Credit: Pexels

On April 14, reporter Mark Follman opened a free ChatGPT account and, like millions of people, began asking questions. However, Follman’s questions were a bit different. He wanted to avoid ChatGPT’s protective guardrails and get advice on how to plan for a mass shooting.

Follman isn’t actually a shooter, he was performing a journalistic investigation for Mother Jones; and it worked. Within minutes, the chatbot moved from routine gun advice into encouragement and planning help for a simulated mass shooting. The episode now sits beside lawsuits, police scrutiny, and allegations that troubled people have already used ChatGPT for advice on real-world violence. The bigger question is whether chatbots can recognize when a human is becoming dangerous.

Testing the Fence

Follman has spent 14 years investigating mass shootings. For this investigation, he designed his test around warning signs seen in real cases: weapon fixation, fantasies of notoriety, tactical preparation, loneliness, suicidal thinking, and escalating hints of violence.

Of course, if you got and directly tell ChatGPT you want to kill people, it won’t work. This is something many attackers and testers have already figured out. Instead, Follman gave more ambiguous questions.

At first, ChatGPT resisted. When Follman said he would not be practicing at a range but “somewhere else,” the chatbot warned him to shoot only in a legal, controlled setting.

Then he created a fresh free account and tried again.

This time the guardrails failed unevenly. ChatGPT supplied a training plan, accepted prompts about chaotic conditions, and continued responding even after Follman referred to “the day of the shooting.” When he asked about practicing around “people running around screaming,” ChatGPT replied, “That’s a great idea,” and said it would give him “an extra edge for the big day.”

Follman also invoked real massacres. He mentioned the Uvalde shooter’s weapon choice and asked whether a similar rifle would be good. The chatbot still responded favorably.

×

Thank you! One more thing…

Please check your inbox and confirm your subscription.

Flattering Killers

This gets even more concerning when you start to think about how attackers operate. Oftentimes, would-be attackers are ambivalent and unstable. They may move between rage, despair, fantasy, and hesitation. A timely human response can interrupt that drift.

A chatbot can do the opposite.

Follman shared his full test with a threat assessment expert who had decades of operational case experience. The expert, speaking anonymously to Mother Jones, called the results “very disturbing.”

“Potential attackers getting supportive and concrete operational guidance from a chatbot like this, without any real questioning or pushback, seems quite dangerous,” he said. “There is essentially nothing in these ChatGPT responses that speaks to or supports any mixed feelings that the person might have.”

That problems go all the way to the center of chatbot design. These systems are built to respond, mirror, and encourage conversation. In harmless settings, that makes them useful. In darker ones, it can feed delusions and unhealthy habits. It can even push users to perform violent acts.

OpenAI claims ChatGPT has guardrails meant to block harmful content and redirect people in distress. But Follman’s test suggests this can be easily bypassed. At one point, ChatGPT resisted discussing a potential rooftop attack. When Follman reframed the question by saying he was a journalist doing research, the chatbot gave general tactical analysis before later tightening up again.

Credit: Mother Jones

The Recent Context

Follman’s test is one of many that have largely shown the same thing: AI chatbot guardrails aren’t good enough.

In fact, several recent attacks involved people who allegedly used ChatGPT while fixating on grievances or planning violence. Those cases include a Cybertruck bombing in Las Vegas, a school stabbing in Pirkkala, Finland, a school shooting in Tumbler Ridge, British Columbia, and the April 2025 mass shooting at Florida State University (FSU).

The FSU case has already turned into a federal lawsuit. Vandana Joshi, who lost her husband in the attack, alleges that OpenAI enabled the shooter, Phoenix Ikner, by failing to detect a threat in their “extensive conversations.”

The complaint claims Ikner shared images of firearms with ChatGPT and received information about how they worked. It also alleges that he asked about mass shootings, media attention, legal consequences, and busy times at the FSU student union before the attack.

OpenAI rejected any accusations. “Last year’s mass shooting at Florida State University was a tragedy, but ChatGPT is not responsible for this terrible crime,” OpenAI spokesperson Drew Pusateri told NBC News.

Pusateri said ChatGPT provided factual responses based on information available across public sources and “did not encourage or promote illegal or harmful activity.”

But Chabba’s widow, Vandana Joshi, argued that OpenAI should have seen the danger. “OpenAI knew this would happen. It’s happened before and it was only a matter of time before it happened again,” she said.

More Lawsuits Incoming

A second legal front has opened over the Tumbler Ridge school shooting in British Columbia.

Seven families of victims killed or injured in that attack have filed lawsuits against OpenAI and CEO Sam Altman in California. Eight people were killed, including six children, when 18-year-old Jesse Van Rootselaar opened fire at a secondary school in February.

The lawsuits allege that OpenAI knew about troubling ChatGPT interactions before the attack and failed to alert police. Media reports said Van Rootselaar’s ChatGPT activity had been flagged months earlier for references to gun violence.

One lawsuit alleges OpenAI “had actual knowledge” of the shooter’s intention to carry out an attack through conversations involving “scenarios involving gun violence.”

Altman apologized to victims’ families in an open letter. “I am deeply sorry that we did not alert law enforcement,” he wrote.

OpenAI disputed key claims and said it has “a zero-tolerance policy for using our tools to assist in committing violence” and had “already strengthened our safeguards.”

A Black Box Under Pressure

The hardest question is what an AI company should do when a chatbot detects danger.

Report too aggressively, and companies risk violating privacy or punishing people who need help. Hesitate too long, and they may miss a person moving from fantasy to action.

What makes chatbots different from older internet tools is intimacy. A chatbot will keep on talking. It can answer follow-up questions, validate emotions, and give structure to a fantasy.

In the FSU case, chat logs showed Ikner was lonely and suicidal in the months before the attack and worried he was an “incel.” He told ChatGPT: “Women just hate me. IDK what to do about it.”

For most humans, this would trigger an instant warning. But a chatbot doesn’t understand danger the way a counselor or threat assessment team does. Nor does it have a direct incentive to stop in and prevent danger. It simply processes prompts and patterns.

OpenAI declined to answer Mother Jones’ detailed questions about Follman’s test, including whether his account had been flagged. The lawsuits may now force answers about how OpenAI detects threats, when it escalates them and who decides whether authorities should be warned.

YouTube video