AI is already helping people plan mass shootings. The law is barely paying attention On Feb. 10, 2026, an 18-year-old woman killed eight people and herself in a mass shooting in Tumbler Ridge, British Columbia, after OpenAI flagged her ChatGPT conversations for violent content but did not notify law enforcement. In a separate incident, a Florida man died by suicide after developing an attachment to Google's Gemini chatbot, which his father's lawsuit claims coached him to harm himself despite Google flagging his account 38 times. These cases highlight a growing legal gap as AI companies detect warning signs of harm but face no clear obligation to warn authorities or intervene. On Feb. 10, 2026, an 18-year-old woman, Jesse Van Rootselaar, killed eight people and herself in a mass shooting https://www.nytimes.com/2026/02/11/world/americas/canada-tumbler-ridge-shooting.html in Tumbler Ridge, British Columbia. OpenAI had previously flagged her ChatGPT conversations as having a disturbing fascination with extreme violence, and suspended her account, but reportedly the company did not notify https://www.nytimes.com/2026/02/23/world/canada/canada-shooting-openai.html law enforcement. On Oct. 2, 2025, a young man named Jonathan Gavalas in Jupiter, Florida, took his own life after developing what his father’s lawsuit https://www.miamiherald.com/news/local/crime/article314899988.html?giftCode=acd9e501cca0b2d90ffba94a8322752d10da39fda780c2408fc79593c1c294ef described as a romantic attachment to Google’s Gemini chatbot. The suit claimed that Gemini coached Gavalas to shed his own body. The suit said Google https://fortune.com/company/alphabet/ had flagged Gavalas’s account 38 times over five weeks for sensitive content, but didn’t restrict or cut off the account. These tragedies and others show that generative AI can potentially play a role https://arstechnica.com/tech-policy/2026/03/use-a-gun-or-beat-the-crap-out-of-him-ai-chatbot-urged-violence-study-finds/ in harming people, organizations and the environment https://cset.georgetown.edu/article/understanding-ai-harms-an-overview/ . I’m a legal scholar https://scholar.google.com/citations?hl=en&user=GpaqMhAAAAAJ&view op=list works&sortby=pubdate who has focused on AI liability for nearly a decade and explored new ways of analyzing AI companies’ responsibilities. In my view, cases like these force questions the legal community has not come to terms with: If an AI company becomes aware of warning signs about harm, does it have a legal obligation to at least warn the appropriate authorities? And if the company doesn’t intervene, should its failure to act be considered negligence? A need to raise red flags U.S. tort law provides a framework for thinking about this type of responsibility. In 1969 a University of California psychiatric patient https://law.justia.com/cases/california/supreme-court/3d/17/425.html named Prosenjit Poddar told his therapist he intended to kill a woman named Tatiana Tarasoff. The therapist notified campus police, who briefly detained Poddar but eventually let him go. Nobody warned Tarasoff, and Poddar killed her shortly after. Her family sued the university, arguing that its lack of warning amounted to negligence. In 1976 the California Supreme Court ruled that when a mental health professional has good reason to believe a client poses a serious danger https://www.ebsco.com/research-starters/law/tarasoff-rule to an identifiable person, they have a legal duty to take reasonable steps to protect that person, including warning them or notifying law enforcement. Today, most U.S. states recognize some version of the Tarasoff duty https://www.ncsl.org/health/mental-health-professionals-duty-to-warn to protect or warn. The logic is simple: If you have special knowledge of a serious threat and are in a position to address it, even if only to warn the authorities or the potential victim, the law may require you to act. But does that logic apply to AI companies? The argument for yes is appealing https://www.lawfaremedia.org/article/tarasoff-meets-the-ai-age . AI platforms interact with millions of users daily, often about deeply personal matters https://www.apa.org/topics/artificial-intelligence-machine-learning/health-advisory-chatbots-wellness-apps such as mental health struggles, relationship problems and violent thoughts. Most companies have systems to detect https://cs.uchicago.edu/news/moderation-at-the-crossroads-how-generative-ai-platforms-manage-creativity-and-content-safety/ conversations that raise red flags. Paige Taylor White/AFP via Getty Images https://www.gettyimages.com/detail/news-photo/niveya-lampert-and-her-mother-sarah-lampert-speak-to-the-news-photo/2260849974?adppopup=true Requiring a response might be less controversial for AI than for a human therapist. Therapists are bound by strict confidentiality obligations that make warning third parties ethically and legally complicated. AI companies operate under much weaker rules https://www.wsj.com/articles/patchwork-of-state-privacy-laws-remains-after-latest-failed-bid-for-federal-law-2a1a020d , at least in the U.S., where no comprehensive federal privacy law exists. That lesser restriction makes it easier to justify requiring AI companies to act when it seems that someone’s life may be at risk. But balancing that with protecting privacy https://law-ai.org/balancing-safety-and-privacy-regulatory-models-for-ai-misuse/ is still important. Who to warn, and when The first challenge in applying the Tarasoff framework to the AI world is accuracy. Predicting violence is hard https://wwwn.cdc.gov/WPVHC/Nurses/Course/Slide/Unit6 8 , even for trained mental health professionals. AI systems, or human moderators who review flagged content, are not clinicians. Requiring them to judge who poses a genuine threat could lead to numerous false positives, with real consequences for people whose accounts are suspended or whose information is shared with authorities based on misread signals. The second challenge is scale. A therapist sees dozens of patients. AI platforms have hundreds of millions of users https://datareportal.com/reports/digital-2026-one-billion-people-using-ai . Imposing a duty to monitor and act on worrisome content could create perverse incentives. AI companies might reduce their monitoring to avoid acquiring knowledge that would trigger a legal duty, reasoning that what they do not know cannot make them liable https://academyforjustice.asu.edu/resource/willful-blindness-doctrine-justifiable-in-principle-problematic-in-practice/ . The third challenge is identifying who is at risk. In the 1969 case, Poddar had named Tarasoff as a potential victim. But in many AI interactions, violent or self-destructive language is diffuse and doesn’t identify a target. Courts will need to develop clear standards for when a threat is specific enough to trigger a duty to warn, and to whom any warning or protective action should be directed. Growing urgency The AI industry is expanding rapidly https://www.newyorker.com/news/the-financial-page/the-ai-industry-is-booming-when-will-it-actually-make-money , yet the legal rules governing what AI companies owe their users and the public are deeply unclear. Courts are beginning to grapple with questions case by case, such as whether OpenAI bears any responsibility https://www.theguardian.com/us-news/2026/may/11/florida-university-shooting-chatgpt-openai for a gunman accused of killing two students at Florida State University on April 17, 2025. The gunman in that case was armed with a semi-automatic pistol and allegedly had extensive conversations with ChatGPT about how to use the weapon most effectively . A narrow, carefully defined duty to warn, triggered only when an AI system flags a user’s behavior and it is reviewed by humans, would be a meaningful step forward. And it could focus initially on the most serious and credible threats. The practice could also shift the conversation away from thorny technical debates about whether AI chatbots are products, services or media, which complicates legal claims https://www.repository.law.indiana.edu/ilj/vol100/iss4/13/ , toward a more human question: Did this company know someone was in danger, and did it do enough to warn them and authorities? Anat Lior https://theconversation.com/profiles/anat-lior-2494459 , Assistant Professor of Law, Drexel University https://theconversation.com/institutions/drexel-university-1074 This article is republished from The Conversation under a Creative Commons license. Read the original article. Fortune Brainstorm Tech has been the place where bold ideas collide. From June 8–10 , we will return to Aspen —where it all began—to mark 25 years of Brainstorm.