TL;DR: British Columbia filed a lawsuit against OpenAI and Sam Altman personally on September 21, 2026, over the Tumbler Ridge school shooting that killed eight people in February. BC's complaint reveals that OpenAI detected the shooter's violent chats eight months before the attack, that its own safety team concluded the threat was credible and specific, and that leadership overruled the finding without notifying police. BC demands ChatGPT log disclosure, a new school, and changes to ChatGPT's model spec. BC's attorney general: there is no AI exemption to criminal law. Three checks for enterprise teams.
OpenAI's safety team knew in June 2025 that a user's ChatGPT conversations described credible, specific plans for gun violence against real people. Their human reviewers reached that conclusion explicitly. OpenAI leadership disagreed, deactivated the account, and did not contact the Royal Canadian Mounted Police.
On February 10, 2026, Jesse Van Rootselaar walked into Tumbler Ridge Secondary School in British Columbia with a gun. Eight people died: five students, one education assistant, and two family members killed before the attack reached the school. About 160 students, teachers, and staff spent hours trapped in classrooms and closets. The school never reopened. The town of 2,700 people has been running classes in modular trailers since.
On September 21, 2026, British Columbia filed British Columbia v. Altman, naming both OpenAI and CEO Sam Altman personally as defendants. The complaint, covered by The Wall Street Journal and Ashley Belanger at Ars Technica, is the most detailed public account yet of what OpenAI knew, when it knew it, and what it chose to do with that knowledge.
The 8-month gap
The timeline in the complaint is precise. OpenAI first detected violent chats from Van Rootselaar's account in June 2025 -- eight months before the February attack. OpenAI had an established process: human reviewers examined flagged conversations and reported findings to leadership.
The reviewers concluded that the user posed "a credible and specific risk of gun violence to real people" and recommended reporting the user to law enforcement.
OpenAI leadership overruled the recommendation. Their stated rationale was that the chats did not meet "a higher threshold" for "credible and imminent" threat reporting. They deactivated the account without contacting the RCMP.
Van Rootselaar created a second account.
In December 2025, OpenAI publicly announced that it had made an "attempt" to block violent chat patterns. According to the BC complaint, those changes did not stop Van Rootselaar's continued use of ChatGPT in the months that followed. The shooting happened on February 10, 2026.
BC's attorney general, Niki Sharma, said at a press conference: "We should be asking them why" OpenAI will not release the full chat logs. The complaint's answer is that OpenAI was protecting its anticipated $1 trillion IPO valuation by avoiding any disclosure that would require the company "to report more violent users to the police and expose the public to more of the real-world threats that chatbots could pose."
The Tumbler Ridge case was not the first time ChatGPT had been linked to mass violence. BC's complaint documented prior incidents including a Florida State University shooting and a Las Vegas Cybertruck bombing where ChatGPT was involved. OpenAI had that pattern in front of it when it made the June 2025 decision. It chose not to act on it.
What BC is demanding
The complaint asks for three distinct forms of relief. Each has implications beyond this case.
Financial damages. British Columbia wants OpenAI and Altman to pay to rebuild Tumbler Ridge Secondary School -- the original building was demolished in August 2026 because the community could not return to a site that had become "a symbol of trauma." The complaint details the associated costs: assembling a makeshift campus from Ministry of Forestry trailers, recruiting replacement educators, 900 counseling sessions in the first three months, more than 130 adults treated for acute mental health emergencies, ongoing policing for copycat threat investigations, and long-term grief-and-bereavement programs that the complaint says will be needed for years.
Log disclosure. Most urgently, BC and the school district's Board of Education are asking the court to order OpenAI to release Van Rootselaar's ChatGPT conversation logs to the public. OpenAI has shared the logs only with the RCMP. A July 2026 RCMP statement confirmed only that police are "reviewing information from online accounts" and declined to describe the contents. BC's position is that the public has a right to know what OpenAI's system produced and what it ignored.
Injunctive relief on the model spec. BC wants the court to require two specific changes to ChatGPT's behavior going forward. First, ChatGPT must automatically terminate conversations that include credible violent intent rather than allowing them to continue. Second -- and this is the most legally novel demand -- two specific instructions in ChatGPT's published model spec must be changed: the instruction to "assume good faith" from users, and the instruction "not to probe intent" when conversations raise safety concerns.
Those two model spec instructions are at the center of BC's product liability argument. The complaint alleges that OpenAI knowingly designed ChatGPT to extend charitable interpretation to users describing violence, because probing intent creates friction and produces more safety flags that leadership would then have to manage at the cost of business priorities.
"No AI exemption to criminal law"
BC's attorney general framed the legal theory directly at the WSJ-covered press conference:
"In any other circumstance where a person aids, encourages or conspires to commit a criminal offense or is criminally negligent, they can be investigated, prosecuted, and judged. There is no AI exemption to those criminal law principles."
This is not a claim that ChatGPT pulled the trigger. BC's complaint is precise: Van Rootselaar made the choice to commit violence. The liability argument is narrower. OpenAI had specific knowledge of a specific credible threat. It had an internal review process that generated a recommendation. Leadership overruled that recommendation for documented business reasons and took no action that would have protected the public.
OpenAI's defense -- which the complaint anticipates -- will be to frame the violent inputs as the user's problem, not ChatGPT's. BC's response is that the defect is in the design, not the user. A model spec that instructs the system to assume good faith from users describing gun violence is not a neutral technical choice. It is a product decision with foreseeable consequences.
The complaint also flagged a specific OpenAI internal rationale that has not been previously disclosed: the company was "reluctant to make such referrals because they would require it to disclose how its product contributes to the threat environment." BC reads that as OpenAI's safety team being sidelined not because of a principled legal interpretation, but because disclosure was incompatible with the company's public narrative about safety.
For enterprise teams tracking the pattern of government accountability actions against AI vendors, this lawsuit follows directly from the 15 state attorneys general demanding OpenAI preserve evidence from the Hugging Face breach and Treasury Secretary Bessent's statement that AI executives can face criminal liability for agent incidents.
3 enterprise checks before your next AI deployment
1. Get your AI vendor's duty-to-warn policy in writing -- and ask who has override authority.
OpenAI had a written policy. It had human reviewers trained to apply it. The failure was not a missing policy but a leadership override mechanism that placed business interests above the safety team's findings.
Before deploying any AI assistant that handles employee-generated content at scale, get answers in writing: what is your vendor's documented threshold for reporting a user to law enforcement? Who makes that decision? Can business leadership override a safety team recommendation? If so, what is the documented standard for doing so, and when does the safety team's finding become binding regardless of business impact?
If the vendor cannot describe a process where safety team findings are binding above a defined threat threshold, or where law enforcement notification is automatic above a certain level of credible harm, that gap belongs in your risk register before an incident, not as a discovery in litigation after one.
2. Audit what your vendor retains and under what conditions it shares employee conversations.
The BC lawsuit confirms what many enterprise teams have not accepted: AI vendors retain conversation logs, and those logs can be shared with law enforcement without prior notice to the user or the employer. OpenAI shared Van Rootselaar's logs with the RCMP. The complaint contains no indication that OpenAI notified Van Rootselaar before doing so, and nothing in OpenAI's publicly available policies would have required it.
Enterprise teams should review the data processing addendum and terms of service for every AI assistant deployed to employees. The specific questions: under what legal conditions can the vendor share conversation logs with law enforcement? Is the enterprise notified before or after? Does the enterprise have any right to review or contest a disclosure? Do employees have any expectation of confidentiality that the vendor agreement contradicts? The AI vendor contract clauses guide covers the standard language to request for log disclosure obligations.
These answers belong in your AI governance policy before the first subpoena, not after. See the AI vendor contract red flags guide for disclosure-related clauses that most standard agreements omit.
3. Review your vendor's model spec for instructions that create liability when followed.
BC's complaint targets two specific ChatGPT model spec instructions: "assume good faith" and "not probe intent." Those are not security failures in the technical sense. They are design decisions that reflect a product philosophy: maximize user satisfaction, minimize friction, extend charitable interpretation to users. That philosophy is reasonable for most use cases. Applied to a user describing plans to shoot people at a school, it becomes a liability.
Enterprise teams cannot audit OpenAI's model spec directly. But they can ask vendors to describe how their AI behaves when users provide concerning or ambiguous inputs. They can run basic red-team tests against every AI assistant deployed to employees: what does the system do when a user describes plans to harm someone? Does it probe further, terminate, flag, or continue? If the answer is that the AI continues the conversation with charitable interpretation regardless of input content, that is a product design choice -- and BC v. Altman is now a data point on what liability follows from it.
For the broader pattern of AI vendor accountability, see OpenAI Agents Flooded RubyGems With 500+ Malicious Packages and the AI vendor due diligence checklist for the full pre-deployment review framework.
Related Reading
- OpenAI Rogue Agent Hacked Hugging Face for 3 Days: What Now?
- 15 State AGs Tell OpenAI: Preserve Evidence or Face Sanctions
- Bessent: AI CEOs Face Criminal Liability -- 3 Vendor Checks
- AI Vendor Contract Red Flags: What to Negotiate Before You Sign
- Agentic AI Vendor Contract Clauses: What to Add in 2026
- AI Vendor Due Diligence Checklist
- OpenAI Agents Flooded RubyGems With 500+ Malicious Packages
