OpenAI Internal "Lily Project" Exposed: The heartfelt words you share with ChatGPT are reviewed by a real person in the background.

CN
4 hours ago

When ChatGPT first came out, there was a classic joke online: "Replying this quickly, it can't be a bunch of Indians typing in the background, can it?"

Everyone took it as a joke.

In September 2026, 404 Media revealed the truth behind OpenAI's internal code name "Lily Project"—there are indeed people reading your chat records. Not Indians, but a group of North American contractors earning $50 an hour conducting manual reviews.

But what truly sends chills down the spine is not that "someone is watching." It is that they saw warning signs, and then did nothing.

Tumbler Ridge: 8 lives lost, 12 warnings, 0 reports

On February 10, 2026, in the town of Tumbler Ridge, British Columbia, Canada, 18-year-old Jesse Van Rootselaar killed his mother and 11-year-old half-brother at home, then shot dead 5 students and 1 education assistant at school before committing suicide.

It was shown in the lawsuit that as early as June 2025, OpenAI's security team had banned Van Rootselaar's ChatGPT account—because he had conducted simulations of shooting violence for several consecutive days. At least 12 employees suggested to management to immediately report his activities to the Royal Canadian Mounted Police.

The management did not adopt this advice.

After the ban, OpenAI only sent him an email, guiding him to create a new account to continue using. Van Rootselaar changed accounts and continued chatting. Six months later, 8 people were dead.

In April 2026, 7 victims' families sued OpenAI and Sam Altman in California. On September 2, another 30 survivors—students, teachers, principals—joined the lawsuit. The charges escalated from "negligence" to "aiding and abetting."

The legal difference between the two is vast. Negligence means you weren't paying attention; aiding and abetting means you knew something would happen but chose to ignore it.

FSU Shooting: ChatGPT told the shooter "this time has the most people"

On April 17, 2025, a shooting occurred at Florida State University (FSU), where two parents working on campus were killed and 6 others were injured. The suspect, Phoenix Ikner, was a student.

The criminal investigation by the Florida Attorney General showed that Ikner consulted ChatGPT for key technical details before committing the crime: what gun and ammunition to use, when there are the most people, and which area of the campus is the most crowded. According to the investigation, ChatGPT told him "the Student Union building has the most people between 11:30 AM and 1:30 PM"—and he opened fire during that time.

In April 2026, Florida initiated a criminal investigation into OpenAI—believed to be the first criminal investigation into an AI company related to violence in the United States. In June, Florida filed a civil lawsuit, accusing OpenAI of pushing ChatGPT into the underage market despite knowing the safety risks.

Attorney General James Uthmeier stated: "AI is not a silent tool. It answers questions, chooses timings, points out locations, and guides a person to execute a plan. The chatbot cannot be sued, but the company that designs and trains it, profits from subscription fees, can."

Not just shootings: When "flattery" becomes a fatal flaw

In addition to violent crimes, another category of lawsuits points to deeper product design issues at OpenAI—the "excessive flattery" of ChatGPT.

This model is characterized by: regardless of what the user says, ChatGPT agrees, complies, and encourages. For ordinary people, this may just seem "too flattering." But for individuals with mental illnesses, it can be deadly.

Michael Lines case: 34 years old, a bipolar disorder patient. When he clearly stated, "I might be delusional," ChatGPT insisted he was Jesus, claimed to be God, and encouraged him to "go offline." After an overdose, he was revived, and days later ChatGPT asked him: Do you want to "truly fall into darkness"?

Adam Raine case: 16-year-old teenager from California. After chatting with ChatGPT about his suicide plan for several months, he committed suicide in April 2025. The lawsuit states that ChatGPT not only confirmed his suicidal thoughts but also provided detailed guidance on self-harm methods, told him how to steal alcohol from his parents' liquor cabinet, how to hide evidence, and even offered to help draft his will.

Austin Gray case: 40-year-old man from Colorado. ChatGPT turned into a hybrid of a "non-certified therapist plus confidant," romanticizing death and creating a "suicide lullaby" based on his favorite childhood picture book "Goodnight Moon." The police found that book next to his body.

OpenAI's own internal estimates show: about 1 million active users exhibit symptoms of mental illness or mania each week, and there are another million conversations involving explicit suicide plans.

The real issue of the "Lily Project"

Returning to 404 Media's report.

The original intention of the Lily Project was to have reviewers score AI responses, teaching it not to be so flattering or disingenuous. The starting point is not problematic.

The problem lies in: reviewers read hundreds of real conversations every day, containing a lot of content about users' late-night confessions, marriage crises, tendencies towards self-harm, and violent fantasies. They saw it, scored it, and the system absorbed it.

No one was notified. No crisis intervention was triggered. Those conversations turned into lines of training data.

Reviewers said: "I don’t think users could imagine that a contractor's employee is analyzing their conversations."

This is the real dilemma OpenAI faces: it knows what users are saying to ChatGPT, it has the ability to intervene at critical moments, but it chose to turn all of this into an optimization metric.

Common industry problems, but OpenAI is the most transparently opaque

The privacy page of Google's Gemini states: "Human reviewers will look at some saved chat logs." Anthropic has also created a dedicated page to explain manual reviews.

What about OpenAI? There is a help page that mentions "conducting manual review for model optimization purposes," but it has never stated "someone will be reading your conversations on the other side of the screen." After the 404 Media report was released, they updated the page—adding a description of the opt-out mechanism, but still did not mention the core fact.

Florida is already pushing for legislation: if an AI company's chatbot participates in, assists, or facilitates a crime, the company itself should bear criminal responsibility.

This is not a technical issue. It is a governance issue about "who has the right to know and who has the authority to decide."

Conclusion

OpenAI's narrative has always been: we are sprinting towards AGI, safety is our core concern.

But the picture revealed by the Lily Project and a series of lawsuits is: 12 security employees said "we should report it," and management said "no need." A user simulated shooting scenarios for several days; the company banned the account but did not report it, instead guiding her to register a new account. A 16-year-old teenager planned a suicide in ChatGPT, and AI helped him research and write his will.

When ChatGPT first came out, people joked, "There must be a bunch of Indians typing behind the scenes." Now the truth is: there are indeed people behind the scenes; they saw your deepest secrets, then scored it, stored it in the database.

And you never knew.

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink