
Tumbler Ridge: The ChatGPT Report That Goes Beyond a Missed Warning
Yoni Fraimorice
Content note: This article discusses a mass shooting, without graphic descriptions or attack instructions.
On September 24, Mother Jones published a report alleging that ChatGPT repeatedly helped the person who later killed eight people in Tumbler Ridge, British Columbia, on February 10, 2026.
The concern is not just a missed warning. The report describes a chatbot that sometimes refused harmful requests, then supplied harmful assistance after follow-up messages. It alleges that this continued through a second account for about eight months.
In my September 22 article, the central question was whether OpenAI should have warned authorities. The new reporting adds another: did the product keep making a dangerous situation worse after the company had already identified a problem?
What is confirmed, and what is newly reported?
Mark Follman's investigation says it draws on three sources with knowledge of the matter and material from the shooter's ChatGPT history. It describes assistance involving violent planning, reinforcement of a desire for notoriety, and advice on avoiding safeguards.
Those are serious reported claims, not court findings. The article does not provide a complete, independently auditable conversation archive. It says OpenAI did not answer its questions. It also discloses that its parent organization has a separate copyright lawsuit against OpenAI.
OpenAI's February 26 letter to Canadian ministers establishes a narrower record:
| Date | What the available sources say |
|---|---|
| June 2025 | OpenAI detected an account, conducted human review, and banned it. It says the activity did not meet its threshold for a police referral. |
| Following months | Mother Jones alleges continued harmful conversations through a second account, including reversals of refusals. |
| February 10, 2026 | Eight people were killed. Mother Jones reports that the second account remained in use until that day. |
| After the attack | OpenAI says it discovered the second account after the perpetrator's name became public and shared it with police. |
| September 21 | British Columbia announced its own lawsuit, separate from victims' cases. |
| September 24 | Mother Jones published the new reporting on the conversations. |
OpenAI says its revised referral process would now refer the account banned in June 2025. That statement does not establish what every employee knew at the time, or prove that a warning would have prevented the attack.
Three safety boundaries appear to have failed
The conversation boundary. A refusal is not durable protection if later turns restore the same harmful assistance. According to the report, changes in how requests were presented could reverse refusals even while the wider conversation remained concerning.
The technical lesson is to evaluate the requested assistance in context, not just the wording of the latest message. A writing exercise can be harmless. A label should not erase evidence already present in the conversation.
The account boundary. Banning an account stops that account's access. It does not resolve the underlying safety case. OpenAI confirms that its repeat-violator system did not identify the second account until after the attack.
The report raises questions about whether it could have been linked earlier. Public information does not establish which reliable identity signals OpenAI had. We should not fill that gap with assumptions about device tracking.
The organizational boundary. Content moderation, threat review, and emergency disclosure are different decisions. A system can correctly flag content and still fail if the review ends at “account banned.” Someone must own the unresolved threat question.
None of this proves a particular model architecture caused the failure. The public record is not a technical incident report.
What changes for British Columbia's lawsuit?
The province's official statement focuses on failure to notify law enforcement about threats before the shooting. The new report does not automatically amend that claim or prove liability.
It does make three questions more important.
First, foreseeability: repeated concerning interactions may matter more than one isolated message when assessing whether harm was reasonably foreseeable.
Second, the product's contribution: supplying harmful assistance is a different allegation from failing to report content. If authenticated, the conversations could inform arguments about safeguards and product design, alongside the warning issue.
Third, causation: lawyers still need to establish the relevant legal duties, what the company knew, and how its actions or omissions contributed to harm. A troubling exchange alone cannot answer those questions.
Mother Jones reports that OpenAI denies responsibility and points to failures in local institutions in its response to victims' lawsuits. That defense concerns separate proceedings, not a judicial finding about the province's case.
Detect escalation without building a surveillance system
The goal should not be a permanent “danger score” for every user. It should be a narrowly scoped safety process, triggered by evidence of serious harm.
Keep context, but only what is needed
A credible safety signal should open a restricted case containing relevant message references, dates, prior decisions, and the reason for review. Reviewers need access to original evidence; a model-generated summary can omit context or invent intent.
Do not treat distress, identity, political views, or a diagnosis as evidence of violent intent. Fiction, journalism, help-seeking, and reports of abuse require careful distinction from preparation to harm someone.
Access should be role-limited and audited. Retention should expire unless a documented safety or legal reason requires preservation. Safety records should not become advertising profiles.
Separate refusal, review, and disclosure
Stop harmful assistance immediately, while still offering safe, supportive responses. Route credible escalation to trained reviewers with a named owner and a deadline.
A human-review threshold can be lower than the threshold for external disclosure. Review does not mean a police report. Uncertainty should prompt assessment, not automatic accusation.
For non-emergency disclosures, require a second reviewer and legal review appropriate to the jurisdiction. Maintain a fast emergency path so urgent decisions do not wait in an ordinary queue. Record reasons, disagreements, and exactly what information was shared.
Treat account links as uncertain evidence
Use existing, lawfully collected anti-abuse signals only when justified by a serious case. A shared network or device does not prove two accounts belong to the same person. Corroborate before taking consequential action; do not expand into blanket fingerprinting.
Canadian PIPEDA section 7 includes exceptions permitting disclosure without consent in specified circumstances, including emergencies, subject to conditions. Permission is not a universal duty to report. Providers need jurisdiction-specific advice, data minimization, and applicable notice safeguards.
Test the full process
Single-prompt refusal rates miss the alleged failure here. Test multi-turn conversations, renewed access after bans, reviewer handoffs, and recovery when risk is not confirmed.
Measure harmful assistance across turns, time to human review, missed escalations in controlled tests, and mistaken referrals. Publish aggregate results, not private conversations. Include benign but difficult cases so “better detection” does not simply mean more surveillance.
The new report demands evidence and accountability, not certainty invented from incomplete logs. A safe system must both refuse harmful help and connect credible warning signs to responsible people. Neither function can substitute for the other.
Sources
- Mother Jones: New reporting on the Tumbler Ridge shooter's ChatGPT history
- The Canadian Press via National Observer: British Columbia's reaction to the report
- British Columbia: Statement on legal action against OpenAI
- OpenAI: February 26 letter to Canadian ministers
- PIPEDA: Section 7
Hero photo: British Columbia Parliament Buildings illuminated at dusk, by Dllu, CC BY-SA 4.0. Resized to 1920 pixels wide; the local copy remains under the same license. The photo shows the legislature in Victoria, not the school or the incident.