Anthropic is building an internal intelligence operation that tracks people who oppose rapid AI development, according to an investigation published on 9 September by The American Prospect. The report draws on job postings and on recorded interviews with the company's security staff. Anthropic did not respond to the publication's request for comment.
The article describes a monitoring programme that reaches beyond ordinary corporate security. Anthropic contracts a risk-detection vendor, Samdesk, for real-time alerts, and one executive was rerouted around a protest after the vendor gave roughly an hour of notice that organisers had moved their schedule. On a podcast, a security manager at the company said the goal was to shift from reacting to threats towards proactive and predictive engagement.
The Prospect also points to a job listing for an enterprise intelligence specialist, paid between $180,000 and $230,000, whose duties include identifying, assessing and tracking global threats such as activism alongside crime, terrorism and nation-state activity. Anthropic has told The Wall Street Journal that it tracks concerning behaviour over time through a person-of-interest process, and it has reported several individuals to police.
One case drew attention in San Francisco. Anthropic reported a Claude user to police after he told the model that he had bought a rifle and had chief executive Dario Amodei in his sights. The man later told The San Francisco Standard that he was not serious, and the Standard reported that Anthropic declined to hand over the messages behind its report.
Not every reader takes the same view. Commentators on Hacker News noted that large technology firms routinely employ security teams, follow protest permits and pass credible threats to law enforcement. On that reading, the argument is less about whether Anthropic protects its staff and more about how far an AI lab should extend that work, and what it does with the political data it gathers along the way.
For founders the practical questions are familiar. Any company running models in production now holds sensitive user data and faces pressure to act on what it sees. Deciding when to escalate to police, what evidence to preserve and how to explain those choices in public is becoming part of product and legal planning rather than a purely internal security matter.