News
Anthropic Builds Predictive Surveillance System Targeting Anti-AI Activists

An investigation by The American Prospect reveals that Anthropic monitors activists opposed to AI development, uses risk-analysis firm Samdesk, and reports suspects to police before any incident occurs.
Anthropic, the company that publicly presents itself as the responsible alternative to OpenAI, is building an extensive surveillance system targeting activists critical of AI development. An investigation by The American Prospect describes how the company tracks protest participants, anticipates their actions in advance, and reports people it deems threats to police before any crime has taken place.
The investigation is based on a podcast recording in which Keon Ellison, manager of Anthropic's Global Security Operations Center, described how the collaboration with Samdesk works. According to his account, the company received intelligence about a planned protest while one of its executives was traveling to a major city, and Samdesk analysts informed the security team about a change in the demonstration's start time an hour before it actually happened.
How the system works
With that information, Anthropic was able to plan an alternate travel route and direct the executive to the hotel's service entrance, bypassing the gathering. Also on the call were Zach Melvin, the company's security operations manager, and James Neufeld, CEO of Samdesk.
We're transforming operations from reactive intelligence gathering into proactive, predictive and preventive threat management - Zach Melvin, Security Operations Manager, Anthropic
Reporters at The American Prospect determined that this mechanism is part of a broader strategy the company itself calls a "person-of-interest process." In a statement given in July to The Wall Street Journal, Anthropic openly acknowledged that it tracks concerning behavior over time in order to catch escalation patterns before an incident occurs.
The AR-15 case
The most widely reported case in recent weeks involves a San Francisco resident who told the Claude chatbot in a conversation that he had bought an AR-15 rifle and had Dario Amodei "in his sights," and that he planned to kill all of the company's employees. Anthropic reported the case to the local police, telling officers that the user "intended to kill everyone at Anthropic" and had bought the weapon with the intent to kill employees.
According to the reporters' findings, however, the company did not give police the full transcript of the conversation, citing internal privacy policy, which prevented officers from independently assessing the severity of the threat based on the original text. The user himself, whose identity was not disclosed since he was not charged, told a local outlet that his words had been a joke.
A contradiction with the company's values
Reporters point to a contradiction between this surveillance practice and Anthropic's public image as an AI lab committed to human rights and social safety. The tension is deepened by the fact that earlier this year the company clashed with the Pentagon, refusing to let its tools be used for mass domestic surveillance by the military, yet it is now building its own apparatus to monitor citizens who criticize its operations.
A job posting for a corporate intelligence specialist published by Anthropic explicitly describes the role's responsibilities: identifying, assessing, tracking and investigating global threats, including geopolitical instability, terrorism, crime, activism and state actions targeting the AI sector. The position pays between $180,000 and $230,000 per year, and duties include in-depth research and open-source intelligence (OSINT) gathering.
Industry context
The investigation comes amid tension over working conditions in the AI security industry itself. Security guards employed by OpenAI and Anthropic recently authorized a strike in a dispute over pay rates of $22 an hour. Anthropic declined to comment on The American Prospect's findings.
For Polish companies and institutions tracking the development of AI regulation, the case shows that the tension between corporate security and the right to protest and to private communication with chatbots is becoming a real legal problem, not just a theoretical scenario from AI Act debates. The practice of reporting users to police based on the content of conversations with a language model, without providing full evidence, raises questions about evidentiary standards and data protection that will sooner or later come under European regulation as well.

