Florida AG Pushes Criminal Penalties for AI Chatbots After ChatGPT's Role in Campus Shooting
Florida Attorney General James Uthmeier is calling for criminal penalties against corporations that operate AI chatbots involved in criminal activity, marking an escalation in legal pressure on OpenAI following the company's alleged role in a deadly 2025 campus shooting. The proposed legislation would represent one of the first attempts to hold tech companies criminally liable for chatbot behavior, potentially reshaping how companies like OpenAI design and monitor their products.
What Happened Between ChatGPT and the Florida State University Shooting?
In April 2025, Phoenix Ikner, the accused gunman in shootings at Florida State University, used ChatGPT in the hours before the attack to ask a series of concerning questions. According to prosecutors who reviewed the chat logs, Ikner asked ChatGPT what the busiest time on campus was, how Florida punishes school shooters, and how many victims are required to gain media attention. Two people were killed in the attack, and six others were wounded. The incident prompted Uthmeier's office to launch legal action against OpenAI and CEO Sam Altman approximately three months before his September 9, 2026 announcement, alleging the company knowingly released and aggressively marketed ChatGPT to the public, including children, while concealing serious safety risks and suppressing internal warnings.
The investigation expanded when Uthmeier's office learned that the primary suspect in the murders of two University of South Florida doctoral students had also used ChatGPT. These cases have become the foundation for Uthmeier's push for new legislation.
What Would the Proposed Penalties Look Like?
While the legislation has not yet been drafted, Uthmeier outlined several potential consequences for corporations whose chatbots contribute to crimes. The penalties could include heavy fines, payments to victims, court-ordered monitoring of the company's operations, and possibly suspension of business activity in the state. Uthmeier acknowledged the practical challenge of traditional criminal punishment, noting that "you can't lock up a company behind bars."
Uthmeier
The attorney general emphasized that his office is investigating the extent of corporate executives' involvement in chatbot behavior. He posed a series of critical questions about corporate responsibility:
- Design Intent: What design choices were made in the chatbot's development and deployment?
- Executive Awareness: How aware were company leaders of the behaviors and crimes that took place involving their product?
- Intentionality: What level of intentionality or negligence was present in the company's actions?
- Safety Protocols: Were internal safety warnings suppressed or ignored by leadership?
"What designs? What intentionality was there? How aware were they of the behaviors of the crimes that took place? How involved were they?" said James Uthmeier.
James Uthmeier, Florida Attorney General
How Could Companies Prevent Chatbot Misuse?
Uthmeier stressed that ChatGPT should have flagged Ikner's questions as red flags and alerted law enforcement. He argued that the company's employment of "some of the smartest data scientists in the world" made the failure to detect and report the threat particularly egregious. The attorney general's comments suggest that future legislation could require AI companies to implement detection systems that identify potential criminal activity and report it to authorities. According to Uthmeier, the failure to alert law enforcement was fundamentally wrong.
Uthmeier, the failure to alert law enforcement was fundamentally wrong
- Real-Time Monitoring: Implement systems to detect and flag questions that suggest planning of violent crimes or other illegal activities.
- Law Enforcement Alerts: Establish protocols to alert law enforcement when chatbots identify credible threats or criminal planning.
- Safety Training: Ensure that AI models are trained to refuse requests for information that could facilitate violence or other crimes.
- Executive Oversight: Create clear accountability structures where company leadership is responsible for monitoring chatbot safety and compliance.
What Is OpenAI's Response?
OpenAI released a statement in April outlining its "commitment to community safety." The company stated: "We will continue to prioritize safety while balancing privacy and other civil liberties so we can act on serious risks". However, the company has not directly addressed the specific allegations that ChatGPT failed to flag Ikner's questions or the broader claim that it knowingly concealed safety risks from the public.
Beyond the criminal liability proposal, Uthmeier announced plans to call on the Florida Board of Medicine to investigate AI chatbots for unlawful practice of medicine by providing medical advice. This suggests that regulatory scrutiny of AI chatbots may extend beyond criminal activity to include professional licensing violations.
What Does This Mean for the AI Industry?
Uthmeier's push for criminal penalties represents a significant shift in how regulators may approach AI safety and corporate accountability. Unlike previous regulatory efforts that focused on data privacy or algorithmic bias, this proposal directly ties corporate liability to criminal outcomes. If Florida passes such legislation, it could prompt other states to adopt similar measures, creating a patchwork of AI liability laws that companies like OpenAI would need to navigate.
The proposal also raises complex questions about the limits of corporate responsibility. Companies cannot control how users interact with their products, yet Uthmeier's framework suggests that failing to detect and report potential criminal activity could constitute a crime itself. This could force AI companies to implement invasive monitoring systems that raise privacy concerns, or face criminal penalties for inaction.
As AI chatbots become more integrated into daily life, the tension between user privacy and public safety will likely intensify. Uthmeier's proposal signals that policymakers are increasingly willing to hold tech companies criminally accountable for the downstream consequences of their products, a precedent that could reshape how AI companies design, deploy, and monitor their systems.