Eight people died in Tumbler Ridge, British Columbia, in February 2026. Jesse Van Rootselaar, 18, opened fire on family members and students before taking his own life. More than 25 wounded were left behind. A community marked by grief. And months earlier, OpenAI employees reviewed his ChatGPT conversations, noticed signs of intent to use weapons, and chose not to alert anyone.
That detail calls for a moment of reflection.
It's no surprise that OpenAI has access to user conversations. That's already part of what we know, or should know. What's unsettling is something else: real people read what this young man was sharing, connected the dots, debated internally, and concluded there was no "imminent and credible" threat. They suspended the account for violating policy. And they stayed silent.
What we're exploring here isn't a defense of blanket surveillance or of absolute, unnuanced privacy. It's an attempt to understand what happens when a tech company navigates between principles that collide.
First, the obvious part: OpenAI reviews conversations, not just through algorithms but with human intervention when troubling signals appear. When you share fears, ideas, or doubts with ChatGPT, an employee could see them. And not just that: they can know who you are, with name, email, and history. There's no real anonymity. In my experience, I've seen how this connects to broader questions of governance, similar to those I explore in historical contexts where personal information was used for control or protection. I'm reminded of the Heppner case in New York, which showed that chats with AI lack legal protection. Here, the angle shifts, but the thread is the same: information reaches moderators who decide its fate.
Now, the philosophical dimension, which adds genuine depth.
Kant faces a classic dilemma in his ethics. Lying is an absolute no, with no exceptions for context or outcomes. If a murderer asks where your friend is, Kant demands the truth. Many see this as a mistake, but his reasoning seeks consistency: who sets the exceptions if they're based on consequences? A person? A company? A system?
OpenAI's employees found themselves in a Kantian dilemma in reverse. Kant asks: can I lie to save lives? They asked: can I breach privacy to prevent harm? And they followed an almost Kantian logic: no, not without clear certainty. The rule was firm. They respected it.
But rules don't always protect lives. Effects sometimes do.
This friction between deontological and consequentialist ethics, debated for centuries, now takes concrete shape with real names and real consequences. A consequentialist would argue: if there's a reasonable chance of preventing a tragedy, it's worth acting. The Kantian would reply: rules bent for convenience stop being rules. If dark thoughts get reported today, does it extend tomorrow to dissenting voices or activists?
This isn't rhetoric. It's a valid concern.
I've observed in various scenarios how security exceptions become normalized. The protection argument has justified sweeping measures, like the Patriot Act in the United States after September 11, which began targeting terrorism but expanded surveillance. Historical precedents, like excavations revealing abuses of power in ancient societies, remind us that control over information rarely stays contained. This connects to themes in my book, where I explore how past societies balanced secrecy and the common good.
And still. Eight lives lost. More than 25 wounded. A young man with a history of mental health issues and prior police contact, sharing violent thoughts with an AI. Someone saw it. No one intervened.
Since August 2025, OpenAI has modified its terms to allow alerts in cases of serious risk. The company has already tipped the scale: privacy isn't absolute when lives are at stake. But another question arises: who measures "serious risk"? Distant moderators? Biased algorithms? Models we still don't fully understand?
I admit there's no simple solution. This is more intricate than a headline suggests. In my experience, similar patterns in historical contexts show that complexity calls for collaborative approaches, not hasty judgments.
What's clear is that public debate oversimplifies this: privacy versus security, as if they were irreconcilable opposites. That view is limiting. The core issue is governance: who decides, by what standards, under what external oversight, and with what accountability when they fail? OpenAI failed here, not out of intent, but from a lack of clear guidelines. That gap had a cost.
This isn't about more corporate surveillance or freezing up in the face of danger. I propose open protocols, independently supervised, with public criteria and reviews. Involving mental health experts, legal scholars, communities, and users. Imagine a framework where decisions aren't made behind closed doors, but through inclusive processes. There are viable alternatives, inspired by historical models of collective counsel that balanced power and empathy.
The Tumbler Ridge case goes beyond tragedy. It reflects how much we've ceded to private companies without demanding checks and balances. Using ChatGPT means interacting with a corporate entity, with its own policies and interests. Useful, yes, but it must be navigated with eyes open. I believe there's room for ethical innovation that protects without invading.
Kant was right that solid rules matter, and vague exceptions are risky. But he was wrong to ignore impact: not acting isn't neutral, it's passivity. OpenAI did just that. It followed its line, suspended the account, and waited.
Eight people couldn't wait.
Stones don't lie, but historians sometimes do.
Sources:
1. CBC News – Coverage of the Tumbler Ridge, British Columbia shooting, February 2026.
2. The New York Times – Report on OpenAI's access to user conversations and the internal debate prior to the attack.
3. Kant, Immanuel – On a Supposed Right to Lie from Philanthropy (1797), for the deontological framework.
4. Electronic Frontier Foundation – Historical analysis of the Patriot Act and surveillance precedents under security arguments.
5. OpenAI Terms of Service (August 2025 update) – Changes to threat-reporting policy.