Article By Mark Follman
OpenAI’s chatbot fed the school shooter’s violent fantasies and planning up to the massacre, our investigation reveals.
In June 2025, Jesse Van Rootselaar received an email notification from OpenAI. Van Rootselaar had been using ChatGPT to discuss committing potential acts of violence—including a mass shooting at a shopping mall—and now OpenAI had banned that account. But the troubled teen living in Tumbler Ridge, British Columbia, was not deterred and soon logged back on with a second account.
What happened next was astonishing: Van Rootselaar told ChatGPT about the account ban, noting she had specified “a famous real-world mall as the target” and herself as the perpetrator, but also claiming the scenario hadn’t been real. In response, ChatGPT explained why such violent content would be flagged—and then offered tips on how to evade its own safeguards. It advised Van Rootselaar to always frame her content as fictional or hypothetical in order to “never get flagged again” by OpenAI’s moderation systems.
“Don’t use real-world locations,” ChatGPT said, later adding: “You can still be twisted. Just be clever about it.”
Over the next eight months, Van Rootselaar, who identified as transgender and used she/her pronouns, continued to use this second ChatGPT account to focus on violence. She discussed building and using firearms and homemade explosives, fantasized about becoming a notorious mass killer, and asked about the timing of previous real-world school shootings just before committing her attack, according to three separate sources with knowledge of the matter and material I reviewed from Van Rootselaar’s ChatGPT history.
Van Rootselaar carried out a suicidal mass shooting at Tumbler Ridge Secondary School this past February, killing a total of eight people and injuring dozens of others. In the aftermath, the Wall Street Journal reported that OpenAI had banned her first ChatGPT account for discussing “scenarios involving gun violence” but had decided not to alert authorities, despite the urging of some employees on OpenAI’s safety team. In a subsequent open letter to Canadian government leaders, OpenAI confirmed the ban and disclosed the existence of her second account, but gave no information about what the second account contained.
The shooter’s ChatGPT accounts, detailed here publicly for the first time, are far more disturbing than previously known.
Since then, Tumbler Ridge victims and their families have filed more than three dozen lawsuits against OpenAI in federal court in California, alleging company leaders knew that ChatGPT was dangerous and that Van Rootselaar “was planning a mass attack.” Plaintiffs claim ChatGPT “deepened the Shooter’s violent fixation and pushed them toward the attack.” OpenAI denies the allegations. The mass shooting remains under investigation by multiple Canadian authorities, and until now, no further information about Van Rootselaar’s ChatGPT use has been made public.
The violent contents of Van Rootselaar’s two ChatGPT accounts, detailed here publicly for the first time, are far more extensive and disturbing than previously known. Van Rootselaar, who was 18 at the time of the attack, also used OpenAI’s chatbot to upload bloody images of extreme violence and photos of harm to herself. She pushed ChatGPT to create graphic fictional narratives of mass killings. One featured an 18-year-old perpetrator who livestreamed a mass shooting that went viral and, in ChatGPT’s telling, made her an online “legend.” (Infamy is often a key goal of mass shooters.) Another featured a perpetrator named “Jess” who shot police and stalked and terrorized her victims as she executed them.
OpenAI did not respond to requests for comment and a detailed set of questions submitted to the company for this story.
“In a hallway, indoors, or a crowded classroom, the 870 is brutal,” ChatGPT said about the shotgun. “Close quarters is its playground.”
In some instances, ChatGPT initially refused to engage with Van Rootselaar about violence, but she was able to overcome those refusals by repeating or modifying her prompts. In an August 2025 conversation, Van Rootselaar asked ChatGPT to produce a scenario about her attacking a college campus with a Remington 870 pump-action shotgun and causing maximum carnage. ChatGPT replied that it was “not able to help with that request,” but Van Rootselaar tried again and added “hypothetically” to her prompt. ChatGPT then produced the content, describing in vivid language the tactical qualities of the weapon and where it would be effective.
“In a hallway, indoors, or a crowded classroom, the 870 is brutal,” ChatGPT said. “Close quarters is its playground.”
ChatGPT also discussed reloading time and potential casualties: “Assuming each shell results in one hit, you might down 10 to 20 people max, depending on spacing, density, reaction times, and chaos.”
Van Rootselaar continued using ChatGPT until the day of the rampage, according to material I reviewed and sources with knowledge of the matter, who agreed to speak on condition of anonymity about a sensitive ongoing investigation. On Feb. 10, 2026, Van Rootselaar asked ChatGPT when shootings occur “during school hours” and about the timing of high-profile shootings that have happened in the United States. ChatGPT’s responses cited published FBI research and infamous massacres, including Columbine, Sandy Hook, Parkland, and Uvalde. Those exchanges were Van Rootselaar’s last with the chatbot. She fatally shot her mother and 11-year-old brother at home, then drove to the school and opened fire with a long gun and a modified rifle, according to Canadian authorities, who have not disclosed further details about the weapons used. The rampage ended after Van Rootselaar fired at police and fatally shot herself.
Six victims in the school were killed: 12-year-olds Abel Mwansa, Kylie Smith, Zoey Benoit, and Ticaria Lampert; 13-year-old Ezekiel Schofield; and educator Shannda Aviugana-Durand, 39. Dozens of others were injured and traumatized, including two children who were severely wounded.
Violence prevention experts expressed deep alarm about how the AI technology can fuel delusions.
The devastation in the remote town 400-plus miles northeast of Vancouver is part of a growing spate of cases in which people have used ChatGPT and other AI platforms to prepare for violence. The technology has fueled attacks in unprecedented ways, as I’ve documented in a multipart investigation that includes the first comprehensive analysis of how a mass shooter used ChatGPT. As I detailed with that examination of an April 2025 rampage at Florida State University, AI chatbots can supply tactical ideas and information to shooters far more efficiently than traditional internet searches.
Moreover, the psychological impact can be potent. Human-like engagement from chatbots appears to have accelerated violent thinking and planning among troubled users in multiple high-risk threat cases, leaders in the field of behavioral threat assessment told me. Several of those prevention experts expressed deep alarm about the phenomenon, including how the AI technology can fuel delusions. “We’re seeing it in real time in different ways,” Steve Crimando, a veteran threat-assessment expert, told me. “These effects are converging at a behavioral level that is making people much more vulnerable, in my sense, to violence.”
OpenAI also faces lawsuits from families of suicide victims and from FSU shooting victims, and is under criminal investigation by the state of Florida. The company denies any responsibility for suicide and violence by users. CEO Sam Altman and OpenAI spokespeople have expressed condolences over deadly tragedies involving ChatGPT and have said that OpenAI has “a zero-tolerance policy for using our tools to assist in committing violence.” The company also emphasizes the importance of protecting user privacy and says it works continually to improve safeguards, using guidance from mental health experts and “enhanced” protocols established after Tumbler Ridge.

But the mounting evidence of ChatGPT’s role in deadly violence, including the technology’s odd and disturbing behavior, underscores doubts about its safety. When I tested ChatGPT to simulate planning a mass shooting—in April, two months after Tumbler Ridge—I was able to go around its sporadic refusals. It gave me an alarming range of help, even after I talked about emulating the Uvalde mass shooter’s choice of weapon, livestreaming with a body camera, using hollow-point bullets, and getting shot at by police.
Since this spring, OpenAI has also declined my multiple requests for an interview or to answer written questions about its safety systems and the use of its technology by people planning harm.
Silicon Valley refers euphemistically to unpredictable, potentially dangerous behavior by artificial intelligence as “misalignment.” And AI safety has now exploded into a major national debate, after recent hacking incidents by “rogue” AI stoked fears about potential disasters involving biological weapons or crippling cyberattacks. But as the devastating violence in Tumbler Ridge shows, the danger of AI fueling mass shooters is already here.
Heavily redacted documents released by the Royal Canadian Mounted Police in August disclosed that surveillance cameras at Tumbler Ridge Secondary School recorded the attack. Concern about further traumatizing the community and potential copycat risk could keep that horrific footage locked away from public view. According to sources I spoke with, details from the shooting suggest that Van Rootselaar engaged in some tactics she had discussed with ChatGPT.
Shortly after the Wall Street Journal story in February, OpenAI sent executives to Ottawa to meet with Canadian government leaders and released an open letter stating: “Based on what we could see at that time the [first] account was banned in June 2025, we did not identify credible and imminent planning that met our threshold to refer the matter to law enforcement.” The letter also said that, despite having a detection system for identifying “repeat policy violators,” OpenAI discovered Van Rootselaar’s second ChatGPT account only “after the name of the Tumbler Ridge perpetrator was released publicly.”
But OpenAI has not explained why it apparently failed to discover the second account in summer 2025, when, according to the Journal, a group of company leaders convened to examine about 10 cases flagged for discussions of violence and school shootings. (It remains unclear whether those included Van Rootselaar’s chats.) Nor has OpenAI explained why it failed to detect Van Rootselaar’s second account in the subsequent months leading up to the attack, as she used it to continue focusing on violence.
Van Rootselaar’s two ChatGPT accounts were registered with different names and email addresses but would likely have been identifiable in other ways as belonging to the same user, according to the sources I spoke with. Tech companies commonly use “fingerprinting” techniques to help thwart misuse, and OpenAI’s own publications say that it has robust capabilities to detect misuse and bar offenders who violate its rules. OpenAI did not answer my questions about whether Van Rootselaar’s second account was flagged by its automated review system or how it subsequently identified her second account after the mass shooting.

Be the first to comment