Anthropic, which has promoted itself as one of the most responsible companies in AI, is now facing allegations that it has been building a predictive surveillance system to watch people opposing the rapid expansion of AI, and in some cases has contacted police before an incident took place.
According to an investigation by The American Prospect reporter Daniel Boguslaw, the company has been constructing an internal monitoring system focused on dissenters critical of fast-moving AI development. Anthropic had not responded to Prospect’s request for comment by press time.
A podcast account described a 60-minute warning
Part of the system’s operation had surfaced earlier in a podcast episode released last year. Anthropic Global Security Operations Center Manager Keon Ellison, Security Operations Manager Zach Melvin, and Samdesk Chief Executive Officer James Neufeld discussed threat monitoring and analysis, including surveillance of dissenters.
Ellison said that when a senior executive was scheduled to travel to a major city last year, the team used Samdesk to obtain intelligence about a planned protest. Because there was a problem with the permit process, the protest was moved earlier than expected. Ellison said Samdesk notified the company 60 minutes in advance that organizers had shifted the timetable.
He described that extra hour as critical. Without the alert, he said, the executive delegation could have walked straight into a chaotic scene after leaving a meeting. The team used the information to arrange an alternate route and had the executive leave through a hotel staff entrance instead. Ellison said what could have become a highly tense situation was defused through Samdesk’s early detection and intelligence support.
The report said this was only one part of the work handled by Anthropic’s Global Safety, Security, Intelligence and Safety team, or GSIS.
GSIS job listing offered $180,000 to $230,000
Last month, the GSIS team posted a corporate intelligence analyst role with annual pay ranging from $180,000 to $230,000. The job description said the analyst would investigate specific threats, actors, and events, then produce full assessment reports to help Anthropic employees stay ahead of a rapidly changing threat environment while maintaining a defensible position.
The posting also said the analyst would identify, assess, track, and investigate global threats including geopolitical unrest, terrorism, crime, social movement advocacy, and targeted actions by foreign states against the AI industry. It added that the role would require deep research into specific threats, actors, and events, along with OSINT, or open-source intelligence, collection.
The article summarized that framework as placing social movement activists and terrorists into the same intelligence-gathering process for evaluation.
Reports to police and internal watchlists
The report also said Anthropic has begun routinely reporting threat cases to police departments across the United States. In July this year, the company told The Wall Street Journal that it uses a "persons of concern" process to track certain individuals over time in order to detect signs of escalation early.
The Wall Street Journal also reported that some of the cases referred to police were already on Anthropic’s internal tracking list.
Last month, The San Francisco Standard reported that Anthropic contacted San Francisco police after a user mentioned to Claude that he had bought an AR-15 semi-automatic rifle and said Chief Executive Officer Dario Amodei "was already in his crosshairs."
When reached by The San Francisco Standard, that user said he was "just talking nonsense."
Fast police reporting, limited evidence sharing
The report said Anthropic moved quickly in notifying law enforcement but was much more restrained when it came to sharing evidence. One detail cited from The San Francisco Standard was that Anthropic refused, citing internal policy, to show police the actual message content sent by the user.
In other words, according to the report, Anthropic reported a user’s statements on its platform while declining to provide the original material that could substantiate an actual offense.
Shift from reactive to proactive prevention
This preemptive enforcement logic was also reflected in remarks from an Anthropic security program manager on the podcast. He said the team was trying to move its operating model away from passively receiving information and toward active, predictive, and preventive threat response. In his view, that level of maturity was what industries needed to protect high-value targets.
Tension with Anthropic’s earlier stance on military use
The timing of the company’s expanding security posture was described as notable. Earlier this year, the U.S. Department of Defense and Anthropic clashed after the company refused to let the military use its tools for large-scale domestic surveillance and autonomous weapons, a dispute that drew broad attention.
Now, Anthropic has posted a role for national security sales and is seeking to restart military contracts, while also stepping up threat monitoring of domestic dissenters. The report said the two developments align with its renewed push into the national security market.

