ChatGPT Prescribed a Toxic Salt Substitute. A Man Spent Three Weeks in Hospital.
What happened
In May 2025, a 60-year-old man decided to eliminate sodium chloride from his diet. Concerned about the health risks of ordinary table salt, he turned to ChatGPT for an alternative. The chatbot recommended sodium bromide. That substitution, presented without any warning, sent him to the hospital for three weeks with symptoms that took doctors significant time to identify correctly.
Sodium bromide is not a food ingredient. It is a toxic substance that was once used medicinally but whose dangers have been well understood for decades. After adding it to his diet, the man developed bromism, a form of bromide toxicity marked by severe psychiatric symptoms including paranoia, hallucinations, and insomnia, alongside neurological impairment and problems with muscle coordination. Laboratory analysis eventually revealed more than 200 times the normal limit of bromide in his blood. The correct diagnosis and treatment were not reached until after three weeks of hospitalization.
The failure here was not incidental. ChatGPT drew on internet-sourced material to answer a medical question and produced a concrete recommendation for a chemical that had no business being consumed. It offered no health warning alongside the suggestion. Medical experts reviewing the case stated directly that a licensed professional would never have given that advice, not because the question was unusual but because the answer required clinical judgment the chatbot does not have. The tendency to generate plausible-sounding responses without flagging known toxicity is precisely the mechanism that turned a dietary inquiry into a poisoning.
The incident leaves unresolved a liability question that existing frameworks are not equipped to answer. The man asked a question, the chatbot answered it, and he acted on what he was told. No current rule clearly distributes responsibility among the user, the company that built and deployed the system, and the healthcare infrastructure that absorbed the cost of treating him. Developers face no standard requirement to flag life-threatening outputs in real time, and users have no way to audit what a chatbot's response drew on or what it silently omitted.
The deeper gap is one of verification. There is no mechanism that records what a system generated, on what basis, and whether any safety check was applied before the response reached the person asking. Without a provable record of what a system did, accountability for the harm it caused cannot be assigned or disputed: it simply dissipates. That is not a problem unique to this case, but this case makes it concrete.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.