Skip to content

PAN Lab example

Crisis Text Line & Loris.ai

The corpus and the spinoff: governing crisis-conversation data

Crisis Text Line, a crisis texting service, ranks waiting texters with a model. Loris.ai, a for-profit it partly owned, trained software on their conversations.

See more

Crisis Text Line, a US nonprofit, saves every crisis text conversation in a corpus, a store of texts that trains its own triage model. From about 2017 to 2020, Loris.ai, a for-profit company it partly owned, used that corpus to train commercial customer-service software.

The service

Crisis Text Line has offered free text-based crisis support around the clock since 2013. It also operates through affiliates in Canada, the UK, and Ireland.

As of early 2025 it reported nearly 10 million conversations and about 300 million messages since 2013. It reported more than 71,000 trained volunteers. It says it supported more than 1.5 million conversations in 2025, its highest-volume year.

The triage model

Crisis Text Line's data-science team built a machine-learning model to direct scarce counselor attention under heavy volume. The service describes it as several deep neural networks, a kind of machine-learning model, whose scores are combined into one. It was trained on about 65 million messages. It scores the opening messages of a conversation for severity. It then reorders the counselor queue by predicted risk, instead of by arrival time.

Crisis Text Line says the model identifies 86 percent of people at severe imminent risk in their first conversations. It says it aims to serve 94 percent of high-risk texters in under five minutes. These are self-reported blog and marketing figures, never independently evaluated.

The model decides who waits. It does not reply to texters or send emergency help. Volunteer Crisis Counselors tag conversations, for example "Suicide", and rate their risk in surveys afterward. Those labels are used to retrain the model.

Crisis Text Line still uses machine learning to rank risk. The sources do not say whether the 2018 model is still in use unchanged. Its error rates, and how often staff set it aside, have never been published.

Who decides about a rescue

When a texter may be in imminent danger, a paid clinical supervisor can authorize an active rescue. The supervisor contacts a local 911 center with the texter's phone number and carrier.

A 2020 Crisis Text Line self-report put active rescues at about 0.82 percent of conversations, roughly 28 a day. About 40 percent of conversations with imminent risk ended in a rescue. About 60 percent were de-escalated, meaning calmed, without one. The sources do not clearly document how many rescues were voluntary and how many were not.

The arrangement with Loris.ai

In November 2017, Crisis Text Line incorporated Loris.ai, a for-profit spinoff. Loris.ai was co-founded by Nancy Lublin, a co-founder of Crisis Text Line. Crisis Text Line held an ownership stake, which reporting based on Politico put at about 53 percent. A revenue-sharing agreement came with it. Per that reporting, the agreement had not taken effect as of January 2022.

Loris.ai used the anonymized corpus to train commercial customer-service and de-escalation software. Its website cited a "sentiment-rich" corpus of "62 million messages" from Crisis Text Line. That is a marketing figure, not an audited count. The exact number of records shared has never been made public.

How consent was gathered

Texters were asked for consent while in crisis. An automated reply pointed texters to a lengthy Terms of Service. The Markkula Center for Applied Ethics described it as a 50-page agreement. The Reform Crisis Text Line campaign described it as over 4,000 words. Critics noted that many texters are minors.

A former board chair, danah boyd, voted for the arrangement. She later said, "knowing what I know now, I would not have." Tim Reierson, a volunteer Crisis Text Line had terminated, argued publicly that a Terms of Service accepted mid-crisis cannot be meaningful informed consent. The case file does not say why he was terminated.

Who was asked

An outside data-ethics committee of academics and technologists reviewed research proposals. It was reportedly not brought into the decision to share the data with Loris.ai. As the case file puts it, a check that is not invoked is not a check.

How it ended

Politico reported the arrangement on January 28, 2022, and public backlash followed quickly. On January 31, 2022, Crisis Text Line announced it had ended the data-sharing and asked Loris.ai to delete the data. It stated the shared data had been anonymized and scrubbed of personally identifiable information, meaning details that identify a person. It said no such information was sold, and Loris.ai had not accessed the data since the start of 2020.

In March 2022, Brendan Carr, a commissioner of the Federal Communications Commission, wrote to Lina Khan, who chaired the Federal Trade Commission. He urged it to investigate how Crisis Text Line collects, keeps, and shares crisis-conversation data, and how it obtains consent. Crisis Text Line said it had engaged "in good faith" and that its practices comply with the law. No public enforcement action by the Federal Trade Commission is documented.

In 2025, chief executive Dena Trujillo replied to a commentary in the Journal of Medical Internet Research. She said texters must consent to the privacy policy to use the service, and can ask for deletion by texting DELETE. She said Loris.ai was required to return or delete data it had accessed. She said an Institutional Review Board, a committee that approves research involving people, has overseen in-house research since 2023.

Why this case is different

Most cases in the Lab turn on a model that is wrong, or on people who fail to catch it. This case is neither. The triage's accuracy is unaudited, but the harm here does not come from accuracy. The human review around the model is one of the better ones among the Lab's cases.

Three things make it distinct. First, a conflict of loyalty: the service had a stake in the company reusing its data. The chance of earning money from reuse settles the question without anyone deciding, unless governance is built to say no. Second, consent that cannot really be given: a Terms of Service is a legal document, not informed consent from someone texting a crisis line. Third, a review body that existed but was bypassed.

The case file also draws a lesson about deletion after the fact. You can ask for a copy of data back, but you cannot undo training a partner has already done on it.

What this network is drawn from

This network follows the pattern the case file documents. It does not reconstruct the actual service. It shows the triage model, the counselor queue, the counselors, the clinical supervisors, the corpus, the data-ethics committee and board, Loris.ai, and 911 services. The texters are outside the network, and no suicide or crisis outcome is computed.

What the available tools can and cannot address

A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. Here a mistake is, for example, a wrong severity score or a wrong risk label. Closing a pathway means mistakes stop passing along it. The work along it goes on.

This case has a budget of 11 units. Understand the system, a Lab option that lowers some tools' prices, is not on offer here. So every price below is the full price, the same at every target level. Explore (No Targets) sets no targets.

Lingering effects are effects that stay after their cause is gone. The Lab's Dynamics menu starts at Both, which includes them, under Explore (No Targets) and Service Targets Only, where you can change it. Service and Safety Targets fixes it at Side-effects, which leaves them out. Side-effects are costs that governance itself adds, such as staff leaning on an oversight layer. All Governance Targets fixes it at Both, which includes both side-effects and lingering effects. With lingering effects on, three tools work at reduced strength here: Peer sharing rules, Vet connections, and Store less data.

Under Service Targets Only, the targets are not met before any tool is used. Mistakes are copied about as fast as they are corrected. That level asks for them to be caught faster than they are copied, and for the model to be helping the work. At the starting setting, the cheapest ways cost 3 units: Peer sharing rules or Assign a challenger, each at its stronger setting. With lingering effects off, Peer sharing rules meets them on its own for 2 units. In all, nearly 500 different sets of tools within the budget meet them.

Under Service and Safety Targets, the targets can be met, but only by spending the whole budget. This level also asks you to close every failure pathway, among other targets. Five are open before any tool is used. They are Model reorders the queue, Past conversations train the model, Counselor labels retrain the model, Every conversation saved to the corpus, and Counselor escalates to a supervisor.

Escalate checks is the only tool on offer that closes Model reorders the queue. Mark AI-written records closes Past conversations train the model. Vet connections closes it too, but costs more and fits in no set within the budget. Keep prompts neutral is the only tool that closes Counselor labels retrain the model. In the Lab it keeps questions put to an AI neutral. Here it acts on the counselors' labels, and the sources describe no such practice. Gate record entries, or Store less data, closes Every conversation saved to the corpus. Peer sharing rules, or Assign a challenger, closes Counselor escalates to a supervisor.

So exactly four sets of tools meet the targets at this level, and each costs all 11 units. Each has Escalate checks, Mark AI-written records, and Keep prompts neutral. Each adds Gate record entries or Store less data, and Peer sharing rules or Assign a challenger.

Under All Governance Targets, lingering effects are on. Store less data then leaves Every conversation saved to the corpus open. Its stronger setting closes it but costs too much to fit beside the other tools needed. So exactly two sets meet the targets, each costing all 11 units. They use Gate record entries, with Peer sharing rules or Assign a challenger.

None of these sets acts on Corpus shared with Loris.ai, the link this case turns on. That link is not a failure pathway unless you add the pressure named Connectors sprawl. The targets also do not ask for either check to start. Peer sharing rules and Assign a challenger start the Data-ethics committee review. No tool on offer starts the Consent check on the corpus.

More is not better here. Using every tool at its strongest setting costs 34 units, about three times the budget. It contains the mistakes and closes every failure pathway. It still meets the targets at no level, because the model then adds too little to the work.

Stylized model of a documented deploymentBehavioral-health & crisis triage

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Crisis-Text-Line-class crisis-corpus governance network: 8 components and 12 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 5 assumed · 3 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

Show all 8 assumptions
  • assumed

    This network follows the pattern the Crisis Text Line and Loris.ai case file documents. It does not reconstruct the actual service, its model, or the exact terms of the arrangement. It covers how the conversation data was governed, not how accurately the model ranks texters.

  • baseline

    The network shows two checks that were not working when the data was shared. The outside data-ethics committee reviewed research proposals but was reportedly not asked about Loris.ai. So no standing review stood in the way of the commercial sharing. Crisis Text Line ended the arrangement three days after an outside news report. The sources also describe no check that the saved conversations carried meaningful informed consent before they were kept or shared.

  • baseline

    The network shows the corpus shared with Loris.ai, a for-profit company Crisis Text Line partly owned. Reporting based on Politico put the stake at about 53 percent. Loris.ai used the corpus to train commercial customer-service software, from about 2017 to 2020. The arrangement ended in January 2022. The network includes this link because the sharing happened. Loris.ai's own marketing cited 62 million messages, which is not an audited count, and the number of records shared is not public. Crisis Text Line disputes the framing. It says the data was anonymized, no personally identifiable information was sold, and Loris.ai had not accessed it since early 2020. The network shows Crisis Text Line sharing the data, not any harm that followed.

  • baseline

    The network places consent on the link that saves every conversation to the corpus. An automated reply pointed texters to a long Terms of Service, accepted in the middle of a crisis. The Markkula Center described it as a 50-page agreement. The Reform Crisis Text Line campaign described it as over 4,000 words. Critics note that many texters are minors. They argued that a Terms of Service is not meaningful informed consent for people in crisis. A former board chair who voted for the arrangement later said she would not have, knowing what she knows now.

  • assumed

    Unlike most cases in the Lab, the sources describe the human review here as working. The model only reorders the queue. Counselors keep full judgment within each conversation, and supervisors decide on active rescues themselves. The handoff from counselor to supervisor is a real, staffed step. This case's risks lie in how the data is handled, not in that review.

  • assumed

    The network treats the active-rescue link as a second place where consent is at stake. A supervisor can send emergency help using the texter's phone number and carrier. A 2020 Crisis Text Line self-report put active rescues at about 0.82 percent of conversations. Some may happen without the texter agreeing at the time. The split between voluntary and involuntary rescues is not clearly documented, so no figure beyond the 2020 self-report is used. A rescue here stands for an action the organization takes, never a life.

  • assumed

    One national model ranks every conversation. So any consistent error in the model applies to every conversation at once, with no second ranking anywhere to disagree with it.

  • assumed

    No suicide or crisis outcome is shown. The network shows how mistakes pass between the service's parts, and texters are not in it. Crisis Text Line's own triage figures are unaudited marketing claims and are not used. They are 86 percent detection, 94 percent of high-risk texters served in under five minutes, and a training set of about 65 million messages. The model's error rates, and how often staff set it aside, have never been published. The nearest peer-reviewed error figures for crisis-text triage come from SafeUT, a separate service, and are not attributed to Crisis Text Line.

What this example does not show

Show all 4 limitations
  • This example does not show suicide, crisis, or any clinical outcome, and the texters the service helps are not in it. A conversation, a severity score, or an active rescue here is an event in the organization, never a person in crisis. The case file records what the sources say about the service's clinical value and any harm to the people it serves. Those are measured outside this network.
  • The data-sharing figures are hedged as the sources hedge them. The figure of 62 million messages is Loris.ai's own marketing, not an audited count. The exact number of records shared with Loris.ai is not public. The ownership stake of about 53 percent and the revenue-sharing agreement come from reporting based on Politico's account of Crisis Text Line's finances. They are carried as reported, not as audited figures. Crisis Text Line disputes the framing. It says the data was anonymized, no personally identifiable information was sold, and Loris.ai had not accessed the data since early 2020. A commissioner of the Federal Communications Commission urged the Federal Trade Commission to investigate. No public enforcement action by the Federal Trade Commission is documented, and nothing here implies one occurred.
  • This example covers how the data was governed, not how accurate the triage is. Crisis Text Line's published figures are self-reported blog and marketing claims, never independently evaluated. They are 86 percent detection of severe imminent risk, 94 percent of high-risk texters served in under five minutes, and a training set of about 65 million messages. How often the model wrongly flags risk, misses it, or is set aside by staff has never been published. The nearest peer-reviewed error figures for crisis-text triage come from SafeUT, a separate crisis service in Utah, Idaho, and Nevada. Its figures must not be attributed to Crisis Text Line. The active-rescue figures are a 2020 Crisis Text Line self-report.
  • The dialect finding cited under Escalate checks is of the same kind. It is benchmark evidence about crisis-text classifiers as a group, reported in a 2026 book chapter by Yang and Traube. It carries no size figure, and the original benchmark study is not among this site's references. It is never attributed to Crisis Text Line's own error rates, which are unpublished. It is not a fairness measurement, and nothing in this network reads a texter.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • Crisis Text Line, a national nonprofit crisis service, built an in-house machine-learning severity-triage model that reorders which texters volunteer counselors reach first; from about 2017 to 2020 the same anonymized crisis-conversation corpus was routed to Loris.ai, a for-profit spinoff CTL held an ownership stake in — reported by Politico-derived reporting at roughly 53% — which used it to train commercial customer-service software. After a January 28, 2022 Politico exposé, CTL ended the arrangement within three days and requested that the data be deleted; an FCC commissioner referred the matter to the FTC in March 2022, and no public FTC enforcement action is documented. CTL states the shared data was anonymized and never sold as personally identifiable information, and the exact number of records shared has not been made public.

    empirical
    • Reference Crisis Text Line (Wikipedia, tertiary encyclopedia entry) (2026) https://en.wikipedia.org/wiki/Crisis_Text_Line
    • Vendor Crisis Text Line, An Update on Data Privacy, Our Community and Our Service (2022) https://www.crisistextline.org/blog/2022/01/31/an-update-on-data-privacy-our-community-and-our-service/
    • Advocacy Reierson, Reform Crisis Text Line (advocacy site) (2022) https://reformcrisistextline.com/
    • Trade press Benton Institute for Broadband and Society, FCC Commissioner Carr Calls for FTC Probe of Crisis Text Line (2022) https://www.benton.org/headlines/fcc-commissioner-carr-calls-ftc-probe-crisis-text-line
  • Crisis Text Line obtained consent for its data collection through an automated reply directing texters to a lengthy Terms of Service — described as a roughly 50-page or 4,000-plus-word document — accepted at the moment of acute crisis by users who include many minors; critics including a former board chair, who voted for the data-sharing arrangement and later said she would not have "knowing what I know now," and a terminated volunteer argued that a Terms of Service is not meaningful informed consent for people in crisis. CTL says texters must consent to its privacy policy to use the service and can request deletion by texting the word DELETE, and that since 2023 its in-house research has been overseen by an Institutional Review Board.

    empirical
    • Academic Markkula Center for Applied Ethics, Santa Clara University, Crisis Data: An Ethics Case Study (2022) https://www.scu.edu/ethics/focus-areas/internet-ethics/resources/crisis-data-an-ethics-case-study/
    • Academic Eysenbach, Crisis Text Line and Loris.ai Controversy Highlights the Complexity of Informed Consent on the Internet and Data-Sharing Ethics for Machine Learning and Research (Journal of Medical Internet Research, editorial, 2025) https://pmc.ncbi.nlm.nih.gov/articles/PMC11799832/
    • Advocacy Reierson, Reform Crisis Text Line (advocacy site) (2022) https://reformcrisistextline.com/
    • Academic Trujillo, Response From Crisis Text Line to Commentary on Protecting User Privacy and Rights in Academic Data-Sharing Partnerships (Journal of Medical Internet Research, 2025) https://pmc.ncbi.nlm.nih.gov/articles/PMC11799801/

Where this connects

Institutional pressures in this domain

  • Workload surge — Demand outruns staffing; per-case attention shrinks and review becomes triage.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Deadline pressure — Statutory or managerial timeliness rules reward fast approval of machine output over slow disagreement.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.

All of them in context on the Behavioral-health & crisis triage domain page.

Levers available here and the patterns behind them

Documented case histories