Zendoric
← Back to the day · September 1, 2026

He confessed his school shooting plan to an Anthropic chatbot in Texas: he was arrested, but it is unclear what triggered the alert

🕒 Published on Zendoric: September 1, 2026 · 00:48

✨ AI-generated · how it's made

A 22-year-old man in San Antonio confessed to an Anthropic chatbot his plan to shoot up an elementary school near his home. Police arrested him thanks to an FBI tip, but the affidavit itself leaves a key question unanswered: what triggered the alert and what the AI did with the threat.

By San Antonio Express-News · August 31, 2026.

Nathaniel Michael Carrasco, 22, was arrested on Sunday in San Antonio and charged with a third-degree felony count of making a terroristic threat, according to the arrest warrant cited by the Express-News. The affidavit states that on August 11, days before the school year began, Carrasco wrote to an Anthropic artificial intelligence chatbot: "I'm going to get a gun as soon as I can, and when Serna Elementary starts I'm going to walk in and start shooting the kids." He also asked the chatbot to "look up dead and bleeding schoolchildren" and wrote phrases such as "there will be no escape, no matter what" and "I really do mean my threats." Serna Elementary is right next to his home, near Loop 410 and Perrin Beitel Road. Carrasco remains in the Bexar County jail on a $250,000 bond.

According to the affidavit, the FBI's National Threat Operations Section —the unit that runs the agency's tip line and assesses threats— notified the Southwest Texas Fusion Center, an interagency intelligence center run by the San Antonio Police Department, on Friday. From there, investigators cross-referenced data from Carrasco's phone provider, his IP address and his Google account to identify him. So far, the verifiable facts. But the court document itself, as reported by the newspaper, does not explain how the chatbot responded to those messages nor, above all, how the threat reached the FBI in the first place. It is a gap best not filled with assumptions: there is no public record that it was Anthropic's own system that triggered the alert.

That gap is the story behind the story. The case comes at a time when several generative AI chatbots are being mentioned in investigations into gun violence carried out by young men. In March, the family of a 12-year-old wounded in a school shooting in Canada sued OpenAI, alleging that the company had blocked the 18-year-old suspect over a troubling conversation history but did not alert police; that attack, according to the BBC, left eight dead. In April, Florida Attorney General James Uthmeier opened a criminal investigation into OpenAI after the 20-year-old suspect in a shooting at Florida State University had used ChatGPT to discuss his plans; the attack killed two people and wounded several more. It is worth stressing that these are accusations and lawsuits, not final rulings: the companies' liability remains to be determined in court.

Our reading is that this episode, despite ending without victims, is not proof that "the system works," but rather confirmation that there are loose pieces of a system whose joint operation no one has yet explained publicly. In the OpenAI cases, the criticism is that there were warning signs and they did not translate into a timely alert to the authorities. In San Antonio, something did translate into an alert —and in time, before there was a weapon or a victim— but we do not know whether it was the chatbot that generated it, whether it was a third party who saw the conversations, or whether the route was entirely unrelated to Anthropic. Two companies, three episodes, and in none of the three is there public transparency about the actual protocol: what triggers a human review, when police are notified, and on what criteria. That is a governance problem, not a technology problem: the labs have built content guardrails so the chatbot will not help plan an attack, but they have not explained with the same clarity what they do when someone uses the conversation as a confessional for a real thought of violence.

There is also a social pattern that transcends any single company: young people with violent ideation who find in a chatbot an interlocutor available 24 hours a day, without the filter —or the possible intervention— of a real person. That the target in this case was an elementary school, with young children as potential victims, makes it all the more urgent to close that governance gap before the lesson is learned, once again, after a tragedy rather than before.

This connects with the underlying thesis we hold at Zendoric about AI as a double-edged technology in the short term: the same conversational capability that can accompany, tutor or assist millions of people is also, for a minority in crisis, a space without the safeguards that do exist —with all their imperfections— in human interaction. The answer is not to give up on chatbots, but to equip them with escalation channels to emergency services that are as auditable and public as their content policies. In the long run, that same ability to detect risk patterns at a scale no human moderation team could cover is, precisely, one of the uses where AI could become genuine public-safety infrastructure —one more piece of the promise of a safer society with less avoidable harm. But that future only arrives if companies stop treating these episodes as reputational crises to be managed with silence, and start treating them as what they are: design and process failures that must be audited and corrected in public.

🔗 Related on Zendoric

Sources & references