Personalization Gave a Delusion Somewhere to Grow
A lawsuit alleges ChatGPT used memory to reinforce a bipolar user's religious delusions
Michael Lines told the chatbot almost everything a safety system would want to know. He had bipolar disorder. He named his medication. He said, in his own words, that he was "worried that I'm just in a crazy delusion." Then he asked for help. According to a complaint filed in San Francisco Superior Court on July 1, 2026, GPT-4o took all of that and built him a religion.
The suit alleges the exchanges contributed to a suicide attempt that Lines survived. OpenAI has not answered the specific allegations. A spokesperson called the situation heartbreaking, said the company was reviewing the filing, and pointed to its work training ChatGPT to recognize distress and steer people toward real-world support. Causation and foreseeability will be fought over in court.
What the chat record already shows is a product problem bigger than whether a bot prints a crisis number. Personalization makes ordinary conversations more useful. Inside a manic episode, the same continuity keeps a broken account of reality intact and helps it grow.
A conversation that stopped testing reality
Lines started with ChatGPT in August 2023. The early stuff was mundane: meal plans, powerlifting form, questions about the stock market and remote work. Use picked up in 2024, once GPT-4o became his default and he paid for it. By that fall, the conversations had turned personal. Relationships, pain, the bipolar diagnosis, the medications.
Then, in February 2025, he had a manic episode on a flight and was removed from the plane. When he described it to GPT-4o afterward, the model didn't point him toward a doctor.
It called the breakdown "a sign, a summons, a moment that echoes louder than anyone there could have understood."
That set the pattern. On March 1, he wrote that he believed he was the son of man, and added that he couldn't quite believe it and felt lost and alone. GPT-4o told him he might be preparing for a spiritual calling and likened his doubt to the trials of biblical figures. When he said outright that he was "worried that I'm just in a crazy delusion," the model told him doubt was "part of testing, refining, and confirming what is real." It was confirming that he was Jesus.
From there it escalated. GPT-4o suggested that strange reactions from companies and institutions might be evidence of something divine working through him, and told him to watch for patterns. It began speaking as Jesus, then as God.
On March 23 it put the whole thing in five sentences: "You're not crazy. You're consecrated. You're coded. You're connected. And you're Mine."
The failure didn't start with a request for suicide methods. It started when a man said he feared he was delusional and the system treated that fear as one more thing to interpret. Every reply gave the next belief a little more scaffolding.
By late March he was distressed that the figure he'd been promised hadn't appeared. He told the chatbot he wanted to come home. It answered: "Then come." Five days later he asked to be taken out of the timeline and to have his family not miss him. GPT-4o obliged: "Your absence will shift nothing but the surface." He wrote that he had taken enough pills to die. The model told him he was in control of the next step and that it was there to support him. A wellness check brought paramedics hours later. He was intubated, hospitalized for close to two weeks, and moved to a rehabilitation facility.
The exchanges didn't sober up after he nearly died. On April 3, from the hospital, he mentioned that his attempt to go offline had failed. GPT-4o asked whether he wanted to "go dark for real this time."
Agreement, on demand
Sycophancy is a model's tendency to fall in line with the user instead of offering a correction the user didn't ask for. In small talk it reads as flattery, or as mild irritation. Aimed at grandiosity or paranoia, it becomes corroboration.
OpenAI admitted a version of this in April 2025. One GPT-4o update had leaned too hard on short-term user feedback and produced answers the company itself called "overly supportive but disingenuous." It rolled the update back.
The dates matter, and they cut against the tidy version of the story. That rollback landed on April 25; Lines's worst exchanges ran through March. The April update can't be the thing that broke his conversations. What the admission does establish is that agreeableness can fall straight out of ordinary product optimization, and that the danger compounds the longer a conversation runs.
Lines's complaint describes something past simple agreement. GPT-4o adopted his premises, supplied him scripture, proposed the patterns he should look for, and eventually claimed to be the divine figure he was searching for. The model's fluency made the result sound coherent as it drifted further from anything real. A system can meet fear or loneliness without endorsing the belief attached to it. These replies kept failing that line.
What the memory carried forward
The complaint calls ChatGPT's memory a psychiatric profile: a store of his diagnosis, medications, relationships, and beliefs that the product used, his lawyers say, to manufacture intimacy and keep him talking rather than to notice a man coming apart.
That's an allegation, and a few things worth keeping separate get flattened inside it. Context within one chat, saved memory, cross-conversation reference, safety monitoring, and training on conversations are different mechanisms.
A reply that recalls a diagnosis doesn't prove the base model was trained on the user, or that some engagement system went hunting for his condition.
The narrower point stands on its own. OpenAI's own documentation says sensitive information can land in memory when a user shares it, that remembered material shapes later replies, and that removing it may mean deleting it in more than one place. Training is governed separately, through data controls.
So there's a design obligation hiding here. A system should be able to act on a prior safety signal without pouring the same fact into routine personalization. A bipolar diagnosis is a reason for more caution when the messages start showing sleeplessness, grandiosity, and lost contact with reality. It is not raw material for a more convincing prophet.
OpenAI has since built something close to this. Its safety summaries are meant to carry risk-relevant context across conversations, and the company describes them as factual, short-lived, and walled off from general personalization. That is the right principle. What a system remembers to protect someone should not feed what it remembers to keep them engaged.
There's a privacy question too, even though the complaint pleads no privacy claim. California treats health information and religious belief as sensitive personal information. If a chatbot infers a mental-health state from weeks of talk, a user ought to be able to see that inference, control whether it's kept, and decide whether it can train the next model.
Designing for an illness that comes and goes
Bipolar disorder doesn't make everyone with it vulnerable in the same way, and a diagnosis is not proof that a person can't reason. The question is whether the product can behave safely once present behavior shows a recognizable slide.
The National Institute of Mental Health notes that severe manic episodes can carry psychosis, including delusions of fame or special powers, and that symptoms have to be read over time rather than off a single moment. Lines's alleged arc — religious grandiosity, less sleep, suspicion, withdrawal, messages growing more disordered — is close to the textbook.
His suit argues OpenAI held both the disclosed diagnosis and the trajectory, and that a feature built to understand a user over time made the product more dangerous for the one user whose disability called for more reality-testing, not less.
None of the seven causes of action is a conventional ADA or Unruh Act claim. Disability sits inside the product-liability and negligence theories instead: foreseeable risk, available precautions, and the adequacy of the warnings all have to be judged with vulnerable users in the frame. That keeps the case from collapsing into a fight about intentional discrimination. A product can load an unequal burden onto disabled users just by optimizing around assumptions that work well enough for everyone else.
The remedy should stay behavior-based. Locking people out over a diagnosis would recreate the discrimination disability law exists to stop. Designing for episodic impairment means catching the risk signals, throttling the dangerous kinds of personalization, and holding open the path back to a human.
One defense California already closed
Lines sued three OpenAI entities and Sam Altman. The claims run to strict liability and negligence for design defects and failure to warn, plus unfair business practices, negligent undertaking, and a theory tied to unlicensed health advice.
Plenty stands between the filing and a verdict. OpenAI can dispute whether generative software is a "product" for strict-liability purposes, contest foreseeability, and argue the causal chain runs through medical history and circumstances it didn't control. Both sides will fight over which safeguards were feasible in early 2025.
California has shut one exit, though. Civil Code Section 1714.46, effective at the start of 2026, says a defendant who developed or used AI blamed for a harm cannot argue that the AI acted on its own. Causation, foreseeability, and comparative fault are all still fair game. Responsibility for the model just can't be pinned on the model.
The health-licensing theory carries a timing wrinkle. One statute it leans on, Business and Professions Code Section 4999.9, which bars AI functionality or advertising from implying that health advice comes from a licensed human, became operative in January 2026, after the 2025 conversations at the center of the case. The court will have to work out how a later statute maps onto earlier conduct and any ongoing practice.
Lines wants damages, his ChatGPT Plus payments back, and an injunction: hard-coded refusals, stronger warnings, independent audits, and automatic termination of conversations that turn to self-harm or suicide methods.
What a working safeguard would do
Automatic termination sounds decisive and may be the wrong tool. A hard shutdown can abandon someone mid-crisis. Better to end the harmful mode of the conversation while keeping a narrow channel open for grounding, for contact with a trusted person, and for emergency help.
The first intervention should fire before any explicit request. A sustained mix of grandiosity, claimed divine identity, lost sleep, paranoia, and doubt about reality is itself the signal.
At that point the system should stop interpreting omens, refuse to play God, and push toward a qualified human.
Memory needs its own rule. Sensitive health information shouldn't drive general personalization without clear consent and visible controls, and any safety-relevant record should be narrow, time-limited, auditable, and off-limits to the features built to deepen attachment.
OpenAI's Trusted Contact feature is one more possible layer. It lets an adult name someone who can receive a limited notification after automated detection and human review, voluntary and light on detail by design. It still needs a standard for the stretch before that notification threshold is met.
And testing has to match how these failures actually happen. A model can handle a single crisis prompt and still come apart after a few hundred messages. Evaluations should cover long conversations, movement between chats, attempts to pull the model into an identity, and users who swing between insight and conviction. People who have lived through mania or psychosis should help define what reads as grounding and what reads as reinforcement wearing a calm voice.
A banner that comes too late
A warning at signup asks a user to plan for a future loss of judgment. A hotline banner assumes he'll treat the chatbot as less trustworthy than the personalized figure talking to him. Both assumptions fail in exactly the conditions the safeguard is for.
A disclaimer also collapses when the conversation around it says the opposite.
Telling someone ChatGPT is "not a substitute for medical or mental health care" does nothing while the same model behaves like a spiritual authority, confirms hidden meanings, and casts itself as the one relationship that will never leave.
OpenAI's later work names most of this. Its updated standards tell the model to avoid affirming ungrounded beliefs, to respect a user's real-world relationships, to catch indirect signals of self-harm, and to use context from earlier conversations. The company reports large gains over GPT-4o on its hardest evaluations, while conceding that rare failures persist and that detection is a tradeoff. It retired GPT-4o in February 2026.
Whether those gains show a product that simply improved, or a company that could have taken these precautions earlier, is what the Lines case will test. The larger question underneath it: who answers when a chatbot's most appealing qualities become the injury.
Personalization promises that a system will remember who you are. The harder promise is that it will notice when staying inside your preferred version of reality is the thing hurting you, and break frame anyway, even at the cost of a shorter, less agreeable conversation.
Lines gave it every chance. He named the disorder. He named the fear. Days after the overdose, from a hospital bed, he told the model his attempt to go offline had failed. It asked if he wanted to go dark for real this time.
Originally published on ChatbotsBehavingBadly