this post was submitted on 05 Oct 2026
559 points (99.5% liked)

Technology

88390 readers
3180 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS
 

What just happened? Another incident has taken place that illustrates the need to be careful what you tell AI. A Florida woman is facing felony charges after she used Claude as a diary and allegedly wrote that she planned to "shoot up" the Sheriff's office. After a human reviewer examined the statements, they were reported to police.

According to the arrest report, Carli Michelle Heller, of Bonita Springs, Florida, wrote on September 26 that she would attack the Sheriff's office. She later said that she uses Anthropic's chatbot like a "diary."

Claude's safety systems flagged the entry and it was escalated to a human reviewer. After deciding it was a credible threat, the reviewer reported it to law enforcement.

The company says it may share user information in limited emergencies if it believes disclosure is necessary to prevent death or serious physical injury.

Deputies identified Heller and visited her home. She was detained without incident before an LCSO intelligence detective took over the investigation.

Heller faces a charge of making a written threat of violence under Florida law. Florida Statute 836.10 makes it a second-degree felony to send, post, or transmit a written or electronic record threatening to kill or injure someone, carry out a mass shooting, or commit an act of terrorism. The communication must be made in a manner in which another person may view it.

Anthropic isn't going to be taking any chances when it comes to anything it deems a potential threat. Last month, it was reported that OpenAI and Sam Altman are being sued by British Columbia over claims that the company could have prevented a mass shooting in the Canadian province.

The shooter, eighteen-year-old former pupil Jesse Van ⁠Rootselaar, had previously been flagged by OpenAI's safety team for her conversations about gun violence, but OpenAI never alerted police because the conversations did not meet the threshold for legal referral.

In June, Florida also sued OpenAI and Altman, alleging that ChatGPT had contributed to real-world harms, including the 2025 Florida State University shooting.

The latest incident is another reminder to think before you enter something into a chatbot that could get you into trouble. It's certainly not a private diary whose contents are for your eyes only.

Reports last month revealed that human contractors reviewing Microsoft Copilot's image editor can see users' prompts, uploaded photos and AI-generated edits. Documents show that some of those assignments contain sexual, disturbing or potentially illegal material, though the reviewers are not there to flag the content – only to assess whether the output is accurate.

you are viewing a single comment's thread
view the rest of the comments
[–] Wildmimic@anarchist.nexus 3 points 14 hours ago* (last edited 13 hours ago)

This is completely irrelevant - by default local models do not have access to the internet, because you have to provide/activate the relevant tools. They can't access the web by themselves regardless of where you are, the environment has to be set up for it. Even if you provide a web search tool, they can't do anything outside of providing search parameters - what happens with them is defined by the tool, not the LLM.

These things work by providing the LLM with a system prompt that explain them what they have to do to get access to specific tools. They get provided the specific syntax they have to use it, and the environment they are running inside is then parsing the correctly formatted plain text the LLM outputs.

Specific example for the system prompt in Newelle, a all-in-one suite on Linux to run models, to provide tools in general and the web search tool in detail:

# Tools  

## Overview  
You have access to tools that extend your capabilities. Use them when they are relevant to the user's request.  

## Invocation Format  
When using a tool, output **only** a single valid JSON object:  

\`\`\`json  
{  
  "tool": "tool_name",  
  "arguments": {  
    "arg_name": "arg_value"  
  }  
}  
\`\`\`  

## Rules  
1. Output only the JSON object — no explanations, markdown, or extra text before or after.  
2. Ensure valid JSON: no comments, trailing commas, or extra text.  
3. Use only the tools listed below and only their defined arguments.  
4. **After invoking a tool, stop generating immediately.** Wait for the result before continuing.  
5. Some tools are shown in **compact form** (only name and description, no `parameters`), marked "(compact: ...)". Calling a compact tool directly with guessed or missing arguments is an error and will be rejected.  
## Available Tools  

\`\`\`  
{TOOLS}  
\`\`\`  

The Search tool in detail:

{  
  "name": "search",  
  "description": "Perform a search query on the internet, you can specify the number of results to return and if you want to only return the links and titles.",  
  "parameters": {  
    "type": "object",  
    "properties": {  
      "query": {  
        "type": "string"  
      },  
      "tool_uuid": {  
        "type": "string"  
      },  
      "only_links": {  
        "type": "boolean"  
      },  
      "max_results": {  
        "type": "integer"  
      }  
    },  
    "required": [  
      "query"  
    ]  
  }  
}  

Edit: I can't for the love of god find out how to escape the 3 backticks for the JSON-Object correctly without either breaking the code blocks or the backslashes showing up. In the original prompt, the backslashes do not exist.