Pull to refresh
Logo
Anthropic builds predictive surveillance operation to monitor activists

Anthropic builds predictive surveillance operation to monitor activists

New Capabilities

AI lab tracks protests in real time and reports chatbot users to police over in-app speech

Yesterday: Prospect publishes surveillance investigation

Overview

Updated 1 hour ago

Anthropic, the AI lab that positions itself as the safety-first alternative to OpenAI, runs a 24/7 security operation that tracks protest activity near its executives and keeps files on individuals it calls 'persons of interest.' It reports chatbot users to police based on what they type to Claude, and its own security manager describes the goal as predictive, preventative threat management.

The American Prospect's 9 September investigation, built from job postings, police records, and a podcast interview with two of Anthropic's security chiefs, shows the company pays intelligence analysts up to $230,000 to investigate 'activism' as a threat category, alongside terrorism and crime. In one documented case, Anthropic reported a Claude user to San Francisco police for saying he had CEO Dario Amodei 'in his sights,' then declined to show police the actual chat logs.

Why it matters

A private AI company now decides which chatbot conversations become police referrals, with no court review and no public oversight.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$230,000
Top salary for Anthropic intelligence analyst role
The enterprise intelligence specialist posting lists a range of $180,000 to $230,000 to investigate threats including 'activism.'
60 min
Advance notice from Samdesk of a moved protest
Anthropic's security operations center manager said the alert let the company reroute an executive away from a demonstration.
24/7
Global Security Operations Center coverage
Anthropic runs a round-the-clock security center that monitors protests and threats near executives and facilities.
1
Documented police referral from chatbot speech
Anthropic reported a Claude user to San Francisco police over an alleged threat to its CEO, then withheld the chat logs.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

Play

Exploring all sides of a story is often best achieved with Play.

Most of these play right now — no account needed. Sign up to save scores, keep a streak, and unlock Debate and Predict. Log in Sign Up
Predict 4 ways this could play out. Back the one you believe — contrarian picks score more when a scenario has a resolution date. Log in to play

People Involved

Organizations Involved

Timeline

2025 September 2026

5 events Latest: Yesterday
Tap a bar to jump to that date
  1. Job posting seeks intelligence analysts

    Recruiting

    Anthropic posts $180K-$230K role to investigate threats including activism.

  2. WSJ reports person-of-interest tracking

    Disclosure

    Anthropic tells the Journal it tracks concerning behavior over time to catch escalation early.

  3. Anthropic security chiefs describe protest monitoring

    Disclosure

    In a podcast, security managers describe using Samdesk for real-time protest tracking and executive rerouting.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

1956–1971

COINTELPRO (1956–1971)

The FBI ran a covert counterintelligence program targeting domestic political groups—civil rights organizers, anti-war activists, and others. Agents used informants, wiretaps, and disruption tactics against citizens with no criminal charges.

Then

Exposed in 1971 when activists burglarized an FBI office in Media, Pennsylvania, and leaked documents to the press. The Church Committee investigations followed, leading to restrictions on domestic surveillance.

Now

Generated lasting legal limits on government surveillance of political activity, including the Foreign Intelligence Surveillance Act of 1978.

Why this matters now

Anthropic's job posting lists 'activism' as a threat category alongside terrorism and crime. The parallel to state surveillance of political dissent is direct, except this time a private corporation with national security ambitions runs the program.

December 2014 – June 2015

Elonis v. United States (2015)

Anthony Elonis posted rap lyrics on Facebook describing killing his wife and an FBI agent. Federal prosecutors charged him under a law barring interstate threats, and a jury convicted him.

Then

The Supreme Court reversed the conviction 8-1, ruling that prosecutors must prove the speaker intended the statement as a threat.

Now

Established that online speech can't be punished as a threat without proof of intent, giving First Amendment protection to hyperbolic or joking statements.

Why this matters now

Anthropic reported a user to police for telling Claude he had an AR-15 and CEO Dario Amodei 'in his sights.' The user said he was 'just f**king around'—exactly the kind of speech Elonis protects unless intent is shown.

2014–2016

Geofeedia and protest surveillance (2014–2016)

Chicago's Geofeedia sold law enforcement a social media monitoring tool that tracked protesters in real time during the Ferguson uprising and Black Lives Matter demonstrations. The ACLU of California obtained procurement records tying the tool to hundreds of police departments.

Then

After the ACLU exposed the contracts in October 2016, Facebook, Twitter, and Instagram cut off Geofeedia's access to their data streams. The company's core product collapsed.

Now

Showed that private protest-surveillance tools can be dismantled when the public learns how they work and platform access is revoked.

Why this matters now

Anthropic's contract with Samdesk mirrors Geofeedia's model—real-time monitoring of protest activity—but the client is a corporate security team, not police. The difference is that Anthropic also holds the conversational data from its own chatbot.

Sources

(6)