How to verify authorship of the Nancy Guthrie ransom notes
AI detectors and stylistic hunches alone cannot establish who wrote a suspicious communication. This verification workflow applies a corroboration standard to the Nancy Guthrie ransom notes, where the FBI's documented doubts rest on operational signals and the 'AI-written' label remains attributed commentary.
- Jurisdiction
- US-Arizona
- Court
- Pima County Superior Court
- AI tool named
- Unspecified
- Ruling date
- Jul 1, 2026
- Source document
- View primary court order ↗
- Last verified
- Aug 3, 2026
Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.
Companion explanation — secondary to the source document above
An “AI-generated” label is not a finding. It is a claim about authorship, and in a live threat matter it needs the same discipline as any other attribution claim: source status, preserved evidence, corroborating operational facts, and a record of what was actually verified. That is the useful starting point for lawyers and editors reading about the Nancy Guthrie ransom notes after the Pima County sheriff release—not whether a sentence sounds strange, but what can safely be repeated.
The Guthrie materials are a good stress test because the public record is already layered. FBI Phoenix publicly used limited language: some notes were “deemed to be extortion attempts without legitimacy,” while others “may potentially be legitimate,” and the matter continued to be investigated as a kidnapping-for-ransom case. [1] Reuters, citing an anonymous FBI official, reported a stronger position—that all three notes were fake—and added a reported operational fact about a cryptocurrency-deposit request that had not been acted on. [2] CBS reported that the two February notes came from the same IP address. [3] Those are not the same evidentiary category.
For the full Guthrie record, read this piece alongside the site’s case files: the full note text, the evidence summary, the case timeline, the AI-authorship discussion, and the FRE 901 authentication analysis. This article does not try to re-try the disappearance or reproduce the notes. Its job is narrower: how to handle a threatening communication when someone says, too quickly, “AI wrote it.”

First, separate the questions
A ransom note can be real in one sense and false in another. It can be a genuine communication sent by a real person and still contain lies. It can be sent by someone uninvolved in the underlying disappearance. It can be human-written, AI-assisted, copied, spoofed, or routed through infrastructure meant to mislead. Treating all of that as “fake” is convenient, but it is not precise enough for legal advice, court filings, or careful reporting.
| Question | What it asks | What does not answer it |
|---|---|---|
| Authenticity | Is this the item claimed to have been received, preserved without material alteration, and tied to a reliable chain of custody? | A claim that the message sounds machine-written |
| Authorship | Who composed, dictated, generated, edited, sent, or controlled the communication? | An AI-detector score or a stylistic hunch |
| Legitimacy | Does the sender have a real connection to the threat, victim, funds, or demanded action? | Proof that the note was actually delivered |
| AI generation | Was a generative tool used to draft or revise the communication, and if so, by whom and for what part? | The mere presence of awkward phrasing, misspellings, or generic ransom-note language |
That separation matters in the Guthrie record. The FBI Phoenix public statement did not announce a public forensic determination that any note was AI-written. It drew a legitimacy distinction: some notes lacked legitimacy; others remained under investigation. [1] Reuters’ anonymous-source account supplied a reported law-enforcement position and a reported operational detail, not an official public authentication ruling. [2] CBS’s IP-address reporting is operationally important, but it does not, by itself, identify a human author or establish AI generation. [3]
Use a source-status ladder before using a conclusion
The quickest way to damage a live-case analysis is to flatten the record. An official public statement, an attributed media report, an anonymous-source account, expert commentary, and a detector output can all be relevant. They cannot be cited as if they carry the same weight.

| Material in the Guthrie record | Evidence class | Safer wording |
|---|---|---|
| FBI Phoenix statement that some notes were deemed illegitimate while others may potentially be legitimate | Official public position | The FBI publicly distinguished between illegitimate extortion attempts and notes still under investigation. [1] |
| Reuters report citing an anonymous FBI official who said all three notes were fake | Anonymous-source law-enforcement reporting | Reuters reported that an anonymous FBI official described all three notes as fake. [2] |
| Reuters report that a cryptocurrency-deposit request was not acted on | Reported operational clue | Reuters reported that a requested crypto deposit had not occurred; that detail supports doubt about legitimacy but is not a public AI-authorship finding. [2] |
| CBS report that two February notes came from the same IP address | Reported technical signal | CBS reported a same-IP-address link between two notes; the implication depends on surrounding network and device evidence. [3] |
| NewsNation’s attributed AI-authorship theory from Jennifer Coffindaffer and Morgan Black | Commentary or expert opinion, depending on foundation | NewsNation reported an AI-authorship theory attributed to named commentators; that remains a theory unless corroborated by operational evidence. [4] |
| William Eggington’s KOLD comments on linguistic analysis | Expert caution about method | Eggington treated linguistic observations as potentially confirmatory, not independently identifying. [5] |
| AI-detector output | Tool output with known false-positive and false-negative problems | A detector result should not be used as the sole indicator of AI authorship. [6] |
A source-status ladder is not a way to ignore inconvenient evidence. It is a way to keep each fact in its proper lane. “Reuters reported that an anonymous FBI official said X” is a different sentence from “The FBI announced X.” “A linguist identified features that may be consistent with Y” is different from “Y has been authenticated.” These distinctions feel fussy until a partner, judge, client, or reporter repeats the stronger version and has to walk it back.
Preserve the communication before interpreting it
The first operational act is boring and essential: preserve the communication in the form received. For an email, that means the original message and headers, not a forwarded screenshot. For a text or messaging-app threat, it means exports where available, device screenshots with visible timestamps, account identifiers, and a record of who handled the device. For a paper note, it means physical custody, photographs, packaging, and documentation of when and by whom it was received. If the message was released publicly, preserve both the public version and any underlying file metadata that can lawfully be obtained.
This is not just a courtroom habit. It changes the investigation. Once a screenshot circulates, people start arguing about phrasing. Once the original is preserved, counsel can ask better questions: what channel delivered it, what account or infrastructure touched it, what timestamps line up, what device or network data exists, and whether later copies introduced artifacts that look meaningful but are not.
- Store the original communication or best available native copy.
- Record who received it, who accessed it, and when it was transferred.
- Keep screenshots, PDFs, and media copies, but label them as derivatives.
- Do not run the only copy through online analysis tools that may store or alter the material.
- Separate the question “is this the item received?” from “who wrote it?”
For legal use, that preservation step also supports later authentication. The Guthrie FRE 901 issue is handled separately in the site’s authentication analysis, but the practical point is the same in and out of court: authorship arguments become weaker when the item’s path into the record is undocumented.
Corroborate operational signals before arguing style
Operational signals do not magically identify an author. They do, however, move the analysis from impression to testable fact. In the Guthrie reporting, two such signals stand out: CBS’s report that two February notes came from the same IP address, and Reuters’ report that a cryptocurrency-deposit request had not been acted on. [2][3]
The same-IP detail can support several narrower propositions. It may link two communications to a common network path. It may support the inference that two messages shared infrastructure. It may help investigators compare timing, accounts, devices, subscriber information, VPN use, or access logs. It does not, standing alone, prove that the same person wrote both notes, that the sender lacked a connection to the case, or that a generative-AI tool drafted the language.
The crypto-deposit detail is similar. If a demand instructs payment to a wallet and investigators can verify that no requested deposit occurred, that fact may bear on whether the communication functioned as a real ransom demand. It may also matter to motive, opportunity, and timing. But “the wallet did not receive the requested deposit,” if established, is not the same as “the note was AI-written.” It is an operational clue about conduct, not a linguistic conclusion.
A useful verification memo would therefore put operational questions ahead of prose reactions:
- Delivery channel: how did the communication arrive, and what account, number, address, platform, or physical route delivered it?
- Timing: when was it created, sent, received, opened, released, or acted on, and how do those times compare with known events?
- Network or device data: what IP addresses, device identifiers, login records, geolocation records, or platform logs can be lawfully obtained?
- Payment or demand mechanics: were wallets, accounts, phone numbers, meeting points, codes, or instructions actually used?
- Contact pattern: did the sender continue contact, respond to verification prompts, or demonstrate nonpublic knowledge?
- Independent confirmation: what can be verified through a separate trusted channel rather than by replying inside the suspicious channel?
The order matters because urgent cases invite narrative shortcuts. A strange message arrives; someone sees robotic phrasing; a detector score appears; a label hardens. By the time operational records are requested, the public version may already be stronger than the evidence.
Treat AI-authorship commentary as commentary unless it is tied to evidence
NewsNation reported an AI-authorship theory attributed to former FBI agent Jennifer Coffindaffer and cyber-safety expert Morgan Black. [4] That kind of commentary can be useful. It may tell counsel what knowledgeable observers are noticing, what hypotheses investigators may test, and what questions a reporter or opposing party may ask. It should not be laundered into “the notes were confirmed to be AI-written” unless the underlying evidence supports that stronger statement.
William Eggington’s KOLD comments are valuable partly because of their restraint. He said he did not “sense an AI influence” in the material he reviewed, discussed features such as comma splices, the word choice “perished” rather than “died,” and the misspelling “recieved,” and warned against cherry-picking isolated quirks. [5] More importantly, his framework keeps linguistic analysis in proportion: it can help confirm or test a theory, but it generally does not identify an author by itself, and the court standard is higher than the investigative standard. [5]
That is the right way to use language evidence in an AI-suspect threat. Linguistic observations may justify follow-up. They may help compare a disputed communication with known writings. They may reveal copying, templating, translation artifacts, or inconsistent register. But they are supporting clues. They need a foundation: comparable samples, known conditions, a defined question, and corroboration from non-linguistic facts.
| Observation | Permissible use | Unsafe leap |
|---|---|---|
| Generic wording or polished structure | Flag for comparison with other communications and possible AI-assisted drafting | Declare AI authorship |
| Odd punctuation or comma splices | Compare against known writing habits if reliable samples exist | Treat the quirk as a signature |
| Misspellings or unusual word choice | Ask whether the same error appears elsewhere and whether copying or disguise is possible | Assume the error proves a human author or disproves AI use |
| Detector score | Record as a non-dispositive screening artifact, if used at all | Use as the sole basis for an authorship conclusion |
Do not let a detector become the witness
AI detectors are tempting because they produce a number or label when everyone wants certainty. That is precisely why they should be handled carefully. The University of San Diego Legal Research Center guide warns that AI detectors have false positives and false negatives and states that they “are problematic and not recommended as a sole indicator.” [6]
For a lawyer, the immediate problem is not whether a detector is sometimes directionally useful. The problem is what happens when its output is treated as a conclusion. A false positive can label a human-written threat as AI-generated. A false negative can give undue comfort about a generated or assisted communication. Either way, the tool can distort the next steps if it is allowed to outrank chain of custody, platform records, payment activity, witness confirmation, or a careful comparison of known writings.
If a detector is used at all, document it as a screening step: which tool, which version if known, what text was submitted, whether the text was complete or excerpted, and what limitations were known. Do not quote the score without the surrounding caveat. Do not submit sensitive threat material to a tool without understanding retention, confidentiality, and privilege consequences. And do not call a detector result authentication.
Build human verification into the workflow
The strongest practical advice in AI-suspect communications is not technical. Eman El-Sheikh of the University of West Florida Center for Cybersecurity and AI advised slowing down, resisting manufactured urgency, and verifying through independent channels. [7] That applies to ransom notes, spoofed texts, executive impersonation, settlement-demand scams, witness messages, and anonymous threats.
Independent-channel verification means the responder does not rely on the channel that carried the suspicious communication. A hypothetical example: if a message purports to come from a client’s executive and demands urgent payment, counsel should not authenticate it by replying to that same message thread. Use a known phone number, a preexisting secure portal, a designated incident-response contact, or a law-enforcement contact already established outside the suspicious exchange. In a kidnapping or extortion setting, that step must be coordinated with investigators; the point is not improvisation, but channel separation.
Joseph Lestrange’s digital-forensics-lab point, also reported by NPR, explains the tension: clues such as location data and pixels can be effective, but the work is slow when time is critical in kidnapping cases. [7] That is exactly why a workflow should be set before the urgent communication arrives. The point is not to eliminate judgment under pressure. It is to prevent the first plausible label from becoming the institutional position.
A defensible memo format
When counsel has to brief someone quickly, the format should force precision. A useful memo does not begin with “AI-written?” It begins with the communication, the custody record, the source status of each claim, and the operational facts already verified.
| Memo field | What to include |
|---|---|
| Item received | Native file, physical note, screenshot, email, platform message, or public release copy; identify derivatives separately |
| Custody | Receiver, handlers, preservation steps, transfers, and gaps |
| Source status | Official statement, attributed report, anonymous-source report, expert commentary, tool output, or internal observation |
| Operational facts verified | Delivery channel, IP or device data, payment activity, timing, account records, contact pattern, and nonpublic knowledge |
| Linguistic observations | Only observations tied to defined comparisons or expert review; no standalone authorship conclusion |
| AI-tool evidence | Direct evidence if any, such as prompt logs, account records, admissions, device artifacts, or platform records; detector output labeled as non-dispositive |
| Independent confirmation | Steps taken outside the suspicious channel and by whom |
| Permitted public wording | The narrowest statement supported by the record |
Applied to the Guthrie notes, that format would not produce a clean public verdict. It would say that the FBI publicly distinguished between illegitimate extortion attempts and notes still under investigation; that Reuters reported a stronger anonymous-source position; that CBS reported a same-IP connection for two February notes; that AI authorship has been advanced in attributed commentary; that a forensic linguist urged caution about identifying authorship from language alone; and that detector output would not be enough. [1][2][3][4][5][6]
That is less dramatic than “fake” or “AI-written.” It is also more useful. It tells the next decision-maker what is official, what is reported, what is technical, what is expert caution, and what remains unproved.
What can be safely said about the Guthrie notes now
On the public record available here, there is no public forensic determination establishing that any Nancy Guthrie ransom note was AI-written. There is public FBI language stating that some notes were deemed illegitimate extortion attempts and that others may potentially be legitimate. [1] There is Reuters reporting, based on an anonymous FBI official, that all three notes were fake. [2] There is CBS reporting about a shared IP address for two February notes. [3] There is attributed AI-authorship commentary, and there is expert linguistic caution. [4][5]
The sheriff has disputed a broad public dismissal of the notes, saying reports that the notes were dismissed were “not the truth.” [1] The reported wallet-deposit detail should be treated as reported, not independently confirmed here. [2] Materials from social-media posts or other release channels should be re-verified against the original source before citation. Callella’s plea, as discussed in the site’s timeline, concerns spoofed texts; it does not resolve the authorship or legitimacy of the media ransom notes.
The professional standard is therefore procedural, not theatrical. In an AI-suspect threat, preserve the item, classify each source, corroborate operational evidence, use linguistic analysis as support rather than identification, treat detector output as non-dispositive, and verify through independent human channels before relying on an authorship label. “AI-written” is an assertion to be proved, not a shortcut.
References
- FBI official pushes back claims Nancy Guthrie kidnapping ransom demands fake report — Fox News — July 1, 2026
- FBI determines Nancy Guthrie kidnapping notes to be fakes, source says — Reuters — July 1, 2026
- Nancy Guthrie ransom notes released — CBS News
- Former FBI agent: Guthrie ransom notes written by AI — NewsNation
- Linguistic expert explains how investigators may analyze ransom notes in Nancy Guthrie case — KOLD — August 1, 2026
- AI Detectors — University of San Diego Legal Research Center
- Nancy Guthrie AI deepfakes — NPR — February 10, 2026
Related records
Tool profile
Browse tool evaluations →Governing regulation
The 2025 DACA Protection Bills, Provision by ProvisionPreventive workflow
Browse verification workflows →
Report a correction or tip
Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.
Report a correction or tip for this record →