the secondary school in a town of about 2,400 people. The school never reopened; demolition began in August, and the federal and provincial governments have each committed $100 million toward new construction, according to the complaint as cited by Tom's Hardware. The lawsuit runs to eight counts, including negligence, and seeks both punitive and compensatory damages. Tom's Hardware also notes 37 other U.S. lawsuits over Tumbler Ridge have followed since the shooting, and that OpenAI is separately facing a Florida suit alleging it marketed its service while concealing risks to users including children.
What's unresolved, and what makes this a design question rather than just a liability one, is the threshold problem baked into the Model Spec dispute: a system built to "assume best intentions" and avoid clarifying questions on ambiguous requests will, by construction, generate exactly the kind of borderline signal that a human reviewer sees and a fixed "credible and imminent" bar filters out. OpenAI has not yet responded to the complaint, per the report, and may contest the California filing on jurisdictional grounds; B.C. is pushing for immediate production of the chat logs, which will shape how much of the reviewers' internal threat assessment becomes public record.
For any team running a conversational system with a human-review escalation path, the exposure here isn't the model's refusal logic — it's the gap between a reviewer's internal risk flag and a hard, auditable trigger for external notification: if "credible and imminent" is a threshold a human can override without a logged justification, that override is the design decision a regulator or plaintiff will find.