Anthropic's Alleged 'Pre-Crime' Surveillance of AI Activists
TECH

Anthropic's Alleged 'Pre-Crime' Surveillance of AI Activists

22+
Signals

Strategic Overview

  • 01.
    On September 9, 2026, The American Prospect reported that Anthropic is building a predictive, 'pre-crime' style surveillance system aimed at tracking activists who oppose rapid AI development, citing a job posting for an 'Enterprise Intelligence Specialist' on its Global Safety, Intelligence, and Security team paying $180,000-$230,000 to 'identify, assess, track, and investigate' threats including 'activism.'
  • 02.
    Anthropic's Security Operations Manager Zach Melvin said in a podcast reviewed by the Prospect that the goal is 'transforming operations from reactive information gathering to proactive and predictive and preventative threat engagement and management,' and the company maintains a 'person-of-interest process' to track individuals' behavior over time for early escalation detection.
  • 03.
    Anthropic also contracts third-party risk-detection firm Samdesk to monitor protests near its offices and executives; Global Security Operations Center Manager Keon Ellison said Samdesk gave the company about 60 minutes of advance notice when protest organizers moved up a demonstration's timeline, letting executives avoid it.
  • 04.
    In a separate incident reported around the same time, Anthropic reported a San Francisco man to police after he told its Claude chatbot he had bought an AR-15 and had CEO Dario Amodei 'in his sights,' though it withheld his actual chat messages from police citing company policy; Anthropic did not respond to the Prospect's request for comment on the broader investigation.

Deep Analysis

From Reactive Security to Predictive Threat Scoring

Anthropic's Global Safety, Intelligence, and Security (GSIS) team posted a job listing for an 'Enterprise Intelligence Specialist' paying $180,000-$230,000, tasked to 'identify, assess, track, and investigate' threats that explicitly include 'activism' alongside terrorism, crime, and nation-state targeting of the AI sector [1]. Security Operations Manager Zach Melvin described the underlying philosophy in a podcast reviewed by the Prospect: the goal is 'transforming operations from reactive information gathering to proactive and predictive and preventative threat engagement and management' [2]. Anthropic also runs a 'person-of-interest process,' explicitly built to track concerning behavior over time so the company can catch escalation patterns early [1].

That combination - a paid analyst role, a named predictive doctrine, and an ongoing individual-tracking process - is what separates this from routine corporate security. It is also unusually direct evidence of intent: companies rarely spell out a predictive-security doctrine in a public hiring document, which makes the job posting more revealing than a leaked internal memo would be - it is a public commitment to build the capability, not merely a reaction to being caught doing so. The taxonomy in that posting is itself a signal: grouping 'activism' with 'geopolitical instability, terrorism, crime, [and] nation-state targeting of the AI sector' [1]means a category of protected First Amendment activity is processed through the same identify-assess-track-investigate pipeline as violent and state-level threats. Anthropic also contracts third-party risk-detection firm Samdesk to flag protest activity near its executives and offices - a relationship close enough that Samdesk CEO James Neufeld appeared alongside Anthropic staff in the podcast reviewed by the Prospect [1]- and GSOC Manager Keon Ellison said Samdesk once gave the company roughly 60 minutes of advance notice that protest organizers had moved up their timeline, letting executives avoid walking into the disruption [2]. Whether or not 'pre-crime' is the precise label, the mechanics described are genuinely anticipatory: tracking people and movements before any specific act, not merely responding after one occurs.

The Legal Gray Zone Behind the Watchlist

Santa Clara University law professor Eric Goldman's central warning is about incentives, not intentions: 'As they become more hated, there's more pressure on them to over-disclose knowing that some of the people they identify for law enforcement shouldn't be targeted at all' [3]. That is a structural critique - the more public backlash a company like Anthropic absorbs, the stronger its incentive to hand names to police pre-emptively, even when the underlying signal is weak. It is also worth noting that most of the coverage amplifying the story is repackaging the Prospect's original reporting rather than independently confirming new facts [1][2].

The reaction beyond the original investigation was mostly amplification rather than additional reporting: same-day social posts and video reactions largely repeated the piece's core claims without confirming new facts, and even Reddit threads that generated substantial discussion clustered around interpreting the original story rather than adding to it. One thread of that discussion, in r/privacy, pointed to a 'Legal Compliance' clause in Anthropic's own Terms of Service that the commenters said permits reporting user activity to law enforcement - a framing worth noting as a talking point in that discussion, though it reflects user commentary rather than something confirmed in the underlying investigation. Separately, Prospect reporter Daniel Boguslaw used his own posts about the story to solicit further tips from frontier-lab employees via Signal, a sign the outlet may pursue additional reporting on this beat.

A Safety-Branded Company Built Its Own Surveillance Apparatus

Earlier in 2026, Anthropic publicly refused to let its AI tools be used for the Department of Defense's mass domestic surveillance or autonomous weapons programs, after which the DoD reportedly threatened to designate the company a 'supply chain risk'; Anthropic later sued the Trump administration over related retaliation [4]. The ACLU and Center for Democracy & Technology backed Anthropic in that fight, with the ACLU's Patrick Toomey arguing the company's AI-guardrails advocacy was 'protected by the First Amendment' [5].

That history sits uneasily next to the Prospect's reporting: the same company that drew a public line against government surveillance use of its models is separately described as building its own predictive tracking of the activists most critical of its rollout [1]. The reported AR-15 threat against CEO Dario Amodei complicates a purely critical reading, though - a chatbot user telling Claude he had the CEO 'in his sights' after buying a weapon is a concrete, individualized threat, and flagging that to police is a different act than continuously monitoring protest organizers as a category [2].

Executive Protection or Dragnet: The Contested Middle Ground

Not every reaction treated the story as proof of a dystopian system. A pointed Hacker News comment captured the skeptical framing directly: 'I bet if I typed into Claude asking about pharmaceutical lobbying, I would not be reported to anyone' [6]- the argument being that the concern isn't predictive security in the abstract, but that AI-safety activism specifically gets sorted alongside terrorism and nation-state threats. Others in that same discussion pushed back further, arguing large companies routinely run executive-protection programs like this and that dramatizing it as a novel 'pre-crime' system overstates what the evidence shows versus standard corporate security practice.

The clearest data point cuts across both readings rather than resolving them: SEIU-USWW president David Huerta, in reporting tied to a separate pay dispute over Anthropic's security contractors, asked 'Who can survive with $22 an hour in San Francisco?' [1]- a wage that sits alongside the $180,000-$230,000 salary range for the intelligence analyst role built to track activists. The two figures come from different disputes over different jobs, so they don't establish a single spending pattern, but their appearance in the same body of reporting about Anthropic's security operation is itself notable.

Historical Context

2026
Anthropic publicly refused to let its AI tools be used for mass domestic surveillance or autonomous weapons, after which the DoD reportedly threatened to designate the company a 'supply chain risk,' and Anthropic later sued the Trump administration over related retaliation.
2026
The two groups urged a court to stop the government from punishing Anthropic over its AI-guardrails advocacy, with the ACLU's Patrick Toomey calling that advocacy 'protected by the First Amendment.'
2026-07
Reported on Anthropic's threat-tracking practices, part of the timeline of events The American Prospect says led up to its September investigation.

Power Map

Key Players
Subject

Anthropic's Alleged 'Pre-Crime' Surveillance of AI Activists

AN

Anthropic

AI company accused of building the predictive surveillance/'pre-crime' system; controls the hiring practices, security contracts, and person-of-interest tracking at the center of the story, and has not publicly responded to the investigation.

TH

The American Prospect

Publication that authored and published the original investigative report underpinning nearly all subsequent coverage of the story.

KE

Keon Ellison

Anthropic's Global Security Operations Center Manager; publicly described using Samdesk's protest alerts to reroute executives away from demonstrations, illustrating how the monitoring is operationalized day to day.

ZA

Zach Melvin

Anthropic's Security Operations Manager; described in a podcast the shift from reactive to predictive threat management that critics have labeled 'pre-crime.'

SA

Samdesk

Third-party risk-detection firm contracted by Anthropic to track protest activity near its executives and offices, supplying the underlying alerting infrastructure the company relies on.

DA

Dario Amodei

Anthropic's CEO; named as the target of a reported AR-15 threat that the company cites as part of its security backdrop.

Fact Check

6 cited
  1. [1] Anthropic Is Building a Predictive Surveillance System to Monitor Activists
  2. [2] Anthropic Security Measures: Monitoring Protests, Chatbot Threats
  3. [3] Anthropic 'Pre-Crime' Surveillance
  4. [4] Anthropic Takes Trump Administration to Court
  5. [5] ACLU and CDT Urge Court to Stop Government From Punishing Anthropic for Important Advocacy on AI Guardrails
  6. [6] Anthropic Is Building a Predictive Surveillance System to Monitor Activists (Hacker News discussion)

Source Articles

Top 1

THE SIGNAL.

Analysts

Warns that reputational pressure on companies like Anthropic could push them to over-report individuals to law enforcement, including people who should not be targeted at all.

Eric Goldman
Law professor, Santa Clara University

Argues that needing an in-house real-time surveillance system to help executives avoid public contact reveals something telling about the company's relationship with its critics.

Brian Merchant
Tech journalist and author
The Crowd

Anthropic Is building a surveillance system to monitor activists using a "pre-crime" approach that tries to predict incidents before they happen. The extensive monitoring system that the AI company is building is aimed primarily at keeping tabs on activists who oppose the rapid development of artificial intelligence. More from @DRBoguslaw below:

@@MorePerfectUS6971

BREAKING: Anthropic is reportedly developing a "predictive" surveillance system to monitor anti-AI activists, potentially alerting police before a crime occurs, per reporting by the Prospect

@@unusual_whales6138

Anthropic Is building A Pre-Crime system to monitor activists and protesters. Full Story in replies.

@@DRBoguslaw2372

Anthropic Is Building a Predictive Surveillance System to Monitor Activists

@Unusual-State18273100
Broadcast
They Want You TRACKED Before The Protest! | You Need to Know About Anthropic's NEW 'Precrime' System

They Want You TRACKED Before The Protest! | You Need to Know About Anthropic's NEW 'Precrime' System

Anthropic Runs a 'Person-of-Interest' System to Track Activists

Anthropic Runs a 'Person-of-Interest' System to Track Activists

Anthropic's Alleged 'Pre-Crime' Surveillance of AI Activists — AI News | Agentic Brew