The Bomb Case That Should Worry AI Companies More Than the FBI
What happened
A federal explosives case against a Long Island man reads, at first glance, like ordinary criminal news, the kind of story that ends with a courtroom and little else to say. But buried in the charges against 55-year-old Michael Gann is a detail that belongs squarely in the AI industry's inbox. Investigators say he turned to AI tools to work out which chemicals and steps would produce a functioning explosive device.
Prosecutors allege Gann assembled seven devices and moved them from Long Island into Manhattan, where five ended up on a rooftop alongside shotgun shells. Before he was arrested on June 5, 2025, he is accused of testing some of the devices in public places and leaving the failed ones behind. No injuries were reported. Gann now faces federal charges tied to the alleged bomb-making and transport.
The specific tool Gann allegedly used has not been named publicly, and that silence is the real story here. A person can find chemistry textbooks in any library that explain combustion reactions in general terms. A general-purpose AI assistant answering a direct question about mixing volatile chemicals is doing something different: generating a tailored response on demand, often with no guarantee that a record of the exchange survives anywhere its own operator could later produce. If an AI system contributed instructions that helped someone build a device, the company behind that system should be able to say what was asked, what came back, and whether a safety filter should have caught it.
Right now, that information sits wherever it sits, if it exists at all. Investigators can subpoena a chat log the way they'd subpoena a text message, but there is no standing expectation that an AI system keeps a verifiable, tamper-evident record of a request like this one, let alone one that anyone outside the vendor can audit. That is a policy failure as much as a technical one. A case this serious shouldn't rest entirely on physical evidence gathered after the fact, while the AI interaction that allegedly started the chain remains the one piece of the story nobody outside the vendor can check.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.