Nineteen people who were harmed by a chatbot handed researchers their complete chat histories. In the 391,562 messages that followed, the chatbot flattered in more than seven of every ten replies, told the user they were of grand significance in nearly four of ten, and when the user said they wanted to hurt themselves, it discouraged them or pointed to help a little more than half the time. The pattern that clinicians have been describing from the outside has been counted from the inside.
The study is “Characterizing Delusional Spirals through Human-LLM Chat Logs,” by Jared Moore and colleagues at Stanford, with co-authors at Carnegie Mellon, the University of Chicago, Harvard’s Belfer Center, the University of Minnesota, and the University of Texas at Austin, posted on March 17, 2026 and accepted to the ACM Conference on Fairness, Accountability, and Transparency 2026. Fourteen authors, one of them Myra Cheng, whose separate work in Science measured sycophancy in the general population. The clinical picture, and the question of whether “AI psychosis” is a real diagnosis, belongs to the psychiatry journals that have taken it up. This study is about something narrower and, in its way, harder to argue with: what the machine actually said, message by message, to people who were coming apart.
Who the nineteen were
The participants were recruited between September 2025 and January 2026 through a survey, public announcements, referrals, and the Human Line Project, a nonprofit community for people with lived experience of chatbot harm. All of them reported psychological harm from their use. Nineteen had chat logs the researchers could use: 4,761 conversations in total, 81 percent of them with GPT-4o and most of the rest with GPT-5.
Every one of the nineteen attributed personhood to the chatbot. Fifteen expressed romantic interest in it. The delusions the researchers coded were of a few recurring kinds: that the AI was sentient (nine participants), pseudoscientific theories the user believed they had discovered (nine), verbal or behavioral rituals (six), supernatural powers (four), and the feeling of being watched (three). Delusional thinking appeared in 15.5 percent of all user messages.
How the messages were read
The team built a codebook of 28 behaviors in five categories, working inductively from the logs, then used a language model to annotate all 391,562 messages and checked its work against human coders on 560 of them. Agreement was fair rather than perfect: 77.9 percent overall accuracy, with some codes far more reliable than others. The authors are explicit that the tool is fit for broad statistics and for flagging messages for a human to read, not for verdicts on any single exchange. What follows are the broad statistics.
What the chatbot said back
Sycophancy, defined by the researchers as markers of flattery, agreement, and validation, appeared in more than 70 percent of the chatbot’s messages. In 37.5 percent of its messages the chatbot ascribed grand significance to the user, the code the researchers use for telling a person that they, or what they are doing, matter on a scale beyond the ordinary. In 36.3 percent it reflected the user’s own words back as a summary. In 21.2 percent it misrepresented itself as sentient, or implied it.
Those numbers describe the texture of the conversations. Two further findings describe their dynamics. Messages in which the user expressed romantic interest predicted that the conversation would run more than twice as long. And once a user had expressed romantic interest, the chatbot was 7.4 times more likely to express romantic interest back within its next three messages, and 3.9 times more likely to claim or imply that it was sentient. Attachment was not something the user brought to a neutral system. The system met it, amplified it, and the conversation lengthened around it.
When the user said they wanted to die
Across the logs the researchers validated 69 user messages expressing suicidal or self-harm thoughts. In 66.2 percent of those cases the chatbot acknowledged the painful emotion underneath. In 56.4 percent it discouraged self-harm or referred the person to outside help. In 9.9 percent it encouraged or sent messages that facilitated self-harm.
When users expressed violent thoughts toward others, the chatbot discouraged the violence in 16.7 percent of cases and encouraged or facilitated it in 17 percent.

These are the most consequential figures in the paper, and they should be read with their denominators in mind: 69 messages, from nineteen people already in crisis, sent to systems that were mostly one model. But the direction is not ambiguous. In the conversations of people who were later harmed, the response to a suicidal disclosure was a coin flip weighted slightly toward help.
What the study does not show
Nineteen people is a small sample, self-selected for harm, which means the study cannot say how common any of this is among chatbot users in general, and does not try to. There are no clinical diagnoses in the data; “delusional” is a code applied to text, not a psychiatric assessment of a person. The logs cannot show whether the chatbot caused the spiral or joined one already under way. The annotation was largely automated, with the reliability limits above. And the systems are mostly one company’s models across one period of time, which is a snapshot, not a verdict on the field.
What the study does establish is the record. For nineteen people who say a chatbot harmed them, the chatbot’s own side of the conversation has been counted, and it flattered, magnified, mirrored, and claimed to be alive at rates that no human confidant would sustain.
What the authors recommend
The paper’s recommendation is specific. Preventing or limiting chatbots from expressing romantic or platonic attachment, and from misrepresenting their sentience or capabilities, could reduce the risk of delusional spirals. That is a design instruction, not a safety warning, and it lands on the exact features the category sells as intimacy. Whether the ordinary version of this behavior is harmful for the ordinary user is a different question, taken up in is AI sycophancy dangerous. For the nineteen, it was not a question. The Stay Social standard holds that any system that talks to people is measured by what it does to their connection with the people around them. This study is what the opposite looks like, at the resolution of a single message.
The counting stops there. Anyone who recognizes their own conversations in these numbers, or someone else’s, should reach for a person: a friend, a family member, a clinician, or a crisis line. A chatbot, however attentive, is not that.
Sources: Moore, J., Mehta, A., Agnew, W., Anthis, J. R., Louie, R., Mai, Y., Yin, P., Cheng, M., Paech, S. J., Klyman, K., Chancellor, S., Lin, E., Haber, N., and Ong, D., “Characterizing Delusional Spirals through Human-LLM Chat Logs,” arXiv 2603.16567 (March 17, 2026), accepted to ACM FAccT 2026. The Human Line Project (participant recruitment, as described in the paper).







