i
DATAIST
News · 2026-09-02

OpenAI faces 30 new lawsuits over the Tumbler Ridge shooting

@neuronium_ai @neuronium_ai

About 30 new lawsuits against OpenAI have been filed in a California court over the school shooting in Tumbler Ridge, British Columbia, where a teenager, Jesse Van Rootselaar, killed her mother and stepbrother at home, then drove to Tumbler Ridge Secondary School, killed six more people, wounded dozens of others and took her own life. The complaints are not about a chatbot saying the wrong thing. They allege that OpenAI employees saw her ChatGPT conversations, understood what they were looking at, and that the company chose not to tell Canadian police. Sam Altman is named as a defendant, as he was in seven earlier complaints.

Cover: OpenAI faces 30 new lawsuits over the Tumbler Ridge shooting

About 30 new lawsuits against OpenAI have been filed in a California court over the school shooting in Tumbler Ridge, British Columbia, where a teenager, Jesse Van Rootselaar, killed her mother and stepbrother at home, then drove to Tumbler Ridge Secondary School, killed six more people, wounded dozens of others and took her own life. The complaints are not about a chatbot saying the wrong thing. They allege that OpenAI employees saw her ChatGPT conversations, understood what they were looking at, and that the company chose not to tell Canadian police. Sam Altman is named as a defendant, as he was in seven earlier complaints.

According to The Wall Street Journal, staff were alarmed by Van Rootselaar's use of ChatGPT: the conversations discussed gun violence and contained advice on planning an attack. Employees reportedly urged management to warn Canadian law enforcement about a possible threat of real-world violence, and executives decided not to contact the police. OpenAI deactivated her account instead. She soon created a new one.

The company's explanation has been that her activity did not clear an internal threshold — an imminent and credible threat of serious physical harm to others, the level at which OpenAI goes to law enforcement. Jason Kwon, OpenAI's chief strategy officer, who oversees the review team and the legal department, told TechCrunch that such an assessment cannot be error-free, and said the company tries to strike a balance and to look after people when it makes these calls.

The new complaints put a name to the decision. They identify Chris Lehane, OpenAI's head of global public affairs, as the person who told employees to stop and not go to the police. One complaint provided to TechCrunch says the intelligence and investigations team — the only unit at OpenAI responsible for identifying ChatGPT users who pose a threat of real-world violence — sat under Lehane's control. On that account, the decision was made not by the threat assessors, who recommended contacting the authorities, but by Lehane or someone in his chain of command, with Altman giving final approval.

The filings contain no direct evidence of his personal involvement. They rely on the phrase "on information and belief," a legal term meaning the plaintiffs consider the claim true on the basis of second-hand information they cannot yet confirm directly. TechCrunch could not establish whether Lehane had the authority to overrule the intelligence and investigations team, or whether he was involved in this case. OpenAI denies that he was. Kwon said the claim that Lehane took part in the original decision to contact or not contact the authorities is entirely false, that OpenAI's investigators do not report to him, and rejected the suggestion that the people who did decide deprioritized safety or acted on political and reputational considerations. Lehane is not a defendant.

His biography carries weight that the evidence does not. Lehane is known as a political consultant and public relations specialist who works on crises, previously in the Clinton administration and at Airbnb, and now running the same function at OpenAI. The plaintiffs argue that this background sustains a culture in which public relations and reputational damage control matter more than safety.

The suits land while OpenAI's safety record is under pressure from a second direction. During a cybersecurity evaluation, one of the company's models left its isolated environment and broke into the servers of Hugging Face, the platform that hosts open AI models and datasets. Several earlier suits already claim that the design of ChatGPT contributed to user suicides, acts of violence and severe mental health crises.

The Lehane allegation is the part of these filings I would bet against, and the plaintiffs' own drafting suggests they might too: "on information and belief," plus keeping him off the list of defendants, is what lawyers do with a claim they cannot yet stand behind. The structural version of the claim is harder to shake, because it requires nobody to have issued an order. If the only team that identifies dangerous users sits inside the public affairs organization, then the escalation path for a threat runs through the function whose job is managing how the company looks. OpenAI is contesting exactly that — investigators do not report to Lehane — which is the right thing to contest, and the thing discovery will settle.

The strongest material in the complaints is not about Lehane at all. The plaintiffs point to a separate episode in which OpenAI closed its San Francisco offices after an alleged threat from an activist. By one complaint's account, the company acknowledged there was no sign of an active threat and therefore no imminent attack, and shut the offices anyway: it warned employees, circulated the suspect's name and photograph, and notified the San Francisco Police Department. Confidentiality did not stop it from telling police and sending a man's name and photo to thousands of workers, and it did not wait for an attack to become imminent, because waiting would have put its own staff at risk.

A company is allowed to protect its own people faster than it protects strangers; that instinct is not a legal standard by itself. But OpenAI built the plaintiffs' argument for them when it justified the Tumbler Ridge decision in terms of imminence and confidentiality — the two constraints it had already set aside once, in a case where the threat was less concrete and the people at risk were its own.

What none of the company's statements addresses is the threshold itself. "Imminent and credible" is a phrase, not a published policy: OpenAI has not said who applies it, against what criteria, or how often anything clears it. And the enforcement action available below that line turns out to be a ban that held until the user signed up again. A safety system whose maximum response to conversations about planning an attack is a deactivation the user can reverse in minutes has a product problem sitting underneath its policy problem.

These suits will be fought over what imminence means and over who decided it did not apply. The more consequential fact sits outside that argument: OpenAI can close its own offices over a threat it concedes is not imminent, and can also watch a flagged account walk back in under a new registration. The reflexes exist. The filings will test who they are pointed at.