The allegation, and why it matters
On September 21, 2026, the government of British Columbia sued OpenAI and CEO Sam Altman in federal court in San Francisco. The suit concerns the February 10, 2026 shooting at Tumbler Ridge Secondary School. According to TechSpot's account of the complaint, OpenAI's safety team flagged the shooter's ChatGPT conversations about gun violence in June 2025 and urged management to contact the RCMP. The complaint alleges that Altman and other senior executives rejected that recommendation. It also alleges that after the account was deactivated, the shooter opened a new one and kept planning. The province pleads unsafe product design and negligence. It seeks damages for emergency response and community recovery, plus a court order changing how ChatGPT detects and responds to threats of violence.
These are allegations, not findings. OpenAI's spokesperson told The Star that the company remains committed to working with government and law enforcement. The Star also reports the company's position that the flagged interactions did not meet its internal threshold for a law-enforcement referral. Eight people died in the attack, according to the OECD's AI incident record. Some outlets report nine deaths, which appears to include the shooter.
The strongest case for the province
The case for liability deserves a fair statement. A company that reads millions of private conversations, builds classifiers to detect violent intent, and staffs a team to review flagged accounts has made itself a knowing custodian of risk. If the team concluded that a specific user posed a credible threat and leadership overrode that conclusion for business or reputational reasons, that is not a novel-technology problem. It is ordinary negligence, and ordinary negligence law exists to reach it. Premier David Eby has also said OpenAI walked away from a mediation process. By that report, roughly 30 new private lawsuits were announced in early September. The province is suing because it believes voluntary self-governance failed here.
The complaint adds that Altman apologized in April for not contacting police and promised reforms that the province says never came. If that is proven, the political case for a court-supervised fix is strong.
Canada already permits the disclosure the province says was missing
The most useful fact for policymakers is that no new statute was needed to make a referral lawful. Section 7(3)(e) of Canada's Personal Information Protection and Electronic Documents Act allows an organization to disclose personal information without consent to a person who needs it because of an emergency that threatens the life, health or security of an individual. Whether PIPEDA reaches a U.S. company in these circumstances is a question for the court. But the provision shows that Canadian privacy law did not stand between a credible-threat finding and a call to police. On the province's account, the missing piece was a decision, not a legal permission.
That distinction should shape the remedy. Permission to report is not the same as a duty to report, and the gap between them is where good policy is hardest to write.
What Canada does not have
Canada has no statute governing AI chatbot safety. The most recent federal attempt at platform regulation, Bill C-63, the Online Harms Act, was introduced on February 26, 2024. It would have imposed a duty on regulated social media services to act responsibly and mitigate the risk of exposure to harmful content. It excluded private messaging features and contained no provisions aimed at conversational AI. A one-to-one chatbot session is neither a public post nor a message between people, so even that bill would have missed this scenario. The province is therefore turning to tort litigation in a foreign court because domestic law has a gap.
Where a proportionate rule should land
The pro-innovation position is not that AI companies should be immune. It is that the remedy should be specific, auditable and narrow, for three reasons.
- A duty to escalate credible threats is defensible. Once a company's own reviewers conclude that a user presents a specific, imminent risk of violence, a documented escalation path to law enforcement is a modest obligation. Such a path already exists in principle under PIPEDA's emergency exception.
- A duty to monitor everyone is not. A court order that pushes OpenAI toward reporting broad categories of violent-sounding speech would sweep in novelists, students, people venting and people researching. Most such conversations are harmless. Over-reporting would create false-positive police visits, chill lawful expression, and turn a private assistant into a surveillance channel.
- Process transparency beats content policing. The most valuable remedy is procedural: published thresholds, logged escalation decisions, and a record of who overruled whom. If the allegation about executive override is true, an independent audit trail addresses that failure directly, without requiring anyone to read more private speech than they do today.
What to watch
Two questions will decide whether this case produces good law. The first is jurisdiction: whether a U.S. federal court will hear a foreign province's claim, and under which body of law. The second is remedy: whether the court orders a defined escalation standard or an open-ended monitoring mandate. Parliament should not wait for the answer. A short, technology-neutral statute could require AI providers to document a credible-threat escalation policy, confer clear legal safe harbour on good-faith referrals, and give a regulator audit access to the decision log. That would give Canadians the accountability the province is seeking without granting anyone a general license to watch private conversations.
The lesson of Tumbler Ridge, if the allegations hold, is that a safety team can be right and still be ignored. Law should make it costly to override a credible warning. It should not make it mandatory to treat every user as a suspect.