Pull to refresh
Logo
Anthropic builds predictive surveillance operation to monitor activists

Anthropic builds predictive surveillance operation to monitor activists

New Capabilities

AI lab tracks protests in real time and reports chatbot users to police over in-app speech

2 days ago: Follow-up reports expand on surveillance program

Overview

Updated 2 days ago

Anthropic runs a security operation that tracks protests near its executives and keeps files on people it calls 'persons of interest.' It markets itself as the safety-first alternative to OpenAI, yet refers chatbot users to police over what they type to Claude.

The American Prospect's September 9 investigation showed Anthropic pays analysts up to $230,000 to investigate 'activism' as a threat category, alongside terrorism and crime. Runtime Wire's follow-up found a second posting for a Protective Intelligence Analyst to monitor social media and dark-web forums. In one documented case, Anthropic referred a Claude user to police over an alleged threat to CEO Dario Amodei, then withheld the chat logs.

Why it matters

A private AI company now decides which chatbot conversations become police referrals, with no court review and no public oversight.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$230,000
Top salary for Anthropic intelligence analyst role
The enterprise intelligence specialist posting lists a range of $180,000 to $230,000 to investigate threats including 'activism.'
60 min
Advance notice from Samdesk of a moved protest
Anthropic's security operations center manager said the alert let the company reroute an executive away from a demonstration.
24/7
Global Security Operations Center coverage
Anthropic runs a round-the-clock security center that monitors protests and threats near executives and facilities.
1
Documented police referral from chatbot speech
Anthropic reported a Claude user to San Francisco police over an alleged threat to its CEO, then withheld the chat logs.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

2025 September 2026

6 events Latest: 2 days ago
Tap a bar to jump to that date
  1. Follow-up reports expand on surveillance program

    Latest Reaction

    Runtime Wire details a second job posting for a Protective Intelligence Analyst who would monitor social media and dark-web forums. Activist outlets describe the operation as a 'pre-crime' unit.

  2. Job posting seeks intelligence analysts

    Recruiting

    Anthropic posts $180K-$230K role to investigate threats including activism.

  3. WSJ reports person-of-interest tracking

    Disclosure

    Anthropic tells the Journal it tracks concerning behavior over time to catch escalation early.

  4. Anthropic security chiefs describe protest monitoring

    Disclosure

    In a podcast, security managers describe using Samdesk for real-time protest tracking and executive rerouting.

Scenarios

1

Congress opens inquiry into AI-lab surveillance

Possible Resolves by Q2 2027

Discussed by: The American Prospect; civil liberties advocates following the report

The report reaches the House Committee on Oversight and Government Reform, prompting a formal inquiry into whether Anthropic's police referrals based on chatbot speech raise First Amendment concerns, and whether its lobbying to have AI designated 'critical infrastructure' shapes its security posture.

2

AR-15 case ends without charges; program continues

Likely Resolves by Q1 2027

Discussed by: The San Francisco Standard's coverage; the man told the paper he was 'just f**king around'

The San Francisco District Attorney declines to charge the individual Anthropic referred. Anthropic continues its person-of-interest tracking and police referral practices, and public attention fades as the company advances its national security contracts.

3

Anthropic tightens police-referral policy after backlash

Possible Resolves by End of 2027

Discussed by: Tech-policy critics cited by the American Prospect and ShofTech

Under public pressure, Anthropic revises its policy to require a court order or a specific, imminent threat of physical harm before reporting chatbot conversations to law enforcement, and stops classifying 'activism' as a tracked threat category.

4

Rival AI labs adopt similar protest monitoring

Possible Resolves by Q3 2027

Discussed by: American Prospect's framing; gadget review and ShofTech coverage

OpenAI or Google DeepMind confirm their own security teams track protest activity near executives and refer threats from chatbot users to police, normalizing the practice across the industry.

5

Civil liberties group challenges police referrals

Possible Resolves by End of 2026

Discussed by: Runtime Wire's analysis; The American Prospect's investigation

The police report shows an Anthropic employee saw no immediate safety concern, yet the company made a proactive referral. A civil liberties group could challenge the practice as a First Amendment problem, arguing it chills what users feel safe typing to Claude.

Historical Context

3 moments from history that rhyme with this story — and how they unfolded.

1956–1971

COINTELPRO (1956–1971)

The FBI ran a covert counterintelligence program targeting domestic political groups—civil rights organizers, anti-war activists, and others. Agents used informants, wiretaps, and disruption tactics against citizens with no criminal charges.

Then

Exposed in 1971 when activists burglarized an FBI office in Media, Pennsylvania, and leaked documents to the press. The Church Committee investigations followed, leading to restrictions on domestic surveillance.

Now

Generated lasting legal limits on government surveillance of political activity, including the Foreign Intelligence Surveillance Act of 1978.

Why this matters now

Anthropic's job posting lists 'activism' as a threat category alongside terrorism and crime. The parallel to state surveillance of political dissent is direct, except this time a private corporation with national security ambitions runs the program.

December 2014 – June 2015

Elonis v. United States (2015)

Anthony Elonis posted rap lyrics on Facebook describing killing his wife and an FBI agent. Federal prosecutors charged him under a law barring interstate threats, and a jury convicted him.

Then

The Supreme Court reversed the conviction 8-1, ruling that prosecutors must prove the speaker intended the statement as a threat.

Now

Established that online speech can't be punished as a threat without proof of intent, giving First Amendment protection to hyperbolic or joking statements.

Why this matters now

Anthropic reported a user to police for telling Claude he had an AR-15 and CEO Dario Amodei 'in his sights.' The user said he was 'just f**king around'—exactly the kind of speech Elonis protects unless intent is shown.

2014–2016

Geofeedia and protest surveillance (2014–2016)

Chicago's Geofeedia sold law enforcement a social media monitoring tool that tracked protesters in real time during the Ferguson uprising and Black Lives Matter demonstrations. The ACLU of California obtained procurement records tying the tool to hundreds of police departments.

Then

After the ACLU exposed the contracts in October 2016, Facebook, Twitter, and Instagram cut off Geofeedia's access to their data streams. The company's core product collapsed.

Now

Showed that private protest-surveillance tools can be dismantled when the public learns how they work and platform access is revoked.

Why this matters now

Anthropic's contract with Samdesk mirrors Geofeedia's model—real-time monitoring of protest activity—but the client is a corporate security team, not police. The difference is that Anthropic also holds the conversational data from its own chatbot.

Sources

(8)