Do Criminal Threat Statutes Cover AI-Generated Ransom Notes?
Existing federal and state criminal threat statutes are medium-neutral and apply on their face to AI-generated ransom notes, but prosecutors will face novel intent, authentication, and authorship challenges when the threatening communication was authored by a language model. This article maps the applicable statutes and identifies the key defense arguments and evidentiary gaps.
- Jurisdiction
- US Federal
- Court
- General federal courts
- AI tool named
- Generative AI (unspecified)
- Ruling date
- Jul 24, 2026
- Source document
- View primary court order ↗
- Last verified
- Jul 24, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
A prosecutor does not need a new “AI ransom note” statute before opening the code book. The first question is still whether a human transmitted a threatening communication that fits an existing offense. On the face of the main federal statutes, the medium is not the hard part: 18 U.S.C. § 875(a) reaches “any communication” containing a ransom demand transmitted in interstate or foreign commerce and authorizes imprisonment of up to 20 years; other subsections cover extortion threats and threats to kidnap or injure.[1] Section 876 separately covers threatening communications deposited in the mail, with penalties that include up to 20 years for ransom demands and lower ranges for certain threats to injure.[2]
That answer is important because it is easy to overstate the novelty. A ransom demand drafted by a language model, converted into a synthetic voice message, or embedded in an AI-generated image is still capable of being a “communication.” The statutory problem begins later, when the courtroom has to decide whose communication it was, what the sender intended, whether the message is authentic, and whether the government can prove those points beyond the familiar evidentiary haze that now surrounds synthetic media.

The Statutes Start Broadly
Section 875 is the cleanest federal starting point for an AI-generated ransom note sent by text, email, social platform, cloud link, encrypted message, or synthetic voice call crossing interstate channels. Congress did not limit the offense to handwriting, paper, telegraphy, or human-composed prose. The word “any” does real work. If the government can prove a qualifying transmission in interstate or foreign commerce and the content contains the prohibited ransom demand or threat, the fact that software helped generate the words does not by itself take the case outside the statute.[1]
Section 876 is narrower in delivery method but similarly indifferent to literary origin. It is about threatening communications deposited in the mail. A defendant who uses a model to draft a ransom demand, prints it, and mails it has not escaped the statute because the first draft came from a machine. The mailing hook may be old-fashioned, but it is not conceptually weaker for synthetic text.[2]
State law can be more element-sensitive. California Penal Code § 422, for example, requires a willful threat, specific intent that the statement be taken as a threat, and resulting sustained fear for the victim’s safety or the safety of immediate family; the offense is described as a wobbler and may carry up to three years, with possible strike consequences.[3] That structure matters because AI does not merely change the appearance of the message. It can complicate the proof of willfulness and specific intent in a way the statutory text itself does not resolve.
| Law | Useful hook | AI-generated note issue |
|---|---|---|
| 18 U.S.C. § 875 | “Any communication” in interstate or foreign commerce containing covered ransom demands or threats | The medium is likely covered; proof shifts to transmission, intent, authorship, and interstate-commerce facts. |
| 18 U.S.C. § 876 | Threatening communications deposited in the mail | AI drafting does not defeat the mailing theory, but the government still must tie the mailed item to the defendant. |
| California Penal Code § 422 | Willful threat, specific intent, and sustained fear | The strongest disputes may concern what the human intended and whether the victim’s fear meets the statutory requirement. |
This Is No Longer Only a Hypothetical
The Federal Bureau of Investigation’s Internet Crime Complaint Center warned in a December 3, 2024 public service announcement that criminals are using generative AI for text-based social engineering and extortion demands, voice cloning to impersonate kidnap victims seeking ransom, and AI-generated images used in sextortion schemes.[4] The same notice identified a practical evidentiary consequence: generative AI can remove old scam tells, including grammatical and spelling errors that victims and investigators once treated as warning signs.[4]
That does not prove effectiveness. It proves adoption and a changed investigative environment. A cleaner threat can still be a fake threat; a synthetic voice can still induce real fear; an extortion message can still be admissible or inadmissible depending on the record built around it. The IC3 warning is useful because it moves the issue out of law-school speculation without answering the legal questions that trial courts will actually have to decide.
A Threat Need Not Announce Itself in Traditional Words
A defendant will not necessarily win by pointing out that an AI-generated ransom note used indirect phrasing or avoided the word “kill.” Courts already look at context and wording. In State v. Farnsworth, the Washington Supreme Court treated a handwritten bank demand note stating “No die packs, no tracking devices, put the money in the bag” as implicitly containing a threat of force sufficient to support a robbery conviction.[5]
That precedent is not an AI case, and it should not be made to carry more than it can bear. Its value is narrower: prosecutors do not always need explicit violent language if the communication, setting, and demand convey coercive force. An AI-generated demand that says less than a movie ransom note may still be threatening in context. But Farnsworth does not solve the authorship problem. It helps with meaning, not with who made the message or whether that person had the required mental state.
Jurisdiction Still Has Edges
The broadest readings still need jurisdictional facts. Section 875 requires interstate or foreign commerce.[1] Section 876 requires use of the mail.[2] A purely intrastate threat sent through a local channel may leave federal prosecutors with a weaker path and put the case under state law, where definitions, required mental states, fear requirements, and immediacy doctrines can vary.
For many digital communications, the interstate-commerce showing may be available in practice, but it should not be treated as magic words. The government still needs a record: the platform used, routing facts if contested, account records, device evidence, or admissions. In an AI-generated ransom-note case, those details may be the difference between a charging theory that sounds obvious and one that survives a serious motion.
The Intent Paradox
The hardest cases will not be the ones where a user plainly directs a model to draft a ransom demand, reviews the output, edits it, and sends it to the victim. In that sequence, the model is evidence of method, not an independent legal actor. Intent can be inferred from the prompt, the edits, the account history, the transmission, the timing, the demand, and whatever corroborating conduct surrounds the communication.

The harder case is a probabilistic output that becomes threatening without clear human direction, review, or awareness. Criminal threat statutes still punish people, not language models. If the defendant did not ask for a threat, did not read the threatening words, did not intend them to be taken as a threat, or did not transmit them knowingly, the defense argument moves from technological theater to ordinary mens rea. California’s express requirements of willfulness and specific intent make that issue visible, but federal extortion and threat theories also require proof that connects the prohibited communication to a culpable human state of mind.[1][3]
This is the paradox. The more deliberately the human uses the model, the less legally mysterious the model becomes. The more autonomous or opaque the generation appears, the more room the defense has to argue that the government is trying to convert output into intent. The question is not whether the words look like a ransom note. The question is what the evidence proves about the human who caused, approved, or transmitted them.
That inquiry will often be granular. Did the user’s prompt ask for leverage, fear, payment, secrecy, injury, kidnapping, exposure of intimate images, or impersonation of a victim? Did the system display the final message before sending? Did the user copy and paste it, or did an automated process transmit it? Were there drafts? Were there model logs? Was the alleged sender even in control of the account? Each answer narrows or widens the distance between machine-generated language and human criminal intent.
Authentication May Decide the Case Before Intent Does
A synthetic message can move faster than the process that verifies it. The National Center for State Courts has described a Florida matter in which AI-fabricated text messages, allegedly generated by an ex-partner, led to a woman’s arrest and two-day incarceration for violating a protective order; the charges reportedly remained pending for eight months before being dropped.[6] That account comes through the NCSC’s discussion and the reporting it cites, not an independently verified docket, so it should be treated as a warning example rather than a litigated appellate holding.
The warning is still sharp. The criminal process can begin before authenticity is settled. A victim may be frightened, officers may make a quick probable-cause assessment, a prosecutor may file, and the defendant may sit with bond conditions, custody, or public accusation while lawyers later fight over whether the message was fabricated. AI-generated evidence does not merely create a trial problem. It creates a timing problem.
For an AI-generated ransom note, authentication has several layers. The government may need to authenticate the message as received, the account or device that sent it, the generation process that produced it, and any logs or metadata offered to link it to the accused. The defense may attack any one of those links: spoofed accounts, fabricated screenshots, missing chain of custody, altered exports, incomplete platform records, compromised credentials, or AI output attributed to the wrong human.
The NCSC has also discussed proposed Federal Rule of Evidence 707 for authenticating AI-generated evidence and has published judicial materials for evaluating AI evidence.[6] Those materials are not settled federal criminal doctrine. They are better understood as a map of the fights to come: what foundation is enough, who must explain the system, what reliability showing is required, and whether ordinary authentication rules can bear the weight of synthetic media.
Victim Fear Remains Real Even When the Media Is Synthetic
A machine-generated threat can still produce human fear. That point matters most under state statutes that require proof of sustained fear or similar effects, and it matters practically in charging decisions even when a federal statute is focused on transmission and content. A synthetic voice that sounds like a kidnapped relative, an AI-generated intimate image used for sextortion, or a polished written demand may trigger fear before anyone can determine whether the underlying event is real. The FBI’s warning about voice cloning, extortion demands, and AI-generated sextortion imagery confirms that these are current criminal-use patterns, not merely theoretical capabilities.[4]
But fear does not authenticate the source. Nor does it prove the defendant’s intent. The victim’s reaction may establish one element or support probable cause; it cannot substitute for proof that the accused generated, adopted, transmitted, or knowingly used the threatening communication. That distinction will be especially important where the government’s emotional evidence is strong and its technical attribution is thin.
Criminal LLM Supply Chains Add Pressure, Not Settled Law
There is also evidence that criminal groups are not merely experimenting with generic tools. In a May 2026 interview, Ardi Janjeva of CETaS at The Alan Turing Institute described criminal uses of LLMs that include tactical and strategic decision-making, psychologically targeted extortion demands tailored to victim profiles, analysis of exfiltrated data to estimate ransom amounts, and visually alarming ransom notes.[7]
That is a risk signal, not a substitute for elements. A sophisticated criminal operation may make intent easier to infer in some cases because the AI system is part of a larger extortion scheme. It may also create more records: prompts, templates, data inputs, wallet instructions, access logs, and coordination messages. But the more complex the supply chain, the more careful the attribution question becomes. The person who bought access, the person who prompted the model, the person who transmitted the demand, and the person who collected payment may not be the same actor.
What Prosecutors Can Charge, and What They Still Must Prove
The chargeable theory is straightforward in the strong case. A defendant uses an AI tool to draft a ransom demand, sends it through an interstate communication channel, and the content fits § 875. Or the defendant prints and mails the demand, bringing § 876 into play. Or the facts fit a state criminal-threat statute such as California Penal Code § 422, including the required willful threat, specific intent, and victim fear.[1][2][3]
The proof theory is less forgiving. The government should expect disputes over at least six points: whether the exhibit is the message actually received; whether the accused controlled the sending account or device; whether the accused generated or adopted the threatening language; whether the accused reviewed the final output before transmission; whether the communication meets the statute’s threat or ransom-demand element; and whether the jurisdictional hook is present.
Defense counsel should not oversell the phrase “the AI wrote it.” A model is not a general-purpose mens rea eraser. If the client supplied threatening instructions, approved the demand, sent it, and pursued payment, the authorship objection may sound more like a drafting-tool argument than a defense. The stronger defense is narrower: the government cannot prove that this defendant knowingly generated, adopted, reviewed, intended, or transmitted the threatening content in the form alleged.
Judges, meanwhile, will be asked to make admissibility decisions on records that may be technically uneven. Screenshots, platform exports, model logs, forensic images, witness testimony, and expert explanations may all appear in the same hearing. The legal question will not be whether AI evidence is frightening or fashionable. It will be whether the proponent has laid a sufficient foundation for the particular exhibit and the particular inference attached to it.
Where the Law Currently Stops
The strongest present conclusion is about chargeability, not settled liability. The cited sources do not identify a reported federal or state appellate decision squarely holding that an AI-generated ransom note satisfies the elements of § 875, § 876, or California Penal Code § 422. That absence matters. It means courts will likely borrow from ordinary threat doctrine, robbery-by-demand-note cases, authentication rules, and emerging AI-evidence guidance rather than apply a clean AI-threat precedent.
Existing statutes likely reach AI-generated ransom notes on their face. Prosecutors have tools now. Defendants have serious and largely untested arguments about mens rea, authorship, authentication, and attribution. The outcome in any case will depend less on whether a language model can produce threatening words than on whether the record proves what a human did with those words.
References
- 18 U.S. Code § 875 - Interstate communications, Legal Information Institute, Cornell Law School.
- 18 U.S. Code § 876 - Mailing threatening communications, Legal Information Institute, Cornell Law School.
- California Penal Code § 422 PC – Criminal Threats, Shouse Law Group.
- Criminals Use Generative Artificial Intelligence to Facilitate Financial Fraud, FBI Internet Crime Complaint Center, December 3, 2024.
- A Threatening Note is Robbery, Ransom Law Firm.
- AI-generated evidence: A threat to public trust in courts, National Center for State Courts.
- AI for Criminals, AI Policy Perspectives, May 2026.
Related records
Tool profile
Browse tool evaluations →Governing regulation
The 2025 DACA Protection Bills, Provision by ProvisionPreventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →