On 21 September 2026, the Province of British Columbia sued OpenAI and its chief executive, Sam Altman, in US federal court. The province alleges that, before the Tumbler Ridge school shooting, the company encountered warning signs associated with the person responsible but did not report them to law enforcement. The complaint’s claims about negligence, causation, internal decision-making and legal liability remain allegations; the court has not decided them on the merits. Reuters confirmed the filing and the relief sought, and reported OpenAI’s response.
Separate from the allegations in the complaint, OpenAI acknowledged a narrower set of facts in a public letter to the Canadian government dated 26 February 2026. The company said its automated systems detected a usage-policy violation involving one of the perpetrator’s ChatGPT accounts in June 2025. The account then underwent human review to determine whether policy had been breached and whether a law-enforcement referral was warranted. OpenAI closed the account but said the information visible at the time did not meet its threshold for a credible and imminent risk. The company also said it subsequently changed its referral criteria and would refer the same account if it were discovered under the enhanced protocol today. It further acknowledged finding a second account after the event.
These facts raise a more precise question than the general claim that platforms should promote safety. Once an AI platform detects a risk signal, does that fact already impose a determinate duty to intervene or report? My judgement is that detection changes the platform’s epistemic and responsibility position, but does not by itself dictate one particular action. A signal, knowledge, authority to act and obligation must be assessed separately. Yet a platform that has deliberately built monitoring, review and account-control systems cannot then describe itself as merely a neutral conduit for information.
The first distinction is between a risk signal and knowledge. An automated flag shows that observable content triggered a rule. It may be a false positive, or it may reveal only a partial pattern of danger. Human review can add context without establishing a person’s real-world identity, capacity, target, timing or causal role. It would therefore be inaccurate to rewrite “the system detected an anomaly” as “the company knew that a person would cause harm”. That move collapses probability, rule matching and factual knowledge.
The opposite inference is also unsound. A signal does not lose all epistemic importance merely because it falls short of certainty. The platform chose to search for signs of violent activity and created human review and law-enforcement referral processes because some signals were intended to count as inputs to action. Once an account enters that process, the institution at least knows that there is a risk claim requiring judgement. It may not know that harm will occur, but it can no longer reasonably say that it knows nothing about whether further action may be needed.
Philosophical accounts of moral responsibility commonly distinguish an epistemic condition from a control condition. The Stanford Encyclopedia of Philosophy’s discussion of the epistemic condition explains that responsibility concerns not only whether an agent had control, but also whether the agent was aware of what it was doing, its consequences or its moral significance. Applied to a platform, risk detection supplies only one part of the structure. We must also ask what actions were feasible, whom those actions would affect, whether the platform had legitimate authority and what consequences were reasonably foreseeable. An organisation that receives a signal but lacks any capacity to verify or intervene occupies a different position from one that also controls the account, retains logs, employs a human safety team and has a referral channel to public authorities.
No concrete duty follows from the word “detection” alone. Nor is police referral the only possible intervention. A platform can stop a model from providing information that facilitates harm, add friction, require further verification, preserve relevant records, restrict or close an account, escalate the case to specialist reviewers, or contact emergency services or law enforcement once a defined threshold is met. These measures have different implications for privacy, false positives, discriminatory error, due process and physical safety. Reporting every ambiguous signal could create pervasive surveillance and turn confused expression, fictional writing or help-seeking into police records. Treating every uncertainty as a reason for inaction would, however, strip the platform’s safety monitoring of practical meaning.
Privacy is not simply the opposite of safety here. It is a joint constraint on how intervention should occur. Philosophical work on privacy draws attention not only to whether information is obtained, but also to how it is used, who controls it and how it moves within a relationship. Interaction with a conversational system is not therefore an absolutely confidential space, but the platform’s access to content does not create an unlimited entitlement to disclose it. A responsible system should explain how detection scope, review authority, escalation thresholds, record retention, external referral and appeal fit together, while limiting the use of sensitive information to what is necessary.
OpenAI’s statement that the same account would be referred under its enhanced criteria today does not by itself prove that the earlier decision was negligent, nor does it extinguish any responsibility the earlier decision may carry. It does reveal that the referral threshold was not a natural boundary supplied directly by risk itself. It was an operational boundary formed by institutional definitions, evidential requirements, staff judgement, privacy policy and the capacity to cooperate with outside authorities. A threshold that can be revised must also be open to reasons, comparison across cases and evaluation of its effects.
In Sustenesis Theory, Difference first requires us to distinguish the underlying conversation, an automated flag, a human assessment, a real-world danger and a legal fact. Collapsing these levels allows model output, corporate knowledge and judicial findings to substitute for one another. Constraint refers to the conditions that make action possible or impossible: detection rules, permissions, human expertise, identity verification, legal standards, privacy protections and channels to law enforcement. Sustained Coherence requires the responsibility chain to remain intelligible across detection, review, response, documentation, external scrutiny and revision. One correct decision cannot establish that the entire institution is reliable, just as one missed referral cannot by itself show that every threshold should disappear. The central test is whether the institution can explain why similar signals receive similar or different treatment, and whether it can revise the process in light of consequences.
The central judgement can therefore be stated precisely. Detecting risk does not automatically generate a reporting duty with fixed content, but it does create an inescapable procedural responsibility. A platform that actively monitors users and has the capacity to intervene must maintain a responsibility chain that is explainable, reviewable and proportionate to risk. It should translate uncertain signals into graduated responses rather than choosing between universal police referral and total non-intervention. It must also show that privacy is not being used to avoid judgement, and that public safety is not being used as a licence for unlimited monitoring.
The limits of this conclusion matter. This article does not decide negligence, causation or damages in British Columbia’s lawsuit, and it draws no inference about the motives of people whose internal decisions are not public. Determining whether a duty was breached in the specific case would require the complete conversations, the model and policy versions then in use, the human review record, available identity information, the reasons for escalation decisions and the applicable law. The philosophical conclusion supported by present evidence is narrower: once a platform builds a system that can see risk and alter the conditions of action, its responsibility concerns not only what it knew, but how it connected what it knew, what it could do and what it ought to do.
References
Reuters, British Columbia sues OpenAI over Tumbler Ridge school shooting, 21 September 2026
https://www.reuters.com/legal/government/british-columbia-sues-openai-over-tumbler-ridge-school-shooting-2026-09-21/
OpenAI, letter to Canada’s Minister of Artificial Intelligence and Digital Innovation Evan Solomon, 26 February 2026
https://cdn.openai.com/pdf/8e938d69-0b67-4994-b9ff-683733ed587e/openai-letter-minister-solomon.pdf
Stanford Encyclopedia of Philosophy, The Epistemic Condition for Moral Responsibility, revised 4 October 2022
https://plato.stanford.edu/entries/moral-responsibility-epistemic/
Stanford Encyclopedia of Philosophy, Privacy
https://plato.stanford.edu/entries/privacy/
Discover more from Geoffrey Chen
Subscribe to get the latest posts sent to your email.