Anthropic runs a threat-intelligence operation aimed at the activists who protest against it, according to American Prospect, which first described the system. The publication spoke with senior members of the company's security staff and worked through Anthropic's own published job listings to map how the network operates. Beyond monitoring demonstrations outside its offices, the lab uses an approach the outlet compares to predicting crimes before they happen: looking for early indicators of possible civil unrest.
The example the company offered to illustrate it came from Kion Ellison and Zach Melvin, who run Anthropic's security operations, together with James Neufeld, chief executive of the threat detection firm Samdesk. Last year an Anthropic executive traveled to a major city while Samdesk was feeding the company information about a planned protest. Confusion over police permits then moved the demonstration an hour earlier, and Samdesk passed on the change roughly 60 minutes before it began. That was enough time, Ellison said, to keep executives from walking out of their meetings directly into the middle of the protest. A situation that could have produced a tense confrontation was defused by early detection and by routing the information to the security team.
Note what the example actually shows. The threat being managed is an executive's calendar colliding with a permitted street protest, and the outcome is that nobody had an uncomfortable encounter on a sidewalk. That is a real service, and it is also a long way from the language used to describe the system. An Anthropic security manager framed the work as a shift from reactive information gathering to proactive, predictive and preventive threat management, and said this level of operational organization is what it takes to protect high-value targets in any industry. Those are the words of a corporate security program built for kidnapping and armed attack, applied here to political opposition.
The second element is harder to file under executive protection. Anthropic has also reported users' conversations with Claude to police. In August, San Francisco Standard reported that the company passed the San Francisco police information about a man who told Claude he was holding a rifle and that chief executive Dario Amodei was "in his sights." When Bay Area police followed up, Anthropic declined to hand over the chat log. American Prospect's characterization is blunt: the company effectively reported the man without producing concrete evidence that he had broken any law.
That combination is the part worth sitting with. A company can plausibly argue that a specific threat against a named executive justifies calling the police. It is much harder to argue for reporting a user and then refusing to supply the record that would let anyone else evaluate the report. The chat log is the only artifact that distinguishes a credible threat from a bad joke, and it stayed inside the company. Anthropic kept the discretion to decide who gets referred to law enforcement and the discretion to decide what evidence anyone sees afterward.
There is also a sharper irony in who is doing this. Anthropic has built its public identity on the argument that AI systems are dangerous enough to require external constraint, and the field's running debate is about strengthening guardrails on large language models, not about what the model operator does with what users type into them. A surveillance apparatus that treats conversations as an intelligence feed and protest organizers as leading indicators is the same capability, pointed outward, run by the company that says it worries most about concentrated power over these systems.
None of the activity described is illegal. Firms hire threat intelligence vendors, and companies report specific threats. What is new is the scale and the target: a frontier lab assembling a permanent predictive operation whose subject is the movement that opposes it, staffed through public job postings, with no external body checking which conversations get escalated and which do not. Anthropic asks governments to regulate AI developers because self-restraint is not enough. It has just demonstrated what self-restraint looks like when it is the one holding the data.