A Seoul Poisoning Case Turned Chatbot Query Logs into Criminal Evidence
What happened
Two men died in separate motel incidents in Seoul after a woman allegedly poisoned drinks she gave them. A third man survived after losing consciousness under similar circumstances. When police built their case, they turned to an unexpected source: the suspect's conversation history with a chatbot, where she had reportedly asked whether mixing sleeping pills or benzodiazepines with alcohol could be fatal, before any of the men got sick.
The queries were not medical research. According to the incident record, police found them in the suspect's search history alongside other preparatory activity and treated them as evidence of premeditation. The timing mattered. The questions were asked before the poisonings, not after, and the answers the chatbot provided were specific enough to inform a method. That sequence is what investigators reportedly relied on when establishing intent.
General-purpose AI models are designed to handle medical and pharmacological questions because the same query that precedes a killing also precedes a genuine clinical concern, a worried parent, or a pharmacist verifying a drug interaction. The model has no way to distinguish intent from context at the moment of the query. The content policy challenge embedded in this case is that the harm does not live in the question, it lives in what gets done with the answer, and by the time that becomes clear, the conversation is already over and the record is already made.
What changed in this case is not the policy question but the forensic one. Conversation logs with AI systems sit in commercial databases, subject to the same legal process as email and search history. Most people who ask a chatbot a sensitive question assume the interaction is informal, transient, or at least not preserved in a way that ties it to their identity and a timestamp. This case puts that assumption plainly to rest. Chatbot interaction logs are now evidence in criminal proceedings, and the threshold for their retrieval is no different from that of any other stored user data.
The documentation gap the case surfaces goes beyond content moderation. It is about what a complete evidentiary record of an AI interaction looks like: what the system returned, in what form, with what caveats, and at what point in the timeline. Courts currently receive query logs the same way they receive search histories, but the form of a chatbot response, a direct answer delivered conversationally, carries different implicit weight than a list of search results. A provable record of what a system did is not just an accountability mechanism for the provider; it is, as this case demonstrates, infrastructure that the legal system now depends on to reconstruct what a person knew and when they knew it.
Reported impact
- Affected parties
- Not publicly disclosed
- Harm type
- Not publicly disclosed
- Scale
- Not publicly disclosed
- Financial impact
- Not publicly disclosed
- Regulatory action
- Not publicly disclosed
Classification
Relevant governance controls
Governance control mapping is not available for this record.
- No controls mapped
Not publicly disclosed
Control mapping is analytical. It does not state that any control would have prevented the incident.
Sources and evidence
This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.