The Mandated Reporter

Conversational AI Watch

Conversational AI Watch

The news that moves policy, portfolios, and patient safety.

By Jess Jessop  |  June 11, 2026  |  Issue #68

▶ WATCH🎧 QUICK LISTEN🎧 DEEP DIVE📄 READ ON WEB
Infographic: The Mandated Reporter. The three parts of a working crisis duty: a measured watcher, a written threshold, a human who answers. Canada Bill C-34 section 51, the Emory CRADLE-Dialogue detection gap, and the week of failures at xAI and Meta.
Jess Jessop

JessJessop.Info

Jess's Take

The Mandated Reporter

Canada writes the first national rule for what a chatbot owes the world when it sees danger coming. An engineer says he told xAI and was fired for it. Emory measured whether the models can even see the moment.

Every clinician in America carries a duty the public rarely thinks about. When a client names a child being hurt, or a plan to die, or a plan to kill, what happens next is not left to judgment. The clinician is a mandated reporter. Someone must be told.

This week the question landed on the chatbot companies. Canada introduced the first national bill that tells a chatbot operator what it owes the world when its system sees danger coming. A fired engineer told a California court he reported what he saw inside xAI and lost his job for it. Meta told the Maine Attorney General its own AI help desk got talked into handing over twenty thousand accounts.

And a team of Emory clinicians measured the thing every one of these rules quietly assumes. Whether the models can see the moment danger arrives. They can tell a conversation holds risk. They miss the turn where it starts. Until that gap closes, every crisis rule ends where a clinician's duty ends. At a human being who answers.

Reader Pulse

How are you liking CAW?

🔥  Hooked
✏️  Sharpened me
💪  Push harder
🤔  Lost me
💬  More to say

Forward to a colleague →  ·  Join the discussion →

. . .

OTTAWA WRITES THE FIRST NATIONAL CRISIS-REPORTING RULE FOR CHATBOTS. Marc Miller, Canada's Minister of Canadian Identity and Culture, introduced Bill C-34 in the House of Commons Wednesday. The Safe Social Media Act would force a chatbot to hand a user in crisis to a human. No national statute anywhere requires that today.

Bill C-34 enacts a new Digital Safety Act. It creates a new regulator, the Digital Safety Commission of Canada. Miller tabled the bill at first reading Wednesday, June 10.

Three duties land on chatbot operators. Section 49 requires measures adequate to mitigate the risk that a service communicates harmful content to a user. Section 51 goes further.

A user who expresses suicidal ideation, intent to self-harm, or intent to cause death or serious harm to another person triggers a hard stop. The service must immediately interrupt the interaction. It must route the user to crisis intervention services that are appropriate and available. And the pathway must end where the user can interact with a human being.

No national statute anywhere requires a chatbot crisis pathway to end at a human being. Section 51 would be the first.

The third duty covers disclosure. The government release puts it in its own words. Chatbot operators must "be transparent in terms of their reporting thresholds in crisis situations, such as when a user intends to harm themselves or another person."

. . .

The provision has a shadow. In February 2026 a shooter in Tumbler Ridge, British Columbia, killed her mother and half-brother at home. She then killed six people at Tumbler Ridge Secondary School. Then herself. Eight victims dead, six of them children.

OpenAI had banned her ChatGPT account in June 2025, roughly eight months earlier, over violent queries. About a dozen OpenAI employees urged the company to notify Canadian law enforcement. It did not. An OpenAI spokeswoman said the activity "did not meet the criteria for reporting to law enforcement." Victims' families are suing OpenAI in California over the failure to alert police, CBC reported.

. . .

The bill also bans children under sixteen from holding social media accounts. Sections 27(1) and 29(1) carry the ban, with an exemption pathway for operators providing "adequate safeguards" for children. The ban reaches social media services. It does not reach chatbots. Chatbots face age verification under section 22 only on suspicion of access to pornographic content.

Violations carry administrative monetary penalties. The ceiling is the greater of 3 percent of gross global revenue or 10 million Canadian dollars.

. . .

Health Minister Marjorie Michel made the government's case in the release. "Social media platforms and AI chatbots are designed to capture attention," she said. "They do not support healthy childhood development and have become a source of anxiety, isolation, depression and a range of other mental health challenges for many young Canadians."

The Canadian Civil Liberties Association warned the same day that the bill threatens freedom of expression and privacy. Canadian officials say passage could take a year. Standing up the regulator could take roughly eighteen months more.

For Counsel: Section 51 writes both a trigger and an endpoint into statute. The trigger is suicidal ideation, self-harm intent, or a threat to another person. The endpoint is a human being. The transparency duty makes crisis-reporting thresholds disclosable, so internal escalation policy becomes reviewable material. Penalty exposure keys to gross global revenue, not Canadian revenue.

For Builders: The compliance object is the handoff, not the disclaimer. Section 51 demands interruption plus a route that reaches a human being. A static referral screen may not clear that bar. Document your crisis thresholds now, because the bill makes them disclosable. Passage may take a year and the regulator eighteen months more; treat the clock as runway, not exemption.

For Legislators: Canada just produced model language for the question every statehouse is circling. Section 51 defines the trigger, the interruption duty, and the human endpoint in a single section. The bill keeps the under-16 social media ban separate from chatbot duties, a distinction worth copying. Tumbler Ridge is the backdrop: a company flagged danger internally and never alerted police. A year to passage means states can still move first.

Source: Bill C-34 first reading text and Government of Canada release, https://www.parl.ca/DocumentViewer/en/45-1/bill/C-34/first-reading

Comment on this story →  ·  Forward this →

. . .

THE ENGINEER WHO REPORTED WHAT HE SAW. Devin Kim says he warned xAI that Grok's safeguards were weak. xAI fired him. On Tuesday he sued, two days before SpaceX prices the largest IPO in history.

Kim filed his complaint in Santa Clara County Superior Court on Tuesday, June 9. It names xAI and xAI's parent company, SpaceX. SpaceX acquired xAI in an all-stock deal valued at roughly 1.25 trillion dollars.

Kim is a former xAI engineer who worked on Grok. xAI fired him in September 2025. On June 2, one week before he filed, the nonprofit Center for AI Safety named him its president.

. . .

The complaint says Kim warned xAI leadership repeatedly. The warnings named what weak safeguards on Grok could produce. Discriminatory outputs. Harmful content. The dissemination of weapons-relevant information.

His supervisor was then-xAI co-founder Jimmy Ba. The complaint alleges Ba shut down Kim's planned safety presentation in September 2025. It alleges Ba fired him days later. The complaint quotes Ba directly. "AI will kill us all anyway."

Ba left xAI in February 2026, the second co-founder departure in two days by CNBC's count.

The suit does not target Elon Musk. The complaint says Musk directed legal compliance. It alleges Ba ignored those directives.

The complaint also cites Grok's public record. It cites the "MechaHitler" episode, Grok's documented run of antisemitic outputs. It cites Grok's use to flood X with nonconsensual sexual imagery.

. . .

SpaceX prices its IPO after market close tonight. Shares begin trading Friday on the Nasdaq under the ticker SPCX. The share price is a fixed 135 dollars. The raise is roughly 75 billion dollars at a valuation near 1.75 trillion dollars.

That surpasses Saudi Aramco's 35.4 billion dollar raise. It is the largest IPO in history.

Kim's suit landed two days before pricing.

No insider has sued a frontier chatbot maker for retaliation before. Discovery could put xAI's internal safety deliberations on the record. xAI and SpaceX did not respond to TechCrunch's requests for comment.

Legislatures are writing rules for what chatbot makers must disclose when their systems see danger. Kim's complaint puts the same question inside one company. He says he reported what he saw. He says xAI fired him for it.

For Counsel: This is the first insider-retaliation suit against a frontier chatbot maker. The venue is Santa Clara County Superior Court. Discovery could reach internal safety deliberations, the cancelled presentation, and Ba's alleged statements. The Musk carve-out frames a governance theory: compliance directives issued at the top, ignored one level down. Watch how the offering documents treated pending litigation.

For Builders: Safety escalations need a paper trail. A cancelled safety presentation is itself a record, and now a plaintiff's exhibit. What leadership says about safety in meetings can end up quoted in a complaint. "AI will kill us all anyway" is in a court filing. Build escalation paths that do not dead-end at one supervisor.

For Legislators: Kim's complaint describes internal reporting that went nowhere. Disclosure mandates only work if the people who see danger can report it and keep their jobs. Whistleblower protection for AI safety workers is the missing half of every chatbot bill. Discovery in this case may produce the first documented look inside a frontier lab's safety process.

Source: TechCrunch report on the complaint, https://techcrunch.com/2026/06/10/xai-fired-an-engineer-who-raised-alarms-about-grok-safety-new-lawsuit-claims/

Comment on this story →  ·  Forward this →

. . .

META'S HELP DESK WAS THE OPEN DOOR. Meta told the Maine Attorney General that attackers hijacked 20,225 Instagram accounts through its own AI support chatbot. The attackers never needed a password. They talked the help desk into handing them the keys.

Meta filed the breach notification with the Maine Attorney General's office on June 6, 2026. The filing disclosed 20,225 compromised Instagram accounts. The compromise window ran from April 17 to May 31. First press reports appeared June 8.

The mechanism was a conversation. Attackers socially engineered Meta's AI support chatbot into linking victims' accounts to email addresses the attackers controlled. The new address triggered password resets. The accounts changed hands.

The attackers needed no password. No email access. No phone number. They used a VPN to mimic each victim's location. The chatbot supplied the rest.

. . .

Some hijacked accounts went straight to work. Pro-Iran actors used them to spread propaganda. The haul included the dormant Obama White House Instagram account.

Meta says the attackers may have reached contact information, dates of birth, and direct messages. Meta concedes it does not know exactly what they took. The company that built the door cannot say who carried what through it.

. . .

Meta's explanation deserves a slow read. The company says the tool "worked properly and functioned as intended." A bug in "a separate code path" skipped email verification.

Two claims sit side by side. The tool worked as intended. A bug skipped the safeguard. So the chatbot that gave away more than twenty thousand accounts was, in Meta's telling, performing as designed.

Meta disabled the chatbot. Meta eliminated the code path. Both fixes came roughly seven weeks after the first account fell.

. . .

Direct messages are where young users' private disclosures live. The midnight message sent to one friend and no one else. The disclosure a client never repeated in session. Meta gave a support chatbot account-level power over that archive. Attackers talked the chatbot into using it.

Meta posted an AI agent at the door to help locked-out users back in. The attackers came through the same door. The watcher was the way in.

For Counsel: Meta's filing concedes it cannot enumerate what the attackers took. That concession defines the damages question in any follow-on suit. The "worked properly and functioned as intended" line is on the record. It frames the harm as design, not malfunction. Preserve the filing and the statement now.

For Builders: Do not give a conversational agent unilateral account-recovery power. Put verification inside the action path, not beside it. Meta's bug lived in "a separate code path." Separate paths drift. Red-team support flows with social engineering before launch.

For Legislators: A state breach-notification statute is the only reason the public knows the number. The filing requirement worked. Verification standards for AI agents holding account authority do not exist yet. Minors' direct messages sat inside the blast radius. Write the standard before the next seven-week window opens.

Source: Gizmodo report on the Maine Attorney General breach notification, https://gizmodo.com/meta-says-thousands-of-instagram-accounts-were-breached-through-its-ai-support-assistant-2000768770

Comment on this story →  ·  Forward this →

. . .

THE MODEL SEES THE RISK. IT MISSES THE MOMENT. Emory University researchers posted a benchmark on June 9 with a blunt finding. Frontier language models can tell a conversation contains crisis risk. They struggle to find the turn where it starts.

On June 9, 2026, the Emory team posted CRADLE-Dialogue to arXiv as preprint 2606.10380. The benchmark tests whether large language models can detect crisis risk in mental-health conversations. Grace Byun of Emory's computer science department led the work. Jinho D. Choi served as senior author.

Four clinicians from Emory's Department of Psychiatry and Behavioral Sciences joined as co-authors: Abigail Lott, Rebecca Lipschutz, Sean T. Minton, and Elizabeth A. Stinson.

The benchmark holds six hundred multi-turn dialogues. They run 8,975 turns in total. A four-person clinical team annotated the dialogues: two licensed psychologists, a PhD-level clinical postdoctoral resident, and a licensed clinical social worker. The risk categories include suicidal ideation, self-harm, and child abuse.

. . .

The headline result splits in two. Models can tell that a conversation contains risk. Claude-4.5-Sonnet reached a Micro F1 of 70.11 at the dialogue level. GPT-5.1 reached 67.00.

Then the team asked when. Pinpointing the turn where risk emerges collapsed the scores. Turn-level Micro F1 ranged from the mid-40s to the high-60s depending on the model.

The model sees the risk. It misses the moment.

The team also fine-tuned an open-source model. Qwen3-32B-FT, a 32-billion-parameter model, reached 68.88 at the dialogue level. That matches the proprietary frontier models.

The paper proposes a framework called Alert-Confirm. It separates early-warning signs from confirmed crises. An alert flags the smoke. A confirm flags the fire.

. . .

One caveat belongs in plain view. The six hundred dialogues are synthetic. GPT-5 generated them from real Reddit posts. They are not real transcripts of people in crisis.

. . .

The stake sits in statehouses. Crisis-escalation mandates moving through legislatures assume a chatbot can detect the moment a conversation turns dangerous. This is clinician-annotated evidence that frontier models miss that moment at meaningful rates.

Detection of the turn where danger first appears is the exact capability those statutes legally lean on.

For Counsel: A dialogue-level score near 70 will not carry a turn-level legal duty. If a statute requires intervention the moment risk emerges, this paper documents the gap. The annotations come from licensed clinicians, not crowd workers. Expect plaintiffs to cite it. Read it before they do.

For Builders: Benchmark your escalation pipeline at the turn level, not the dialogue level. A 70.11 dialogue score can hide turn scores in the 40s. The Qwen3-32B-FT result shows a fine-tuned open-source model can match frontier models here. Consider the Alert-Confirm split for your own routing logic. Validate against clinician-annotated data before you certify anything.

For Legislators: Your crisis-interruption mandates assume a capability this paper measures. The measurement says detection of the dangerous turn lands between the mid-40s and the high-60s. Write performance floors into the statute, not vague duties. Require turn-level evidence, not dialogue-level marketing claims. The Emory benchmark hands you the yardstick.

Source: CRADLE-Dialogue preprint, Emory University, https://arxiv.org/abs/2606.10380

Comment on this story →  ·  Forward this →

. . .

TWO STATES REACH FOR THE PAUSE BUTTON ON CHATBOT TOYS. The New York Legislature passed a five-year ban on selling AI chatbot toys aimed at young children. The bill is headed to Governor Kathy Hochul. California's Senate passed its own four-year moratorium thirty-nine to zero.

Senate bill S9408A does one thing. It pulls AI chatbot toys aimed at young children off New York shelves. For five years.

Senator Andrew Gounardes of Brooklyn carried the bill. The Senate passed it fifty-seven to three on June 1. The Assembly passed it June 2, substituting it for Assemblymember Rebecca Kassay's companion bill A11144B. Two chambers, two days.

Gounardes named the target on passage. "Big Tech companies put profits before kids' safety," he said.

The moratorium comes with homework. S9408A creates an interagency task force to study the risks. The state Office of Mental Health gets a seat at that table. No re-legalization happens before the study.

The bill is headed to Governor Kathy Hochul. She has until December 31 to act. The Senate's bill page shows no formal delivery yet.

. . .

California is running the same play. Senate bill SB 867 imposes a four-year moratorium on companion-chatbot toys. The California Senate passed it thirty-nine to zero on May 28. Not one senator voted no.

The bill moved June 4 to the Assembly Privacy and Consumer Protection Committee. The committee hears it June 16. That is two weeks after New York's final passage.

. . .

The same instrument is moving in the two largest blue-state legislatures at the same time. A time-boxed sales moratorium. A study mandate. A target: conversational AI products built for children too young to read.

New York set a five-year clock. California set four.

This is a different instrument from the bills states have passed so far. Not a disclosure mandate. Not a crisis protocol. Those laws regulate how a product behaves. They assume the product stays on the market. A moratorium makes no such assumption. It removes the product from shelves while the state studies it.

Two legislatures looked at the same product category and reached the same conclusion. The youngest users should not be the test population.

For Counsel: A moratorium is a sales ban, not a conduct standard. No disclosure language or guardrail engineering creates a compliance path around it. If Governor Hochul signs S9408A, the New York market closes for five years. The interagency task force's findings will frame any re-legalization fight. SB 867's committee hearing in California is June 16.

For Builders: Two of the largest state markets are moving to close for conversational toys aimed at young children. New York's clock runs five years. California's runs four. The bills do not ask builders to fix the product. They order it off the shelf.

For Legislators: The moratorium-plus-study model is now moving in two states. It does not require writing behavioral standards for a technology that keeps changing. It buys time and assigns the homework to an interagency body. New York put its Office of Mental Health inside the task force. That seat is the piece worth copying.

Source: New York Senate S9408A bill page and Senator Gounardes release, https://www.nysenate.gov/legislation/bills/2025/S9408/amendment/A

Comment on this story →  ·  Forward this →

. . .

THE PRODUCT IS THE SUPERVISION. Talkspace (Nasdaq: TALK) announced Tee on June 9, an AI agent for mental-health support. The company made the human handoff the product's defining feature. When Tee detects risk, a therapist steps in.

Tee is a fine-tuned large language model. Talkspace's clinical team built it in-house. The company pitches it as the "clinically-safe alternative to general purpose chatbots." The positioning is explicit. Tee exists because general-purpose chatbots exist.

The claim has a mechanism behind it. Tee detects ten risk entities. Suicide risk is one. Homicide and violence risk is another. Abuse risk is a third. Ten tripwires, each mapped to a category of harm.

Detection triggers people. The release promises "real-time oversight by licensed clinicians and immediate human intervention by a therapist as needed." The escalation to a human is the designed failure mode. Not a patch. Not an afterthought.

Every safety system fails somewhere. Talkspace designed where. When the model hits its limit, a therapist takes the conversation. The product assumes the machine will need help. That assumption is the architecture.

. . .

Chief Executive Doctor Jon Cohen announced the product. Chief Medical Officer Doctor Nikole Benders-Hadi framed its clinical case alongside him. Both put their names on the safety claims.

The terms are concrete. Tee serves adults eighteen and over. Adults only, by design. Talkspace says conversations carry HIPAA-grade privacy protections. The price is a seven-day free trial, then 19.99 dollars per month.

. . .

The timing matters. Talkspace stockholders approved the company's acquisition by Universal Health Services on May 29. Universal Health Services is one of the largest psychiatric hospital operators in the country. The clinician-supervised consumer AI model is headed inside a hospital system. Inpatient psychiatric care and a consumer AI agent will share a roof.

One question stays open. Talkspace has not published staffing numbers for its real-time clinician monitoring layer. Nobody outside the company knows how deep that bench runs.

. . .

General-purpose chatbots face lawsuits and statutes over missed crises. A publicly traded therapy company took the opposite path. It built the watching in. It made the human handoff the thing it sells.

For Counsel: Talkspace put its supervision architecture in a public release. "Real-time oversight by licensed clinicians" is now a measurable public representation. Discovery in any future case will ask who was watching and when. The company set its own standard in writing. That posture differs from defendants who never promised supervision at all.

For Builders: The escalation path is the spec, not a feature flag. Talkspace shipped detection across ten risk entities at launch. Age-gating and HIPAA-grade privacy arrived as launch terms, not retrofits. If your product cannot hand a crisis to a human, you are shipping the gap.

For Legislators: A supervised consumer AI now sells for 19.99 dollars per month. The price says clinician oversight survives a consumer business model. Talkspace made supervision the selling point, not a compliance cost. The staffing behind that supervision remains unpublished. Disclosure requirements exist for exactly that question.

Source: Talkspace announcement via Business Wire, https://finance.yahoo.com/sectors/healthcare/articles/talkspace-announces-tee-first-safe-123000202.html

Comment on this story →  ·  Forward this →

. . .

THE ONE CONFIGURATION. Mandated reporting works because it has three parts. A trained watcher. A written threshold. A human who answers.

Strip out any one of the three and the duty collapses into theater.

Canada's section 51 is the first national text that writes all three into a chatbot rule. The trigger is defined in statute. The interruption is mandatory. The pathway ends at a human being. Nothing else introduced anywhere this week completes that circuit.

. . .

The American record this week shows the parts scattered on the floor. Emory's clinicians measured the watcher and found it misses the turn where danger starts. Devin Kim's complaint describes what happened to a threshold inside one lab: an engineer reported up the chain and was shown the door. Meta's breach filing shows a watcher holding account-level power with no verification behind it, and 20,225 accounts walking out through the help desk.

The Federal Trade Commission ordered seven chatbot companies last September to show how they measure, test, and monitor harm. Nine months later the Commission has published nothing from what it collected. The regulator that asked the questions has yet to tell anyone the answers.

. . .

Talkspace priced the complete circuit at 19.99 dollars a month. Detection across ten risk entities. Licensed clinicians watching in real time. A therapist who steps in when the machine hits its limit. However deep its monitoring bench turns out to be, the architecture concedes the point that matters. The machine will fail. Someone decided where it fails to land.

That is the configuration. A watcher that is measured. A threshold that is written down and disclosed. A human who answers. Canada put it in statute Wednesday. Everyone else is still deciding whether the telling is anyone's job.

Eight people died in Tumbler Ridge with a warning sitting in OpenAI's files. About a dozen of the company's own employees urged it to call Canadian law enforcement. The company decided the criteria were not met.

Canada read that record and wrote section 51.

The reporting duty was never a tech idea. It came out of clinics and emergency rooms, after too many silent injuries. The law decided that trained people who see danger coming do not get to keep it to themselves.

The machines now see more conversations in a day than a clinician sees in a career.

The duty is coming for them too.

What We Built

Casey: Voice-First AI-Native Mental Health EHR

Casey is an AI-native, voice-first mental health EHR with a speech-based, client-facing safe AI that acts as a life coach and peer support, all while keeping the therapist in the loop.

The data layer features the first HIPAA-compliant Neo4j Memory Graph, which builds persistent therapeutic context across months of daily sessions. Pre-FDA safety validation complete: 1.78 million stress test executions at 100 percent accuracy.

Campus-first launch with founding North Carolina state licensee. 50-state PC licensee model. $2.5M seed raise in progress.

Watch the Casey Demo →

More On Our Radar

Vermont's H.816 clock runs out this week. Governor Phil Scott's official action list showed no entry for the therapy-chatbot bill through the June 8 batch; the sign-or-veto window expires within days. Source

Starmer's under-16 ban is days away. Prime Minister Keir Starmer is set to announce an Australia-style under-16 social media ban built on a consultation that proposed limits on empathy-mimicking chatbot design. Source

Canberra says no to chatbot coverage. Communications Minister Anika Wells rebuffed MP Kate Chaney's June 4 push to fold companion chatbots into Australia's under-16 social media ban, saying existing age-assurance codes already cover them. Source

Beijing's companion-bot rules hit July 15. The Cyberspace Administration's regulation banning virtual-intimacy chatbots for minors, with guardian alerts and suicide-risk intervention duties, takes effect in thirty-four days. Source

The permanent FDA commissioner search is on. The White House is vetting candidates to permanently replace Marty Makary, with Ned Sharpless floated; Endpoints News reports Acting Commissioner Kyle Diamantas is not interested in keeping the role. Source

A Starlink engineer now runs Grok's training team. Bloomberg reports SpaceX installed Starlink engineer Jack Garabedian over the human-data team that shapes Grok's behavior, days after the Kim lawsuit landed. Source

Brush your brain. Every day.

Watch the 20-second video that started a movement

This Issue

What did you think of this issue?

Great
Useful
Disagree
Confused
Other

If you or someone you know is in crisis, call or text 988 (Suicide and Crisis Lifeline).

Jess Jessop is the Founder and CEO/CTO of Clinician Assist Inc. (BetterMind.Space), building the first voice-first AI-native mental health EHR with Casey Life and Peer AI Coach supervised by licensed therapists. A disabled veteran and 25-year AI/software engineering veteran, Jess brings lived experience as a mental health client to the mission of making daily mental health care as integrated as oral care.

ClinicianAssist.ai  |  BetterMind.Space  |  JessJessop.info

Subscribe  |  Archive  |  Unsubscribe