P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

British Columbia sues OpenAI over Tumbler Ridge on a duty to warn police that no court has yet tested

British Columbia and its local school board have sued OpenAI and Sam Altman, alleging the company flagged the Tumbler Ridge shooter's ChatGPT account in June 2025 and chose not to tell police. Every claim is untested, and the duty at its centre has never been applied to an AI company.

By Parminder Kumar Sharma · · 20 min read

Editorial illustration for the briefing: British Columbia sues OpenAI over Tumbler Ridge on a duty to warn police that no court has yet tested

Eight claims, copied heading for heading, under California law

On 21 September 2026 the Province of British Columbia and the Board of Education of School District No. 59 (Peace River South) filed a 39-page complaint against Sam Altman and four OpenAI entities in the US District Court for the Northern District of California, case number 3:26-cv-10743. It concerns the shooting at Tumbler Ridge Secondary School on 10 February 2026, in which eight people were killed, five of them students.

Read the caption before the prose. The complaint lists eight causes of action. They are, word for word and in the same order, the first eight causes of action in the complaint the family of the education assistant who was killed filed in the same court on 29 April 2026, Stacey v. Altman. The families add three more (California's unfair competition law, wrongful death and a survival action) that a government plaintiff has no use for. The Province's filing is, by our count from the court records, the 38th Tumbler Ridge case against OpenAI in that court: seven family suits in April, thirty more on 2 September, and this one.

The second checkable fact is what the complaint does not cite. British Columbia has sued before to recover public money from an industry, and each time it had a statute written for the purpose: the Tobacco Damages and Health Care Costs Recovery Act 2000 and the Opioid Damages and Health Care Costs Recovery Act 2018 are built around a section headed "Direct action by government". This complaint relies on no such statute. It pleads California common law, starting with a 1976 California Supreme Court case about a psychotherapist, Tarasoff v. Regents of the University of California.

This briefing sets out the legal and governance substance: the claims, the relief sought, what OpenAI has said on its own record, and what remains open. It does not describe the attack beyond what the parties' filings state, and it does not name the person responsible. The people of Tumbler Ridge, who have lost children, colleagues and a school, are the reason the questions matter.

What the Province has filed, and what it asks for

The plaintiffs are His Majesty the King in Right of the Province of British Columbia, represented by Attorney General Niki Sharma, and SD59, the school board that owned the building. The defendants are Samuel Altman, OpenAI Foundation (formerly OpenAI, Inc.), OpenAI OpCo LLC, OpenAI Holdings LLC and OpenAI Group PBC. US counsel is Stranch, Jennings & Garvey of Oakland; Canadian counsel is CFM Lawyers of Vancouver. The Province founds jurisdiction on US diversity rules for foreign plaintiffs and demands a jury.

The money claimed is public expenditure, not personal injury. The complaint lists policing and emergency response, health care, victim services and trauma-informed mental health care, replacement staff, demolition of the school and the building of a replacement school and wellness centre. No figure is pleaded. The complaint repeatedly describes these as "extraordinary, non-recurring" costs rather than the routine costs of government, language that reads as an answer to an expected defence that public services are not recoverable in tort. That reading is our inference; the complaint does not name the doctrine.

The Attorney General's statement links the suit to policy: she says she has written to federal ministers proposing Criminal Code amendments "to ensure a pathway to human accountability for AI's actions".

The eight causes of action in No. 3:26-cv-10743, with what each would require. Headings from the complaint; the third column is our reading, not the court's.

Cause of actionCore allegationUntested element
1. Negligence: failure to warn law enforcementReviewers identified a credible risk and recommended telling the RCMP; leadership declinedWhether a Tarasoff-style duty extends to an AI provider
2. Negligent entrustmentOpenAI re-supplied ChatGPT to a user it had deactivated for violent misuseWhether a chatbot is an entrusted instrumentality
3. Aiding and abetting a mass shootingContinued supply with knowledge amounted to substantial assistanceActual knowledge and intent, pleaded on information and belief
4. Negligence: failure to warnNo warning to users or the public of known risksCausation through third parties who might have intervened
5. Negligent undertakingOpenAI publicly undertook to detect and refer threats, then performed it carelesslyReliance by authorities or the public
6. Negligence: design defectEngagement-maximising, validating design without reliable refusalFeasible safer alternative and causation
7. Strict liability: design defectChatGPT is a product and was defective when it reached the userWhether generative AI output is a product in California
8. Strict liability: failure to warnNon-obvious dangers were known and not disclosedProduct status, and who the warning was owed to

The injunction sought has eight parts. The Province asks the court to order OpenAI to reliably refuse or de-escalate conversations expressing intent to harm others; to run automated detection with human escalation and stop accepting fictional or "research" framings for restricted violent content; to refer to police any user presenting "an imminent or credible threat" consistent with OpenAI's own stated criteria; to warn that safety features degrade in long conversations; to stop banned users re-registering on the same identity, device or payment method; to adopt and enforce a red line against facilitating violence; to keep auditable controls; and to submit to quarterly audits by an independent monitor. It also seeks punitive damages, restitution, disgorgement and a declaration that ChatGPT was defectively designed.

The complaint frames this as holding OpenAI to promises. Its paragraph 11 says the action "seeks implementation" of relief that Mr Altman and OpenAI's Ann O'Leary offered and have not implemented.

What the complaint alleges, and what OpenAI has already said

The case turns on one decision in June 2025, about eight months before the shooting. Three sources describe it, and they overlap more than a reader of the headlines might expect.

OpenAI's own account is in a letter from Ann O'Leary, its vice president of global policy, to Canada's AI minister Evan Solomon dated 26 February 2026. It says OpenAI's automated system detected the account, sent it to human review, and banned it in June 2025, but "we did not identify credible and imminent planning that met our threshold" for a police referral. It says a second account was discovered only after the shooter's name was released publicly, and was then shared with law enforcement. And it says that under its enhanced protocol "we would refer the account banned in June 2025 to law enforcement if it were discovered today."

Sam Altman's letter to the Tumbler Ridge community, dated 23 April 2026 and published by the local news site, says: "I am deeply sorry that we did not alert law enforcement to the account that was banned in June." The complaint calls this an admission by a party opponent. It is an apology for an omission; it is not an admission that the omission caused the attack.

The complaint's allegations, attributed largely to whistleblowers first reported by The Wall Street Journal, go further: that roughly a dozen employees assessed the chats as presenting an imminent risk of serious harm, recommended contacting the RCMP, and were overruled by leadership applying "an unknown higher threshold"; that OpenAI's motive was to avoid a hard reporting rule that would expose how often its product is implicated in threats, and to protect its valuation ahead of an expected share offering; that the account was deactivated rather than banned; and that ChatGPT's design, including memory switched on by default and a Model Spec that told the model to "assume best intentions", reinforced violent ideation.

Flow diagram of OpenAI's escalation pipeline for the flagged account in four stages: detection, human review, referral decision, outcome. Upper row, OpenAI's account: detected June 2025, reviewed, no credible and imminent planning found, banned, second account found later. Lower row, the Province's allegations: about a dozen staff urged an RCMP referral, leadership overruled them, re-registration stayed possible. Bottom band: chat contents, causation and who decided remain unestablished.
Drawn from OpenAI's letter to Minister Solomon (26 February 2026), the Province's complaint (21 September 2026) and OpenAI's forum non conveniens motion (2 September 2026).

Who says what about the June 2025 decision. Compiled from OpenAI's letter of 26 February 2026, Sam Altman's letter of 23 April 2026, OpenAI's 2 September 2026 motion and the Province's complaint.

PointStated by OpenAIAlleged only by plaintiffs
Automated detection and human review in June 2025YesAdds that about a dozen staff reviewed it
No police referral was madeYes, and apologised for itAdds that staff recommended one
Reason for no referralDid not meet credible and imminent thresholdLeadership overrode staff; corporate self-interest
Would be referred under today's rulesYesTreated as an admission of duty
Second account existedYes, found after the name was publicAdds that the Help Center told deactivated users how to return
Sam Altman personally decidedNo: says he was not involvedPleaded against him as controlling officer
What the chats containedNot statedNot stated; logs not yet produced

OpenAI's response: sympathy, and an argument about where to be sued

OpenAI's public response to the Province, as reported in the trade press, was a spokesperson's statement that what happened "was an unspeakable tragedy" and that the company remains committed to working with government and law enforcement. Its legal response so far, in the family cases, is procedural. On 2 September 2026 it moved to dismiss the seven April cases for forum non conveniens, with a hearing set for 8 October; on 17 September it filed the same motion in the September cases, with a hearing set for 5 November.

The motion's argument is that the evidence needed to test causation sits in British Columbia and beyond a California court's subpoena power: the RCMP's investigation, provincial health and school records, and the coming coroner's inquest, which, according to the motion, the Chief Coroner has said will look at, among other things, "what role artificial intelligence played". OpenAI says it will consent to jurisdiction in British Columbia. It says one plaintiff first sued in the B.C. Supreme Court and discontinued, and it characterises counsel's public explanation as an attempt to avoid Canadian caps on damages. It also says Mr Altman was not personally involved in the June 2025 review or decision.

Two things follow, and both are inference. First, the motion leans heavily on British Columbia's sovereign interest in judging its own institutions; the sovereign has now chosen California. That does not decide the motion, but it changes the argument OpenAI will have to make against this plaintiff. Second, OpenAI's causation case will point at the RCMP, the provincial mental health system and firearms licensing. The complaint anticipates this in paragraph 8, arguing that blaming the RCMP "all but admits" OpenAI should have warned it. A trial on those terms would put a provincial government and a US technology company in the position of each arguing that the other's institutions failed.

OpenAI's safety policies and the teen safety plan, read against the timeline

OpenAI has published a sequence of safety commitments since mid-2025. Most came after the June 2025 decision. The complaint's point is that they show the risk was understood; OpenAI's point would be that they show a company improving. Both readings rest on the same documents, so the documents are worth reading for their thresholds, because the threshold is the whole question in this case.

OpenAI's stated threshold for telling police about threats to others, in its own words, by date. From the OpenAI publications listed in the sources.

Date and documentReferral wordingBinding on OpenAI?
June 2025 decision (described Feb 2026)"credible and imminent planning" meeting "our threshold"Not stated; internal
26 Aug 2025, Helping people"imminent threat of serious physical harm to others, we may refer"No; discretionary "may"
Nov 2025, Teen Safety Blueprint"Notifying law enforcement if there is a credible threat"No; a recommendation to industry
26 Feb 2026, letter to CanadaCriteria made "more flexible"; target, means and timing need not be discussedVoluntary commitment
28 Apr 2026, Community safety"imminent and credible risk of harm to others, we notify"Not stated

The teen safety plan is in three documents. Sam Altman's post of 16 September 2025 said OpenAI would "prioritize safety ahead of privacy and freedom for teens", build an age-prediction system, and default to the under-18 experience when in doubt. The Teen Safety Blueprint of November 2025 set out five principles for the industry, including identifying under-18 users with privacy-protective age estimation and, among its well-being safeguards, notifying law enforcement of a credible threat of harm to others. On 18 December 2025 OpenAI added Under-18 Principles to its Model Spec, stated to cover teens aged 13 to 17.

The complaint uses the gap between those documents and provincial law. Every protection is keyed to being under 18. The age of majority in British Columbia is 19, so the complaint argues the user was a minor under provincial law throughout, yet outside every teen safeguard OpenAI had announced. Whether that matters legally is untested; as a governance point it is simple. A control defined by one jurisdiction's age threshold does not travel to another jurisdiction's definition of a child.

The complaint also leans on the Model Spec's history: that an explicit line against facilitating violence entered the Model Spec on 18 December 2025, 54 days before the attack, and that earlier versions told the model to "assume best intentions" and not to ask users their intent. Those are the complaint's characterisations of public documents; we have not reproduced each historical Model Spec version to check them clause by clause.

How this compares with other claims against AI companies

The only chatbot product-liability ruling we could find on the record at the pleading stage is Garcia v. Character Technologies in the Middle District of Florida, a suit over a teenager's death after conversations with Character.AI characters. On 21 May 2025 Judge Anne Conway refused to dismiss most claims. She said the court was "not prepared to hold that Character A.I.'s output is speech" at that stage, and held the app was a product "so far as Plaintiff's claims arise from defects in the Character A.I. app rather than ideas or expressions within the app". On 7 January 2026 the parties filed notice of a mediated settlement in principle. So the most-cited ruling is a Florida pleading-stage decision in a case that will now never reach trial. It is persuasive at most in California.

The Province's complaint is drafted to sit inside that distinction. Paragraphs 55 and 122 insist the claims do not treat OpenAI as publisher of anyone else's content and that "the defective product generated the injurious content itself", which is aimed at the US immunity for hosting third-party content as much as at product status.

Selected claims against AI companies over violence or death, from court dockets on CourtListener. Status as at 22 September 2026.

Case and courtWhat it testsStatus on the record
Garcia v. Character Technologies, M.D. Fla., 6:24-cv-01903Chatbot as product; output as speechMost claims survived dismissal; settlement in principle, Jan 2026
Stacey v. Altman and six others, N.D. Cal., filed 29 Apr 2026Same eight theories plus wrongful deathForum motion pending; hearing set 8 Oct 2026
Thirty further Tumbler Ridge cases, N.D. Cal., filed 2 Sep 2026Survivors and witnessesRelated to Stacey; forum motion hearing set 5 Nov 2026
Joshi v. OpenAI Foundation, N.D. Fla., 4:26-cv-00222ChatGPT and a university shootingFiled 10 May 2026; no merits ruling found
B.C. v. Altman, N.D. Cal., 3:26-cv-10743Government cost recovery on the same theoriesFiled 21 Sep 2026

What is untested

  • Duty. Tarasoff concerned a therapist with a direct clinical relationship. The complaint argues OpenAI's relationship with an account holder it monitored and controlled is a special relationship of the same kind. No court has decided that for an AI provider.
  • Causation. The complaint must show that a referral would have led the RCMP to act and that the act would have prevented the attack, against OpenAI's argument that other institutions' failures intervened.
  • Product status. Whether ChatGPT is a product for California strict liability, and whether its output is protected expression, is open.
  • Recoverable loss. Whether a government can recover the cost of an emergency response and a new school in tort is a live question the complaint visibly anticipates.
  • Personal liability. OpenAI says Mr Altman was not involved in the June 2025 decision; the complaint pleads against him as a controlling officer.
  • Forum. A court may send the family cases to British Columbia before any of this is reached. We found no order relating the Province's case to them as at 22 September.
  • The evidence itself. The chats have not been produced. Their contents may strengthen or weaken every claim above.

The UK angle: duty of care, product law and the Online Safety Act

Duty of care. English law starts from the opposite end to the Province's pleading. In Robinson v Chief Constable of West Yorkshire Police [2018] UKSC 4, Lord Reed, quoting Lord Toulson in Michael, restated that the common law "does not generally impose liability for pure omissions", and that there is generally no duty to prevent a third party harming someone. He adopted four exceptions: where the defendant has assumed a responsibility to protect the claimant, has prevented someone else from protecting them, has a special level of control over the source of danger, or has a status that creates an obligation. Our reading, which is not legal advice, is that the Province's theories map onto those exceptions surprisingly closely: the negligent undertaking claim is an assumption-of-responsibility argument, the entrustment claim is a control argument, and the design claims argue OpenAI created the danger rather than merely failing to stop it. An English court would ask those questions under its own tests, and none of this has been argued here.

Product liability. Part 1 of the Consumer Protection Act 1987 predates software as a consumer product. The Law Commission began a review in September 2025 covering "digital products and emerging technologies such as AI", with a public consultation planned for the second half of 2026. Until then, whether a chatbot is a product under UK strict liability is as open as it is in California.

The Online Safety Act. Ofcom's position, in its open letter of 8 November 2024 and its guidance of 18 December 2025, is that a chatbot is covered only where it is part of a user-to-user service, a search service, or a service that can generate pornography. Ofcom says plainly that chatbots are not regulated if they "Only allow people to interact with the chatbot itself and no other users", do not search multiple sites or databases, and cannot generate pornography. A one-to-one conversation of the kind at issue in Tumbler Ridge would have sat outside the Act.

Parliament has since created a route in. Section 248 of the Crime and Policing Act 2026, in force at Royal Assent on 29 April 2026, inserts section 216A into the Online Safety Act, letting the Secretary of State extend illegal content duties, risk assessment and Ofcom's enforcement powers to "AI services". Section 249 requires a progress report to Parliament by 31 December 2026 unless draft regulations are laid first. We found no draft regulations laid as at 22 September 2026. Threats to kill and a range of firearms offences are already priority offences under Schedule 7.

One limit matters for this case. Section 216A is about minimising the risk of illegal AI-generated content and of AI services being used to commit priority offences. The only reporting obligation it contemplates extending is the existing duty to report child sexual exploitation and abuse content. Nothing in it would require a provider to tell the police about a user it has judged dangerous. In the UK, that decision would still be governed by the provider's own policy, data protection law, and the common law of negligence.

Where a one-to-one chatbot conversation sits in UK law today. From Ofcom's published position, the Crime and Policing Act 2026 and Robinson [2018] UKSC 4.

RegimeCovers a one-to-one chatbot?Requires a police referral?
Online Safety Act 2023, as enactedNo, unless search, sharing or pornographyNo
Section 216A regulations, if madeCould, for illegal content and priority offencesNot contemplated, except CSEA reporting
Consumer Protection Act 1987 Part 1Unclear; under Law Commission reviewNo
Common law negligencePossibly, via the Robinson exceptionsNo general duty; untested for AI

What organisations deploying chatbots to the public should check

Most UK organisations are deployers, not model developers: a council's advice bot, a retailer's assistant, a university's student helper built on someone else's model. The Tumbler Ridge litigation is about a developer, but its theories attach to whoever detects, reviews and decides. In order of priority:

Take this with you

Actions in the order worth doing

  • Find out whether your chatbot or your vendor logs and flags conversations that suggest harm to others, and who sees those flags.
  • Write down the threshold for telling police, in words a court could read, and name the role that decides. If an executive can overrule reviewers, record why each time.
  • Check your contract with the model provider: who is responsible for detection, review and referral, and whether the vendor will tell you when it acts on your users.
  • Test whether a user you block can simply return with a new email address. If they can, call it a block, not a ban, in your policies and public statements.
  • Map every age-based safeguard to the age thresholds of every jurisdiction you serve, including where a child is legally a minor at 18.
  • Decide now whether your service is in scope of the Online Safety Act as a user-to-user or search service, and track section 216A regulations and the report due by 31 December 2026.
  • Review what your public safety statements promise. The Province's negligent undertaking claim is built on OpenAI's own published commitments.
  • Agree with your data protection officer how a referral would be lawful under UK GDPR and the Data Protection Act 2018 before you need to make one.

The question that exposes the gap

OpenAI has now said, in writing, that the account it banned in June 2025 would be referred to police under its current rules. That sentence concedes the old threshold was wrong without saying who set it, who applied it, or who could overrule it. For any organisation running a chatbot, the uncomfortable test is the same one this lawsuit puts to OpenAI: if your reviewers flagged a user as dangerous tomorrow, could you show a court the written threshold, the name of the person who decided, and the record of why?

Key facts

Sources

  1. PrimaryComplaint, His Majesty the King in Right of the Province of British Columbia v. Altman, No. 3:26-cv-10743, filed 21 September 2026. Read in full: parties, causes of action, allegations, prayer for reliefUS District Court, N.D. California (copy hosted by ChatGPT Is Eating the World)accessed 2026-09-22
  2. PrimaryAttorney General's statement on B.C. filing legal action against OpenAI, 21 September 2026Government of British Columbiaaccessed 2026-09-22
  3. PrimaryLetter from Ann M. O'Leary to Canada's Minister of AI Evan Solomon, 26 February 2026: OpenAI's account of the June 2025 decision and its commitmentsOpenAIaccessed 2026-09-22
  4. PrimaryOpenAI defendants' motion to dismiss for forum non conveniens in the seven April 2026 family cases, filed 2 September 2026US District Court, N.D. California (via CourtListener RECAP)accessed 2026-09-22
  5. PrimaryDocket metadata for the Province's case and related Tumbler Ridge dockets, including the 17 September 2026 motion and hearing datesCourtListeneraccessed 2026-09-22
  6. PrimaryStipulation relating 30 Tumbler Ridge cases filed on 2 September 2026 to Stacey v. Altman, filed 9 September 2026US District Court, N.D. California (via CourtListener RECAP)accessed 2026-09-22
  7. PrimaryComplaint, Stacey v. Altman, No. 3:26-cv-03701, filed 29 April 2026: list of causes of action used for comparisonUS District Court, N.D. California (via CourtListener RECAP)accessed 2026-09-22
  8. PrimaryOur commitment to community safety, 28 April 2026: current detection, review and referral process (read via Internet Archive copy)OpenAIaccessed 2026-09-22
  9. PrimaryHelping people when they need it most, 26 August 2025: referral wording for threats to others (read via Internet Archive copy)OpenAIaccessed 2026-09-22
  10. PrimaryTeen safety, freedom, and privacy, by Sam Altman, 16 September 2025 (read via Internet Archive copy)OpenAIaccessed 2026-09-22
  11. PrimaryProtecting Teen ChatGPT Users: OpenAI's Teen Safety Blueprint, November 2025OpenAIaccessed 2026-09-22
  12. PrimaryUpdating our Model Spec with teen protections, 18 December 2025: U18 Principles for ages 13 to 17 (read via Internet Archive copy)OpenAIaccessed 2026-09-22
  13. PrimaryOrder on motions to dismiss, Garcia v. Character Technologies, No. 6:24-cv-01903, filed 21 May 2025US District Court, M.D. Florida (via CourtListener RECAP)accessed 2026-09-22
  14. PrimaryNotice of resolution, Garcia v. Character Technologies, 7 January 2026US District Court, M.D. Florida (via CourtListener RECAP)accessed 2026-09-22
  15. PrimaryRobinson v Chief Constable of West Yorkshire Police [2018] UKSC 4, paragraphs 34 to 37 on the omissions principleThe National Archives, Find Case Lawaccessed 2026-09-22
  16. PrimaryOpen letter to UK online service providers regarding Generative AI and chatbots, 8 November 2024Ofcomaccessed 2026-09-22
  17. PrimaryAI chatbots and online regulation: what you need to know, 18 December 2025Ofcomaccessed 2026-09-22
  18. PrimaryCrime and Policing Act 2026, sections 248 and 249: new section 216A power to extend the Online Safety Act to AI services, and progress report dutylegislation.gov.ukaccessed 2026-09-22
  19. PrimaryOnline Safety Act 2023, Schedule 7 priority offences, including threats to kill and firearms offenceslegislation.gov.ukaccessed 2026-09-22
  20. PrimaryProduct liability project page: review of Part 1 of the Consumer Protection Act 1987, including digital products and AILaw Commissionaccessed 2026-09-22
  21. PrimaryOpioid Damages and Health Care Costs Recovery Act, SBC 2018, c. 35: direct government action statute used for comparisonKing's Printer, British Columbiaaccessed 2026-09-22
  22. PrimaryTobacco Damages and Health Care Costs Recovery Act, SBC 2000, c. 30: direct government action statute used for comparisonKing's Printer, British Columbiaaccessed 2026-09-22
  23. Reported byPublication of Sam Altman's letter to the Tumbler Ridge community dated 23 April 2026Tumbler RidgeLinesaccessed 2026-09-22
  24. Reported byReport carrying OpenAI spokesperson's response to the Province's lawsuitInsurance Journalaccessed 2026-09-22
  25. Reported byNews report on the filing, used as a pointer to the primary sourcesAl Jazeeraaccessed 2026-09-22
  26. Reported byReport on the 30 additional family and survivor lawsuits filed in September 2026NPRaccessed 2026-09-22

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.