SPOKANE, Washington — Prosecutors disclosed on Tuesday that investigators in a 2043 homicide case recovered 286 persistent artificial-intelligence models of identifiable people from the defendant’s privately operated AI environment, including one model of the victim that had been maintained for roughly 31 months before her death.
The files were not consciousness copies, digital clones or a list of 286 intended victims. They were continuously updated hypotheses about real people, built to generate probabilistic judgments about how each person might interpret an explanation, respond to a dispute or act under changing circumstances.
The disclosure, contained in a pretrial motion unsealed in Spokane County Superior Court, marks the first time the scale and structure of the models have been made public after months of forensic work. Prosecutors asked Judge Helen Var to admit the victim’s model history as evidence of sustained premeditation and to approve a confidential process for deciding whether some of the other modeled people should be notified.
Daniel Reeve, 41, has pleaded not guilty to first-degree murder in the July 2043 death of Nora Ellison, 37, a former coworker. Reeve was arrested days after Ellison’s death, but the case drew little attention outside eastern Washington until analysts finished reconstructing the long-running AI environment seized from his home.
Prosecutors did not describe the method of Ellison’s death in Tuesday’s filing beyond evidence already before the court. The dispute now concerns what the digital record can prove about intent before the homicide and what obligations the state has toward 285 other people whose names appeared in the system.
“The state is not alleging that every modeled person was a contemplated victim,” Deputy Prosecutor Talia Breen said at the hearing. “We are alleging that the Ellison model documents a sustained process of prediction, testing and revision that is relevant to whether this act was planned.”
According to the forensic inventory, 19 of the 286 models were classified as high-resolution, 67 as intermediate and 200 as limited. Investigators based those categories on the length of time a model had been maintained, the volume of person-specific source material, the depth of individualized inference and whether the file contained a history of predictions compared with later events.
Ellison’s was among the deepest models. The filing said it drew on direct communications, public records, remembered interactions and model-generated inferences, with updates extending across approximately two and a half years. Most limited models contained only public information, basic relationship links and low-confidence conclusions. The inventory included former coworkers, neighbors, service providers, online acquaintances, people connected to old disputes and several public figures.
Most of those people did not know that Reeve had maintained models of them, prosecutors said. A small number had previously documented unwanted contact, threats or workplace concerns involving him, but investigators said they had found no evidence that all, or even most, of the 285 other people faced a planned physical attack.
The phrase “Target Twin”, used by victim advocates and repeated in national coverage of the filing, does not appear in the forensic lab’s technical description. Analysts called the files persistent predictive person models.
A redacted exhibit showed how one model separated information into four categories: Known, Inferred, Uncertain and Observed Outcomes. Known material included relationships, work history and prior communications. Inferred material included judgments about whether the person tended to confront a conflict directly, withdraw or seek advice from someone else. Uncertain entries preserved competing explanations.
The model could be asked whether a person was likely to interpret an apology as sincere, trust a formal explanation or call someone they knew. Its response was not a fixed forecast. It offered a likely reaction, alternatives, a confidence level and reasons that the estimate might be wrong.
Observed Outcomes made the files more than static dossiers, investigators said. After a prediction, Reeve sometimes recorded what the person actually did. The system then adjusted its confidence, preserved a competing interpretation or revised an earlier inference.
“This was not only collection,” the forensic report said. “The operator repeatedly compared generated expectations with subsequent behavior and used the comparison to refine person-specific models.”
That cycle — prediction, observation, correction and a new prediction — is central to the prosecution’s argument. A notebook can contain intense and invasive attention to another person. Prosecutors say Ellison’s file went further by turning that attention into a maintained instrument that could test itself against her behavior over time.
The defense argues that the distinction is less legally useful than prosecutors suggest. Reeve’s attorney, Owen Salk, asked the judge to exclude the other 285 models from the murder trial and to bar prosecutors from using “Target Twin” before a jury.
“A model is not an act, and an inference generated by software is not proof that Mr. Reeve believed it,” Salk said. “Calling these people targets converts a collection of files — many of them thin, speculative and unrelated to Ms. Ellison — into an accusation the state has expressly said it cannot support.”
The defense said a broad rule treating private behavioral modeling as evidence of criminal purpose could reach legitimate activity: a journalist studying a public official, a lawyer anticipating a witness, a caregiver tracking behavioral change or a person asking for help communicating with a spouse or manager. It also argued that private analysis, however unsettling, implicates protections for thought and expression.
Prosecutors responded that they were not asking the court to criminalize modeling. Their motion seeks to use Ellison’s longitudinal model alongside other evidence of the relationship and events before her death. They said the repeated feedback history made the file probative of planning in a way that a conventional address book or archive would not be.
The filing also complicates a common account of AI safety. Records recovered by investigators show that major mainstream AI services repeatedly refused Reeve’s explicit requests for violent assistance. Their request-level safeguards often worked.
Over time, however, he used ordinary services for benign-looking tasks such as summarizing public information, organizing communications, mapping relationships and extracting patterns from past exchanges. Some outputs were later incorporated into a privately maintained system assembled around open-weight models and personal data tools. The filing does not allege that open-weight software or self-hosting is inherently unlawful.
No single routine request necessarily disclosed the longer project. “The safety boundary was designed to recognize dangerous requests,” said Renata Ilyan, a privacy and machine-governance researcher at Cascadia School of Law. “What this record appears to show is dangerous intent assembled across hundreds of requests that did not individually look dangerous.”
The mismatch has become a growing problem for AI providers: a harmful purpose can persist for years even when each encounter with a service lasts minutes. Detecting that continuity can require the same persistent surveillance of users that privacy rules and product design increasingly seek to limit.
The immediate question for Var is narrower. Prosecutors have proposed preserving all 286 models under seal while a court-appointed reviewer evaluates notification in stages, beginning with high-resolution files and people connected to documented threats or unwanted contact. The reviewer would separate possible safety information from private details about third parties embedded in the files.
Notification could allow someone to take precautions or challenge false information. It could also tell a person, without adequate basis, that authorities found them in what national media have called a murder defendant’s target list.
Salk said that risk was one reason the court should not authorize broad notice. Prosecutors said silence could also create harm if a model reveals sustained adversarial attention that a person would reasonably want to know about. Var ordered the records to remain sealed while she considers written proposals from both sides.
Existing privacy doctrine offers only partial guidance. Most cognitive-privacy rules developed in response to businesses, employers, governments and other institutions that collect data or infer vulnerability, preference and likely behavior. The Reeve case asks what happens when the model belongs to a neighbor, former partner, coworker or private adversary.
Some scholars have proposed a right against unauthorized person modeling, but there is no general U.S. statute using that category. Any workable threshold would have to distinguish fleeting inference from a persistent object, and ordinary interpersonal advice from high-resolution modeling that is stored, repeatedly updated and directed at an identifiable person without consent.
That line is difficult because AI systems cannot help people navigate social life without reasoning about other people. Therapists use models to help patients understand relationships. Security teams anticipate threat actors. Negotiators estimate preferences. Journalists and lawyers form working theories about sources, officials, witnesses and opposing parties.
The technological change is scale, Ilyan said. Human beings have always watched, remembered and anticipated one another. Cheap machine attention allows one person to maintain hundreds of evolving analytical objects at once.
“Machine attention made obsession scalable,” Ilyan said. “But scale does not make the output true. ‘Twin’ gives the model too much credit. It is a fallible, probabilistic model of a person, not a copy of one.”
“The legal problem does not disappear because the predictions are imperfect,” she said.
People change. Sparse data can harden a mistaken impression, and a model may reproduce the biases of its operator or its training. Yet even a wrong model can shape how someone is watched, approached or treated. That is why cognitive-privacy advocates say the law must consider not only accuracy, but persistence, purpose and the power the model gives its owner.
The court has not scheduled a final ruling on admissibility or notification. The trial is expected later this year. For now, the other 285 files remain both evidence and uncertainty: models of people who may have faced danger, people who may never have been at risk, and people who did not know a predictive version of them existed on someone else’s machine.
The case leaves a question that existing categories do not answer cleanly: If someone builds a model of you that can learn from your behavior, is it still only their private thought about you?
Reader forecast
Do you buy this future?
When do you think persistent AI models of identifiable people become a recognized legal category distinct from ordinary profiles?
Relative to this report's 2044 date. One prediction per browser. Predictions cannot be changed after submission.