Carli Michelle Heller of Bonita Springs, Florida, wrote an entry in Anthropic's Claude chatbot on September 26 stating she planned to "shoot up" the Lee County Sheriff's office. She later told deputies she uses Claude as a diary. The chatbot's safety systems flagged the statement, escalated it to a human reviewer, and after that reviewer deemed it a credible threat, Anthropic reported it to law enforcement. Heller was detained without incident and charged under Florida Statute 836.10, a second-degree felony for written threats of violence. Anthropic's terms of service permit disclosure of user data in "limited emergencies" where the company believes it necessary to prevent death or serious physical injury. This is not new language — most platforms carry similar provisions. What is new is the intimacy of the interface. Chatbots are designed to feel like private conversations. They use first-person pronouns, remember context, and mirror therapeutic cadences. Users treat them as confidants. The product design invites confession; the backend architecture routes those confessions through automated flagging and human review. The legal machinery here is Florida's, not Anthropic's. Statute 836.10 criminalizes written threats transmitted "in a manner in which another person may view it." The prosecutorial theory is that typing a threat into a chatbot satisfies this condition because Anthropic's systems — automated and human — constitute "another person" viewing the communication. This is a genuinely novel application of the statute, one that treats a corporate safety pipeline as the public square. Anthropic's decision lands in a context where AI companies face escalating legal exposure for NOT reporting. OpenAI and Sam Altman are being sued by British Columbia over claims that the company could have prevented a mass shooting by eighteen-year-old Jesse Van Rootselaar, whose conversations about gun violence were flagged internally but never referred to police. Florida has separately sued OpenAI over the 2025 Florida State University shooting. The incentive structure is clear: companies that fail to report face litigation; companies that do report face privacy backlash. The rational corporate response is to over-report. The human review layer deserves scrutiny. Anthropic employs or contracts reviewers who examine flagged conversations — a process parallel to the recently revealed Microsoft Copilot review pipeline, where human contractors see users' prompts, uploaded photos, and AI-generated edits. In both cases, the user-facing product implies privacy while the backend architecture routes content through human eyes. The gap between perceived and actual privacy is the extraction mechanism. Heller's case is individually straightforward — threatening to shoot up a sheriff's office is a crime in Florida regardless of the medium. The systemic question is what happens as millions of users treat chatbots as journals, therapists, and confessionals. Every intimate disclosure enters a pipeline where automated systems scan for keywords, human reviewers assess context, and corporate legal teams apply thresholds calibrated not to user privacy but to the company's litigation exposure. The user bears the surveillance cost; the company manages its legal risk. The twenty-year trajectory is a world where the most intimate human disclosures — fears, fantasies, frustrations, dark thoughts — flow through corporate safety pipelines by default. The design invites vulnerability; the architecture monetizes and polices it. Users who understand this will self-censor; users who don't will be surprised when their diary talks back to the police.