This website uses cookies

Read our Privacy policy and Terms of use for more information.

Welcome back to “The TAB,” a publication that curates relevant-right-now developments in behavioral threat assessment and management (BTAM) that I think are most worth your attention. Thanks for checking it out, and if you like it please consider sharing with your networks. There are no paywalls in this issue.

Every other Thursday, a new issue of the TAB will arrive with operationally useful updates for professionals in BTAM. Every issue is researched, written, and edited by me. No AI-generated articles and no recycled summaries—just my assessment of what matters and why. And it’s free to subscribe.

In this brief, I’m chasing down the so-called “contagion effect” of mass violence. Studies by serious and learned scholars have produced opposing results. So where are we today? In addition, the U.S. Supreme Court narrowed the application of a criminal statute sometimes used by prosecutors in BTAM. Also, a must-read for large enterprise threat assessment teams: OpenAI just made an announcement about its ability to review concerning activity by users on its platforms.

A 2026 study examines whether mass killing contagion is real or not real.

  • The latest published study in this ongoing debate found no evidence to support a short-term contagion effect among mass killings. But it left the door open.

  • Contagion involves an increased statistical probability of more mass attacks for an acute span of time after one occurs. Copycatting is a different thing—at least in BTAM.

  • This debate exists because researchers are trying to figure out which method of analyzing the stats is the right one. The two leading methods have pointed to opposite results. This study tried out a new process to address problems with both models.

Contagion v. copycatting

First, let’s define contagion in this context and separate it from copycatting. These terms are sometimes conflated, but in BTAM we want to be sure we know which term means what, because they describe related but different phenomena.

Mass violence “contagion” is thought to be a temporary period during which a just-committed, public mass attack increases the statistical probability of other mass attacks, hypothesized to be due at least in part to mass transmission of public information about the initial attack. That’s not to say any single event literally causes a specific event later on in a direct way. In epidemiology, the word contagion describes the communication of a disease from one host to another by direct or indirect contact. That’s more deterministic than we can get here. For our purposes, contagion is probabilistic, and it’s more like a metaphor for a population-level statistical attribution.

Copycat violence, on the other hand, happens when specific attacks and attackers are imitated by admirers at any point in time, even decades later. In the aggregate, certain copycatted aspects of an attack, a manifesto, identification behaviors, etc., can even form a subcultural script. Copycatting has been referred to as “specific contagion” (making “general contagion” the same thing this issue is about), but for max clarity in this TAB issue I prefer copycatting.

So what?

Why do we care about contagion? Well, if the statistics confirm this phenomenon is real and not just our confirmatory bias filling in the blanks for us, then it could realistically trigger a few things to start happening:

  1. It could provide much stronger support for surging organizational resources, both government and private, toward security and BTAM during times of forecasted contagion. Security and BTAM are the two walls standing between targeted violence and its victims.

  2. It could give news media organizations hard data to support a firm policy of non-sensationalizing coverage of mass violence, including but not limited to depriving the offenders of legacy-making by not naming them and not publishing details from manifestos. Currently, this notion of legacy-deprivation is unevenly applied, if at all.

  3. Depending on how deeply into attack characteristics the research goes, the data could someday drive highly focused support to specific populations who are more vulnerable to contagion than others.

The great debate

A genuine debate about whether mass violence contagion is a “thing” has been largely centered around figuring out the correct model with which to analyze the data. Opposing results have come out of the current lines of research—some studies show that apparent temporal clustering of attacks represents contagion (i.e., events cluster together more than chance would predict), while others show ordinary statistical variation (i.e., randomness). Let’s break it down.

Some studies confirm a contagion effect, including the first one to tackle this topic. Confirmation probably resonates with readers of the TAB. After all, extensive media coverage provides plenty of scripting and modeling for copycatters to draw from, so it stands to reason that such events could also serve as inspiration for at least some to act now. Some intriguing articles finding a contagion effect have been published. This one from 2015, with which many of you will be familiar, found that mass killings with a gun and school shootings were temporally contagious for around 13 days, if the index event involved four or more killed. If three or fewer victims died, the effect evaporated. Pretty interesting, right? Hold that thought.

Other research has gone the opposite way, finding only randomness. Those authors point out that temporal clustering can happen naturally within rare-event datasets; basically just by a throw of the dice, events can cluster. This argument, too, makes sense. If you flip a coin a thousand times, at some point you’re going to get a bunch of tails in a row. That doesn’t mean the tails side became contagious. Using the same mass killings data (but not the school shootings) as the 2015 paper I reference above, a different research team using a different method of analyzing the data found no evidence of short-term contagion, and published their work in 2018.

So who’s right?

I’d say it’s not yet clear. Studies finding evidence of contagion tend to be built around a process called “Hawkes,” which starts from a place of assuming the events being studied could influence one another, and it seeks to detect and measure that influence if it exists. Studies finding the opposite tend to be built around a process called “Poisson,” which starts by assuming the events being studied are independent and random, and you’re basically testing against it (i.e., is this pattern somehow distinct from randomness?). Each of these models has its pros and cons in terms of the kinds of data it optimally handle. There has also been methodological disagreement about the way data are sorted, or “binned” for study—also with pros and cons.

The question is, is there a model that’s optimal for violent mass attacks, from which we can derive a confident answer on contagion?

The latest study

So that brings us to the most recent article. The authors took the stance that prior studies’ methods and limitations offer insight about how to build a better model for analyzing contagion. After considering those areas for improvement, this team designed a new model (for statistics fans, it was a three-stage, modified Poisson (periodically-observed time-homogenous Poisson process/Poisson Surprise) + binned model) and used it on a data set of US mass killings 2006-2023—taken from the same database as prior studies used.

Using this new process, the authors found no evidence to support a prominent contagion effect. They did find statistical irregularities between media notoriety of some types of attack and the timing of a subsequent one that weren’t consistent with a subtle contagion effect, yet merit further research to fully understand if there’s an association there. More study is indicated. This sample included three incident types: mass killings committed during the course of another felony, family mass killings, and public-setting mass killings. All were temporally random according to the analysis, although the cause of a huge jump in overall incidence of public mass killings, from late 2015 onward, is unknown and also requires further study.

Important Caveats

These studies largely sourced their incident data from the Mass Killing Database (MKD), jointly maintained by the Associated Press, USA Today, and Northeastern University. The MKD contains only events in which four or more victims were killed. Crucially, that means we don’t know what this methodology or earlier ones would have found regarding mass shootings where fatalities didn’t necessarily occur, or where there were only three fatalities instead of four or more. That’s a pretty serious limitation. And note: the 2026 authors aren’t asserting their analysis precludes the existence of a contagion effect—just that their study didn’t find it.

This won’t be the last word on this, and I’m very interested to read the next chapter, whenever that appears. Until there is consensus on the right statistical model, we’re in a holding pattern on the question of contagion. For now, I’d caution against leaning too heavily into a 13 day period and 4 or more killed equals heightened concern (or, for that matter, that 3 or fewer killed means don’t sweat it), from a resource and operations standpoint. We’re vigilant all the time and, anyway, the best BTAM practice is to focus on prevention, not prediction.

Final note: An even newer study has been done on a contagion effect related specifically to the fate of mass attack perpetrators—isolating each perpetrator’s decision to die at the scene or to live, separate from the decision to attack at all. This is the first team I’m aware of to carve out a specific attack characteristic to study for contagion. I’ll share those results once a final article is published, so stay tuned.

U.S. v. Hemani narrows the usability of one BTAM disruption tool

In a U.S. Supreme Court term filled with high profile and politicized cases, one interesting ruling for BTAM quietly dropped just before the Court closed up shop for summer recess: U.S. v. Hemani. This case relates to Title 18 U.S.C. § 922(g)(3), the federal criminal statute that says unlawful users of a controlled substance can’t possess a firearm. It’s one of the charges you might see filed to disrupt persons of concern on the pathway to targeted violence, or even against a parent or caretaker of a juvenile who got their hands on a gun from home and used it/planned to use it in an act of targeted violence. In fact, it was successfully charged against a parent in association with at least one school shooting case. Remember the 2023 shooting of first-grade teacher Abby Zwerner by a student in her own classroom in Virginia? That one.

In this appeal, a unanimous Supreme Court held that the Second Amendment to the U.S. Constitution prohibits the government from prosecuting someone as a prohibited possessor of a firearm based exclusively on regular marijuana use. Marijuana is still a controlled substance under federal law, and Hemani was an every-other-day user.

In my experience, this is one of those cases that will be prone to misinterpretation unless one reads the opinion in full (or reads the TAB). The Court did NOT strike down § 922(g)(3) as being per se unconstitutional and this ruling does NOT prohibit § 922(g)(3) prosecutions where the substance is marijuana. It only says that regular marijuana use alone can’t support a prosecution of a firearm possessor under this statute. 

The Court didn't say exactly what evidence would be necessary for a prosecution, but they pointedly left several doors open. According to the decision, the Hemani decision does not take a stances on prosecutions:

  • with respect to a person who’s intoxicated by a controlled substance while possessing a gun,

  • where there is individualized proof that the controlled substance makes the person dangerous, or

  • where there is proof that a particular drug always makes its users dangerous due to its potency or some other reason.

I’m pretty skeptical that the third point has a real-world fit, being unaware of any scientific evidence that there’s a controlled substance out there that always makes its users dangerous. Always is a big word. But the first two points are very viable.

Just few weeks ago, the federal Eight Circuit Court of Appeals upheld a conviction under § 922(g)(3) after Hemani. It’s well worth a quick review to examine what separates that success from the failed case in Hemani:

In United States v. Baxter, the defendant gang member was arrested at the scene of an intergang fight. He had a loaded gun and marijuana on him at the time, and a tox screen showed THC or marijuana metabolites in his blood at the time of arrest. He was charged under § 922(g)(3). In making its case under the statute, the government introduced content from Baxter’s social media showing him smoking and/or having marijuana, and showing him brandishing and/or pointing firearms. It introduced expert testimony of a strong connection between chronic marijuana use and aggressive and violent behavior, as well as aggression during withdrawal for good measure. Finally, a police detective in the intelligence unit testified in detail to Baxter’s long-time, frequent marijuana use and possession of as many as 10 firearms. I omit some legal argument on Second Amendment jurisprudence, and for now simply point out the considerable evidentiary differences between Hemani and Baxter.

My Takeaway

If you’re considering a § 922(g)(3) or similar state law prosecution, know that the mere fact of marijuana use isn’t enough to support that charge. You should assume the same for other illegal substances. Inquire: How does the substance use affect the person of concern? Does it contribute to a more dangerous situation? If so, how? Although Hemani was focused on danger presented by the owner/possessor of the firearm, what about a parental situation where evidence shows substance use has directly resulted in failure to secure a gun from a child? Be thorough and consider all aspects of the relationship between the person’s substance use and firearms.

No human access to some customer chat logs at OpenAI

OpenAI just announced a new feature of its Zero Data Retention Policy (ZDR) that ensures no human at OpenAI can view any content of certain customers, even after a safety alert is kicked out by the AI model being used. I know, sounds kind of alarming. After thinking this through, I don’t think it’ll be as extreme as it sounds, but let’s take a look.

OpenAI specified this new option will be available to “eligible API customers.” After poking around online, I believe we’re talking about certain enterprise clients. I can understand how OpenAI found itself at this decision point. When a customer’s data includes things like financial records, health data, confidential business plans, or proprietary research, it would likely violate organizational policy, and probably in some cases regulatory requirements, to use a third party processing service (OpenAI) that allows the third party’s employees to access the customer’s data. But government regulation and corporate policy are two very different things, and where no regulation prohibits doing it, OpenAI almost certainly could carve out a contractual right to review usage flagged as potentially unlawful on its systems, like child sexual exploitation or homicidal planning. That doesn't mean the customer has to accept those terms, of course.

I predict that the “eligible API customers” will be contractually obligated to take responsibility for all safety implications of providing the tool to its employees, leading to some necessary pondering for corporate threat assessment teams. More on this, below.

That leaves non-”eligible API customers”—other enterprises and individual users—to whom this new policy won’t apply, at least for now. Given that it’s currently being sued because of alleged chatbot-facilitated violence, I would speculate that OpenAI will pursue more and more effective ways to prevent its models from being used for bad purposes, even if certain enterprise clients are the responsible parties rather than OpenAI.

Private Safety Processing (PSP) is the name of this few ZDR feature. It actually sounds like an improvement. According to OpenAI, existing ZDR safety systems assess individual interactions between users and AI chatbots. PSP, on the other hand, assesses for risk patterns across related interactions. That sounds like a step in the right direction to me, anyway. For enterprise clients using PSP, when something the AI recognizes as concerning is flagged, two alerts will go out: one to OpenAI and one to the customer; only the customer alert has specifics. OpenAI is only notified of category and severity of the alert.

Takeaways

For corporate threat assessment teams to whom this new policy applies, I recommend promptly discussing this with, at minimum, your IT group and legal counsel. Questions to be answered include but are not limited to: Is the enterprise is entitled to rely on OpenAI’s PSP rather than set up a method of its own to detect concerning or unlawful content in chats? Will that reliance shield it from liability if a threat is not detected by PSP? Even if entitled, does the enterprise want to rely on PSP? Once a safety alert is received, what will your process be for responding to it?

SIGNALS—What I’m watching in BTAM

Final report on the July 2024 assassination attempt on the President

For those interested, DHS has released a redacted version of its OIG final report on missed opportunities to prevent and disrupt the first assassination attempt against then-candidate Trump in July 2024.

New York requirement for WPV prevention plans in hospitals and nursing homes

Starting September 2027, hospitals and nursing home in New York will have to institute workplace violence prevention programs that comply with certain provisions of the Code of Federal Regulations. There is no direct mention of BTAM in the statute, though every county and major city in the state should already be running some kind of threat assessment team pursuant to the governor’s Executive Order 18.

That’s all for this issue of the TAB. Comments or ideas for an issue? Just reply to this email. I read every message.

Reply

Avatar

or to participate