Image: The American Prospect / prospect.org Anthropic Is Building a System to Predict and Monitor AI Critics
A new investigation reveals Anthropic contracts with risk-detection firms, runs a Global Security Operations Center, and lists investigating 'activism' in job postings alongside terrorism.
Anthropic is running a security operation that goes beyond protecting its buildings. According to an investigation published today by The American Prospect, the company is building out a monitoring system that tracks protest activity, predicts activist behavior, and in some cases, reports users to law enforcement.
The reporting draws on job postings, a podcast interview with Anthropic’s Global Security Operations Center Manager, and interviews with security officials at the company. Taken together, they sketch a picture that sits uneasily with Anthropic’s public positioning as a safety-focused, responsible alternative to its competitors.
How the system works
Keon Ellison, who manages Anthropic’s Global Security Operations Center, described the program in a podcast interview. He said the company contracts with Samdesk, a risk-detection firm, to monitor events near Anthropic facilities and executives. When protest organizers shifted the timing of a planned demonstration, Samdesk gave Anthropic roughly 60 minutes of advance notice, which Ellison said allowed executives to use alternate routes and service entrances.
That kind of reactive intelligence is standard corporate security. What goes further is the “pre-crime” framing that appears in both job postings and internal descriptions. Anthropic’s security program manager described the goal as “transforming operations from reactive information to gathering proactive and predictive and preventative threat engagement.”
A recent job posting for an enterprise intelligence specialist, paying $180,000 to $230,000, listed investigating “activism” explicitly alongside terrorism and geopolitical threats.
Reporting users to police
The investigation also describes cases where Anthropic reported its own users to local police departments. In one San Francisco case, the company flagged a user who had told Claude he owned an AR-15 and had CEO Dario Amodei “in his sights.” The user said later he was joking. Anthropic reported the incident to police but did not share the actual messages with officers.
The decision not to share the messages makes it difficult for law enforcement to make an independent assessment of the threat, while still generating a police record for the user.
The tension with Anthropic’s public identity
Anthropic has built its brand around being the measured, thoughtful voice in the AI industry. It publishes safety research, talks often about the risks of moving too fast, and has cultivated a reputation as the company that takes the long view. That positioning has attracted researchers, investors, and customers who want to back a company they trust.
Tracking activist groups, flagging internal job descriptions with “activism” as a threat category, and running predictive surveillance infrastructure is a different posture. These programs aren’t necessarily illegal. Many large companies do similar things. But they sit awkwardly next to the public narrative.
Anthropic did not respond to The American Prospect’s request for comment.
The story arrives on the same day Bloomberg reported Anthropic walked away from a planned $6 billion acquisition of Decart AI, and just one day after a class-action lawsuit was filed over its Max subscription pricing. The company is reportedly preparing for an IPO later this year.
Source: The American Prospect