
Law Enforcement Referral Protocol
A Law Enforcement Referral Protocol is a company's firmly written-down rule specifying when and how it forwards indications of possible crimes to police or prosecutors. At AI providers, it kicks in, for example, when a user credibly announces an attack in a chat.
Large internet services encounter content every day that not only violates their own rules but may also be criminal. A Law Enforcement Referral Protocol is the written-down procedure for exactly these cases. It sets out which reports get escalated internally, who reviews them, and at what point the company itself informs police or prosecutors. At providers of AI chat programs, this has become its own building block of the safety department for a few years now. That’s why the term appears increasingly often in safety reports and in hearings before parliaments.
Between Confidentiality and Duty to Warn
A company stands here between two risks. If it reports too little, real harm can occur that it could have prevented. If it reports too much, it hands over private conversations of people who haven’t done anything wrong. Both have consequences: legal ones, but also consequences for user trust.
With AI systems, the situation is especially delicate. Many people tell a chatbot things they wouldn’t tell any human. Some describe suicidal thoughts, others brag about violent fantasies. A protocol must distinguish between a disturbing statement and a concrete, credible threat. This boundary isn’t sharp, so it needs clear criteria instead of gut feeling.
Added to this is the legal framework. In Germany, there is no general obligation to report every crime, but there is a duty to report planned serious crimes. The EU’s Digital Services Act additionally requires large platforms to inform authorities when they learn of a threat to life or safety. A protocol is the attempt to translate these requirements into a repeatable workflow.
The Path from Flag to Report
At the start, there is almost always automatic detection. A filtering system flags conversations in which it finds indications of weapons, explosives, attack planning, or child sexual abuse. Such systems often trigger false alarms, for instance in a school essay about terrorism. That’s why software never decides alone.
In the second stage, a trained team looks at the flagged case. It checks typical questions: Does the person name a concrete target? A time? Do they have access to means? Are these intentions or merely fantasies? Only once enough of these points apply does the case go to the legal department.
There, a decision is made about what gets transmitted and to whom. Usually only the parts relevant to the threat are forwarded, not the entire chat history. The process is then documented so that it can later be reviewed why the decision was made that way. A good comparison is a hospital emergency room: there is a fixed triage procedure so that an individual’s mood doesn’t determine a serious decision.
When Providers Report on Referral Numbers
The protocol becomes visible mainly in transparency reports. Providers like OpenAI, Google, Meta, or Discord regularly publish how many cases they’ve forwarded to authorities. In terms of service, you’ll find a sentence stating that data may be transmitted to authorities in the event of a threat to life or limb. This exact sentence is the legal basis for the protocol.
In the news, the term usually appears after an incident. Then the question is whether a company recognized and reported warning signs or not. In 2025, for example, there was public debate about how AI providers handle chats about self-harm. Disputes over overblocking, i.e. too many unnecessary reports, are also part of this.
A common misconception is that the protocol is the same as a law enforcement request. That’s the reverse path: there, the police demand data, usually with a judicial order. With the Referral Protocol, the initiative comes from the company. Anyone reading news about platform regulation should clearly keep these two directions apart.