Security1 publisher2 min readPublished
Anthropic refers suspects to police before a crime, according to the American Prospect
Working from job postings and a podcast with two of Anthropic's own security managers, the American Prospect describes a monitoring program aimed at activists who oppose fast AI development, with police referrals at the far end of it.
The Watch · Security desk

What happened
- The American Prospect says job postings and interviews with senior Anthropic security officials describe a monitoring system built to keep tabs on activists who oppose the rapid development of AI.
- The program tries to predict incidents before they happen, and in some cases that means reporting suspects to police before a crime occurs.
- Anthropic contracts the risk-detection firm Samdesk, whose CEO James Neufeld appeared on a podcast last year with two of Anthropic's security managers to discuss threat monitoring.
- The San Francisco Standard reported in August that Anthropic told San Francisco police about a man who wrote to Claude that he had bought an AR-15 and had Dario Amodei in his sights.
- An Anthropic posting from August seeks an enterprise intelligence specialist for its Global Safety, Intelligence, and Security team at $180,000 to $230,000.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Claude users are inputs to an executive-protection process, and a referral can reach a police department that never sees the conversation behind it.
- precedent Physical security teams at other labs now have a working template for domestic intelligence work: a vendor protest feed, a standing file on individuals, and a police contact list.
- contradiction The Prospect describes pre-crime policing of critics while Anthropic's only on-record wording is escalation detection, and neither account carries a count of referrals or of tracked individuals.
- decision Every alert off a third-party protest feed forces a choice between a route change and a police report, and Anthropic's program makes both.
Tracking comes first, then the police call. Anthropic told The Wall Street Journal in July, "We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early" [11]. The Journal reported that "several individuals involved in incidents reported to police were already being tracked by Anthropic security" [12]. Those reports go to police departments across the country [10].
On a podcast last year, Anthropic Global Security Operations Center manager Keon Ellison described what the vendor feed buys [5]. "Last year we had an executive travel into a major city when we received some intelligence through Samdesk about a planned protest," Ellison said [6]. Permitting issues moved the protest earlier than scheduled [7]. "Samdesk gave us about 60 minutes of advanced notice that the protest organizers had moved the timeline," he said [8]. Ellison said the team used the data to plan an alternate route and funnel the executive to a hotel service entrance [9].
An Anthropic security program manager set out the direction on the same podcast. "The goal would be transforming operations from reactive information to gathering proactive and predictive and preventative threat engagement and management," he said, adding that this is "the kind of operational maturity that makes sense for protecting high-value targets in any industry" [16][17].
The San Francisco case is the one with an outside record. Anthropic reported the user, then refused to show police the actual messages, citing internal policy, according to the Standard [15]. The man told the newspaper he was "just fucking around" [14]. The Prospect's account does not say whether police charged him, and no count of referrals or of people on the person-of-interest list is public [4].
The posted band puts the intelligence hire at $205,000 in base pay at the midpoint [1], and the brief is to "investigate specific threats, actors, and events, produce finished assessments, and help keep Anthropic's employees ahead of a rapidly evolving threat landscape and in a defensible position" [18].
At the start of the year Anthropic and the Department of Defense fought publicly over Anthropic's refusal to let the military use its tools for mass domestic surveillance and autonomous weapons [20]. The company is now hiring for national security sales positions to restart military contracts [21]. It did not respond to the Prospect's request for comment [4].
What to watch
- Whether any police department confirms how many Anthropic referrals it has received and how many produced charges.
- Whether Anthropic publishes the internal policy it cited when it kept a user's messages from investigators.
- Whether the GSIS enterprise intelligence role is filled, and whether the posting's scope language changes.