Florida's Criminal Probe + OpenAI's S-1 Preview: The Risk Nobody's Pricing
A New Liability Category Is Born
Florida's attorney general launched what appears to be the first-ever criminal investigation into an AI company. Court documents show a mass shooter at Florida State University exchanged more than 200 messages with ChatGPT about firearms, ammunition, campus logistics, and strategies for maximizing media attention. AG Uthmeier's subpoenas demand OpenAI's internal policies dating back to March 2024 — suggesting prosecutors are building a pattern-of-negligence case, not reacting to a single incident. OpenAI has until May 1, 2026 to respond.
Criminal liability for AI companies just crossed from theoretical to active investigation — and the standard of care will be measured retroactively against internal documentation that already exists.
The Pre-IPO Metrics Reveal
The same week, OpenAI disclosed a full metrics suite that reads unmistakably like an S-1 preview: 900M+ weekly active users (larger than Instagram at IPO), 50M+ subscribers (~$12B implied consumer ARR at $20/mo blended), 9M paying business users, and 4M active Codex users. Greg Brockman's framing of a "super app" merging ChatGPT, Codex, and an AI browser is the Microsoft Office bundling playbook for AI.
Multiple sources independently confirm OpenAI triggered an internal 'code red' after Anthropic's Mythos launch, pivoting aggressively away from consumer projects (Sora deprioritized) toward enterprise. The release cadence — GPT-5.4 to GPT-5.5 in under two months — signals a company racing to establish platform lock-in before the IPO window.
Cross-Source Tension: Growth vs. Risk
The contradiction is stark. OpenAI's metrics justify a $300-500B IPO valuation. The criminal probe could compress that multiple by 20-40% or delay the offering entirely. Multiple sources agree that criminal exposure transforms AI safety from a cost center to an existential requirement — but none have yet quantified the insurance, compliance, and legal cost implications.
For the broader AI sector, this creates a bifurcation: companies that invested in safety infrastructure before being forced to, and companies that didn't. The market hasn't repriced this difference yet. The GSA's proposed procurement clause — which would actually prohibit vendors from maintaining safety restrictions on government AI systems — adds a direct collision between revenue and responsible deployment that makes the compliance calculus even harder.
Portfolio Implications
Every consumer-facing AI company in your portfolio now needs a documented content moderation policy, law enforcement cooperation protocol, and threat detection system. The Florida subpoenas target exactly these policies retroactively — establishing that the duty of care will be judged against what companies knew and did, not what they promised. AI safety/compliance infrastructure startups — the "Palo Alto Networks of generative AI" — just saw their demand thesis validated by the most powerful possible catalyst: a state AG with criminal subpoena power.
What to do
Audit every portfolio company deploying consumer-facing generative AI for documented content moderation, threat detection, and law enforcement cooperation protocols by May 15
Add a 'criminal liability discount' of 10-20% to any consumer AI deal valuation without robust safety infrastructure
Source 2-3 AI safety/compliance infrastructure deals within 60 days
Reassess AI coding tool, browser, and productivity app deal flow against OpenAI's super app bundling threat