WRITTEN IN PLAIN AMERICAN ENGLISH.
About
CLAY TRIBUNE.
ShopCartAccount
Advertisement

Anthropic Is Preparing a Pre-Crime System to Watch Activists Who Oppose Its Own AI

Anthropic is building predictive surveillance to track activists and report them to police before any crime occurs, per new reporting.

By mitch·6 min read
A dimly lit surveillance control room with analysts monitoring screens showing city maps and tracked locations.

Anthropic, the AI company behind the Claude chatbot, is building a surveillance system designed to monitor activists who oppose rapid AI development and attempt to predict incidents before they happen. Job postings and interviews with senior security officials show the frontier lab is taking a “pre-crime” approach; in some cases, that means reporting suspects to police before a crime occurs.

The firm monitors activists who follow its executives and demonstrations that occur close to its physical holdings. The Prospect reached out to Anthropic for a response, which was not provided.

This surveillance posture sits awkwardly with Anthropic’s public image as the responsible alternative to OpenAI. At the start of the year, the Department of Defense and Anthropic clashed publicly over the company’s refusal to let the military use its tools for mass domestic surveillance and autonomous weapons. That tension has eased, according to the reporting, as Anthropic hires for “national security sales” positions and looks to restart military contracts.

Advertisement

Samdesk and the 60-Minute Warning

Last year, a major part of Anthropic’s surveillance system came to light during a podcast interview. Anthropic Global Security Operations Center Manager Keon Ellison and Security Operations Manager Zach Melvin were interviewed by James Neufeld, CEO of Samdesk, a risk-detection firm that Anthropic works with.

Ellison described a close call involving an executive. “Last year we had an executive travel into a major city when we received some intelligence through Samdesk about a planned protest,” he said. The protest had been moved up due to permitting issues.

“Samdesk gave us about 60 minutes of advanced notice that the protest organizers had moved the timeline,” Ellison explained. “That extra hour was critical. Without it our executives would have departed their meetings, they would have ran right into the heart of the disruption.”

Anthropic used that data to reroute the executive to a service entrance at the hotel. “What could have been a high-stress situation,” Ellison said, “was really mitigated through early detection through Samdesk and giving us that information.”

Police Reports and the AR-15 Case

The company has started sending regular reports to police departments around the nation. Anthropic told The Wall Street Journal in July, “We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early.”

The Journal states that “several individuals involved in incidents reported to police were already being tracked by Anthropic security.”

The San Francisco Standard covered a particular incident last month. Anthropic reported a man to San Francisco police after he told Claude that he had purchased an AR-15 semiautomatic rifle and had CEO Dario Amodei “in his sights.”. When the Standard reached out to the man, he said he was “just fucking around.”.

The Standard’s report included a significant detail: Anthropic declined to share the actual messages with police, citing its own internal policy. Put another way, Anthropic flagged a user for in-platform speech but would not furnish the very evidence of wrongdoing requested by law enforcement.

Predictive Policing as an Explicit Goal

According to the Prospect’s review, the podcast makes a pre-crime approach an explicit goal. The security program manager at Anthropic said, “The goal would be transforming operations from reactive information to gathering proactive and predictive and preventative threat engagement and management.”, which supports that assessment.

He said, “That’s the kind of operational maturity that makes sense for protecting high-value targets in any industry.”

The company is constructing a system that works outside due process, and it seems to be doing so with intent.

Inside the GSIS Job Posting

Beyond the C-suite, Anthropic’s predictive security apparatus reaches into its Global Safety, Intelligence, and Security (GSIS) team. A job posting from last month is looking for an enterprise intelligence specialist who “will investigate specific threats, actors, and events, produce finished assessments, and help keep Anthropic’s employees ahead of a rapidly evolving threat landscape and in a defensible position.”.

This position carries a wage range of $180,000 to $230,000, and among its responsibilities is the skill to “identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism, nation-state targeting of the AI sector, and emerging security trends, including deep-dive research and OSINT collection on specific threats, actors, and events.”.

Terrorism, crime, and activism are all grouped together as threats worth tracking.

Critical Infrastructure and the National Security Turn

Recent moves to classify AI systems and their supporting infrastructure, including data centers and power supply, as critical infrastructure now mirror Anthropic’s own broadening of intelligence-gathering on a national and global scale. That classification would place AI alongside water, electricity, and broadband as essential services.

The group Americans for Responsible Innovation (ARI) has pushed the Trump administration to make the shift. According to ARI’s account, AI is “so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”, a claim that underscores its potential impact.

Placing frontier labs under the shield of national security would grant Anthropic, OpenAI, and Google greater access to intelligence products from federal law enforcement and intelligence agencies. It would also encourage these companies to influence how federal agencies regard threats to their bottom line, now reframed as “critical infrastructure.”.

What the Surveillance Net Catches

What this means in practice is that any public pushback against AI, whether it takes the form of protest, organizing, or open criticism, now sits within Anthropic’s own assessment of risks.

Rather than simply responding to protests, the company is attempting to forecast them and to inform authorities about people before they take action. The Samdesk system offers early notice. The GSIS team monitors “actors” on a worldwide scale. The person-of-interest approach watches individuals across time.

The stated reason behind Anthropic’s surveillance net is protecting executives and assets. Yet the system also ensnares everyday users, including the San Francisco man who told Claude about purchasing an AR-15. He was reported to police for remarks made inside a chatbot conversation, and Anthropic subsequently refused to hand over the evidence to law enforcement.

It is an odd stance for an enterprise whose identity was shaped by a commitment to safety and accountability.

The Unanswered Questions

OpenAI and Google are not the only parties involved. Anthropic stands to gain from a critical infrastructure designation as well.

The reporting indicates that the conflict within the Defense Department has subsided. Anthropic’s recent hiring for national security sales signals a return to military contracting. The same company that declined to construct mass domestic surveillance systems for the military is now developing its own predictive surveillance targeting domestic opponents.

The parts connect. Samdesk delivers real-time protest intelligence. The GSIS team follows activists as threats. A person-of-interest system creates records on individuals. Police reports come from those records. The entire arrangement is defended as a way to protect “high-value targets.”.

Operational maturity is how the company describes it. Pre-crime policing is what some critics would label it instead.

The security program manager at Anthropic framed the objective as “proactive and predictive and preventative threat engagement.”. The terminology — predictive, preventative — reads like a strategy of policing people for what they might do rather than what they have actually done.

Anthropic has yet to reply to the Prospect’s request for comment. The reporting leaves several questions unanswered, and this article poses them directly, taken from the reporting itself.

  1. What happens to the people in its person-of-interest files?
  2. How many have been reported to police?
  3. What standard of evidence triggers a report?
  4. What happens when the predictive system gets it wrong?

The answers remain unknown for now, yet the surveillance system itself is a genuine reality.

Source: prospect.org

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.