Anthropic is building an intelligence shop to track its critics

Share
Anthropic is building an intelligence shop to track its critics

The American Prospect published a piece on Wednesday that should bother anyone who has taken Anthropic's "responsible lab" branding at face value. Drawing on job postings, a podcast interview with the company's own security managers, and police records, it describes a frontier AI company assembling an in-house intelligence capability whose remit includes activism — and doing it while its CEO publishes essays about trust.

What the reporting actually shows

Daniel Boguslaw's story rests on three documents, and they are specific. The first is a job posting from last month for an enterprise intelligence specialist on Anthropic's Global Safety, Intelligence, and Security team — GSIS. The salary band is $180,000 to $230,000. The listed duties include tracking "geopolitical instability, terrorism, crime, activism, nation-state targeting of the AI sector, and emerging security trends," including "deep-dive research and OSINT collection on specific threats, actors, and events." Activism sits in that sentence between terrorism and nation-state targeting.

The second is a Samdesk podcast conversation with Anthropic's Global Security Operations Center manager Keon Ellison, who described routing an executive around a planned protest after the vendor gave the company "about 60 minutes of advanced notice" that organizers had moved their timeline. The third is a San Francisco police report from August 14, first reported by The Standard, in which Anthropic flagged a Claude user who said he had bought an AR-15 and had CEO Dario Amodei "in his sights." Officers were sent to Anthropic's Howard Street office; the employee who met them "refused to show me the messages due to Anthropic's company policy," according to the officer's report. Reached by phone, the man said he was "just fucking around." He has not been charged.

Add what Anthropic told the Journal in July: "We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early." The paper also reported that several people involved in incidents reported to police were already on Anthropic's tracking list.

The irony is structural, not cosmetic

The collision here is not that a company protects its executives. It is that Anthropic's public identity is built on refusing that kind of work. Earlier this year the company fought the Defense Department over exactly this: no Claude for mass domestic surveillance, no autonomous weapons. It lost a $200 million contract over the principle and then won in court, and we argued that ruling was a red line for the whole industry rather than a win for one company — the reasoning in The Anthropic–Pentagon ruling isn't a win for one lab. It's a red line for all of them. The company that would not let the Pentagon build a domestic surveillance apparatus is now building its own, with contractors, and pointing it at people whose objection is to AI itself.

The reporting also notes the timing: Anthropic is hiring for "national security sales" roles as it seeks to restart military contracts. A domestic threat-intelligence capability is not a contradiction of that pivot; it is the same organizational reflex applied inward.

The mechanism matters more than the headcount. Predictive threat assessment is a classification problem, and it is exactly the kind AI is good at — the same pattern-matching that makes Claude useful for triaging security logs makes it useful for scoring people. The Prospect quotes a security program manager describing the goal as moving "from reactive information to gathering proactive and predictive and preventative threat engagement." Nobody at Anthropic has said their own models power this. But a lab whose entire thesis is that models can find escalation patterns in text is not going to build a text-monitoring shop and leave the models out of it.

Who has standing to complain

The strongest defense is also the most uncomfortable one. AI executives are receiving credible threats. In April, a man was arrested after a Molotov cocktail was thrown at Sam Altman's home. Companies that receive specific threats of mass violence should call the police, and the SFPD report shows an employee who wanted the event documented rather than someone hauled in — closer to caution than to persecution.

The weak link is not the reporting. It is the withholding. Anthropic made an accusation to police and then declined to hand over the underlying messages. A person-of-interest process with no evidentiary disclosure obligation, no adversarial review, and no notification of the person being tracked is a system in which the error rate is invisible and the errors are borne by the tracked. One person in this story has already turned out to be, on the record, kidding.

That asymmetry compounds with a second one. Last week the security guards who patrol Anthropic's and OpenAI's campuses voted to authorize a strike; SEIU-USWW says roughly 14,000 members were offered a 25-cent raise over four years, with no raise at all in three of them. Anthropic's response was to tell its own staff to work from home. The company is spending on intelligence specialists at up to $230,000 a year while the people physically guarding its buildings are disputing whether they can survive on $22 an hour in San Francisco. This is the gap Amodei diagnosed himself last month when he called the backlash "fundamentally a crisis of trust" — as we covered in Amodei says AI backlash is 'fundamentally a crisis of trust'. You cannot hire your way out of a trust deficit with the same money that widened it.

What to watch

Three things will tell you whether this is a security function or a political one. First, whether the GSIS role's language changes — whether "activism" survives the next revision of that posting, and whether OSINT collection is scoped to named threats rather than to categories of dissent. Second, whether Anthropic publishes a disclosure standard for police referrals: how many it makes, on what threshold, and whether the subject is ever told. Third, the thing to watch most closely — whether a critical-infrastructure designation for AI arrives. Advocacy groups are actively pushing the administration for it, and if AI is formally classed alongside water and power, opposition to a data center or a lab stops being a zoning dispute and starts being a threat to national infrastructure. The coalition that has been fighting data centers across party lines would be reclassified by a single executive order.

Anthropic declined to comment to the Prospect. That is the tell. This is the company that publishes its risk frameworks, its scenario models, and its disagreements with itself — the one that told investors and regulators that transparency is the product. On the question of who it is watching and on what evidence, it has chosen silence, and that choice will be harder to explain than any of the ones it has written down.

If a lab refers users to police over in-platform speech, should it be required to disclose those referrals — and to hand over the evidence? Tell us in the comments.

Sources: The American Prospect — Anthropic Is Building a Predictive Surveillance System to Monitor Activists · The San Francisco Standard — Anthropic called SFPD over threat against CEO · KQED — Workers Guarding San Francisco's Wealthiest Companies Vote to Authorize a Strike · Business Insider — Anthropic tells SF staff to work from home · The American Prospect — Anthropic (Re-)Enlists for War