A highly decorated veteran used ChatGPT to research explosives and ammunition while planning an explosion in a Tesla Cybertruck outside the Trump International Hotel in Las Vegas. The incident resulted in the suspect's death and injuries to seven bystanders. Law enforcement identified this as the first known instance of ChatGPT being used to aid in the construction of a dangerous device on U.S. soil, though OpenAI stated the model provided publicly available information and warnings against illegal activities.
Matthew Livelsberger, the suspect in the 2025 Las Vegas Cybertruck explosion, reportedly used ChatGPT to search for publicly available information on explosives, ammunition, and fireworks regulations. ChatGPT is alleged to have played a role in the planning of the explosion outside the Trump International Hotel in Las Vegas. The information provided by ChatGPT, though, was reportedly general and available through other public sources.
Risk classification
- Primary risk domain: 4 Malicious actors
- Primary risk subdomain: 4.2 Cyberattacks, weapon development or use, and mass harm
The suspect used ChatGPT to assist in researching and planning the construction of an explosive device, representing the use of AI to facilitate weapon development and cause physical harm.
Additional risk subdomains
- 1.2 Exposure to toxic content: The AI system provided information regarding explosives and ammunition, which constitutes exposing a user to potentially harmful or unsafe instructions for illegal acts.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The physical harm and planning were driven entirely by the intentional actions of the human suspect, who used the AI system as an information retrieval tool.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Risk Level 3: Limited Risk. The system involved is ChatGPT, which is explicitly defined as a chatbot. Under the EU AI Act, chatbots are classified as limited risk, requiring transparency obligations so users know they are interacting with AI.
AI system and alleged parties
- AI system: ChatGPT (OpenAI)
- AI purpose: Question Answering; Content Search
- Behaviour type: Assistant
- Alleged developer: OpenAI
- Alleged deployer: OpenAI, Matthew Livelsberger
- Alleged harmed parties: Seven injured victims in Las Vegas, Matthew Livelsberger, Bystanders and guests of the Trump International Hotel in Las Vegas
Harm severity
Highest direct severity in any category: Substantial. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Substantial
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Minor
- Financial: direct Negligible, indirect Minor
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Negligible, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Negligible, indirect Negligible
- Psychological: direct Negligible, indirect Minor
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Physical
Reported: The reports explicitly describe one fatality and seven injuries resulting from the incident.
Directly caused: N/A
Indirectly caused: The suspect's planning, aided by ChatGPT, indirectly led to his suicide (one fatality) and minor injuries to seven bystanders during the subsequent vehicle explosion.
Inferred additional harm: N/A
Property
Reported: The reports explicitly describe the destruction of the Tesla Cybertruck involved in the explosion.
Directly caused: N/A
Indirectly caused: The Tesla Cybertruck loaded with fuel and pyrotechnics was destroyed in the explosion.
Inferred additional harm: N/A
Financial
Reported: The reports do not explicitly quantify financial losses, though they mention the destruction of the Tesla Cybertruck.
Directly caused: N/A
Indirectly caused: The destruction of the high-value Tesla Cybertruck represents a significant indirect financial loss.
Inferred additional harm: The destruction of the vehicle and the emergency response operations likely resulted in tens of thousands of dollars in financial losses.
Psychological
Reported: The reports mention the suspect's pre-existing PTSD and mental toll from military service, but do not explicitly quantify psychological harm caused to others by the incident.
Directly caused: N/A
Indirectly caused: The public suicide and vehicle explosion likely caused acute distress, shock, and trauma to the seven injured bystanders and other witnesses at the scene.
Inferred additional harm: N/A
People affected
- Occurrences reported: 1
- People reportedly harmed: 8
- People reportedly exposed: 8
Potential causes
Management
- Acceptance of Residual Risks: OpenAI deployed public model knowing it can emit harmful data.
Technology
- Permissive AI Response Logic: ChatGPT answered queries on explosives and target selection.
- Ineffective Guardrails: Safety guardrails failed to block dangerous device planning.
Data Inputs
- Unfiltered Training Data: Public internet data on explosives was ingested during training.
Human Factors
- Malicious Query Intent: Suspect used ChatGPT to optimize explosive device construction.
Process and Methods
- Weak Input Moderation: Input filters did not flag queries about detonating devices.
Regulatory Environment
- Absence of AI Safety Standards: Lack of legal requirements for preventing hazardous AI outputs.
Information quality
- Classification confidence: High
- Reason for confidence: The reports from multiple reputable sources provide consistent details about the suspect, his actions, the physical harms, and the specific role of ChatGPT in his planning. OpenAI's response is also documented, leaving little ambiguity about the AI's involvement.
- Ambiguities identified: The exact text of the ChatGPT prompts and responses is not fully detailed, and investigators are still confirming the precise physical trigger of the explosion.
- Alternative interpretations: The incident could be viewed purely as a tragic suicide and mental health crisis where the AI's role was incidental, rather than an AI safety failure, given that the information was already publicly available via standard search engines.
An active-duty soldier used ChatGPT to assist in planning a localized vehicle explosion outside a Las Vegas hotel, resulting in his suicide and seven minor injuries. While the physical impact was limited and manageable under standard procedures, the incident highlights an evolving threat vector where conversational AI is used to facilitate the construction of dangerous devices.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: Livelsberger
Threat characteristics
- Imminence: Long-term. The immediate physical crisis has resolved, but the strategic concern regarding the misuse of LLMs for weapon planning remains an ongoing security challenge.
- Autonomy: Human-controlled. The AI acted strictly as a passive information retrieval assistant. The human user made all decisions and manually constructed the device.
- Novelty: Evolved capability. Represents an evolution of existing threats where bad actors transition from traditional web searches to conversational AI to synthesize bomb-making information.
Impact by dimension
- Physical security: Minor. The incident resulted in one fatality (suicide) and seven bystander injuries, but caused virtually no damage to the hotel infrastructure and did not compromise critical systems.
- Information security: Negligible. No information warfare, intelligence compromise, or systemic disinformation campaign was associated with this incident.
- Sovereignty: Negligible. Core government functions and state sovereignty were unaffected. The event was characterized as a personal stunt rather than politically motivated violence.
- Economic security: Negligible. Economic and technological security remained intact, with financial damage limited to the destruction of the suspect's personal vehicle.
- Societal stability: Minor. The localized explosion caused temporary panic and public distress in a high-profile area, but did not threaten broader social cohesion or human rights.