cd /news/ai-policy/anthropic-builds-threat-intelligence… · home topics ai-policy article
[ARTICLE · art-125257] src=runtimewire.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Anthropic builds threat intelligence operation that treats activism as a security risk

Anthropic, led by CEO Dario Amodei, has built a corporate intelligence operation that monitors protests near executives and facilities, investigates potential threats, and shares information with law enforcement, according to a report by The American Prospect. The operation includes using Samdesk, a real-time risk detection platform, which alerted Anthropic about a protest 60 minutes before it started, allowing the company to reroute an executive. Anthropic is also hiring investigators for roles paying $180,000 to $230,000, reflecting its expansion into proactive threat management.

by read5 min views7 publishedSep 10, 2026
Anthropic builds threat intelligence operation that treats activism as a security risk
Image: Runtimewire (auto-discovered)

A vendor tracked a protest around an executive, while new roles call for OSINT investigations and ties to police.

        By [Ryan Merket](/author/ryan-merket)
        · Published 

Primary source: [The American Prospect](https://prospect.org/2026/09/09/anthropic-artificial-intelligence-surveillance-system-monitor-activists/)

Why it matters #

Frontier AI labs are becoming private intelligence operators as well as platform companies. Anthropic now sets its own thresholds for tracking protests, profiling potential threats, and referring users to police.

Anthropic, led by cofounder and CEO Dario Amodei, has built a corporate intelligence operation that monitors protests near executives and facilities, investigates people deemed potential threats, and exchanges information with law enforcement. A report published Wednesday by The American Prospect ties together Anthropic's job listings, statements to other publications, and an interview in which security officials described using an AI-assisted risk platform to track a protest.

The operation complicates the line Amodei drew in February 2026, when Anthropic refused to remove restrictions against using Claude for mass domestic surveillance and fully autonomous weapons. Amodei argued at the time that AI could combine location, browsing, and association records into comprehensive personal profiles at unprecedented scale.

Anthropic's internal program differs from the government surveillance Amodei opposed. It is a corporate security operation intended to protect executives, employees, and property rather than population-scale monitoring by the state. Its expanding remit still gives Anthropic substantial discretion to decide when protest activity, online speech, or a user's conversation with Claude becomes a threat requiring investigation or police attention.

A protest alert reached Anthropic in 60 minutes

The clearest account of Anthropic monitoring activists came from Keon Ellison, a manager in its Global Security Operations Center, during a 2025 discussion with Anthropic security manager Zachary Melvin and James Neufeld, CEO of security vendor Samdesk.

Ellison said Samdesk warned Anthropic that organizers had moved a planned protest to an earlier time. The alert arrived about 60 minutes before the revised start, allowing Anthropic to reroute an executive through a hotel's service entrance rather than have the executive encounter the demonstration.

Samdesk describes its product as a real-time risk detection and situational-awareness platform using public open-source intelligence, AI-based detection, and human verification. Its alerts can be mapped against facilities, routes, assets, and travelers.

That example establishes that Anthropic uses an outside platform to monitor public information about protests near its executives. It does not show protest organizers being individually identified or investigated. The disclosed system also centers on Samdesk, while a separate Anthropic process monitors activity inside Claude for policy violations and potential threats.

Ellison described Anthropic's objective in broader terms, saying its security operation should move toward "proactive and predictive and preventative threat engagement and management." That ambition has since appeared in Anthropic's hiring.

Anthropic is hiring investigators

A recent Enterprise Intelligence Specialist listing says Anthropic's Global Safety, Intelligence, and Security division operates separate enterprise and executive-focused intelligence functions. The $180,000 to $230,000 role would investigate global threats including terrorism, crime, geopolitical instability, nation-state activity, and activism.

The investigator would conduct behavior-based threat assessments and deep open-source research into specific people, events, and organizations. The listing also calls for daily work with intelligence vendors, law enforcement, industry peers, and government partners.

Another Anthropic listing for a Protective Intelligence Analyst describes monitoring social media, open-source channels, and deep and dark web forums. The analyst would investigate "persons of concern," assess signs of escalation toward violence, and provide real-time intelligence for executive travel and events.

Those listings describe established teams rather than a speculative program. They also place activism inside the same threat-intelligence workflow as violent crime, terrorism, and hostile state activity, even though the listings do not define what forms of activism warrant investigation.

A Claude conversation became a police report

Anthropic's security apparatus also receives signals from its own product. On August 14th, a Claude user allegedly wrote that he had purchased an AR-15 and had Amodei "in his sights," according to a police report obtained by The San Francisco Standard.

Anthropic notified San Francisco police the following Tuesday. The responding officer wrote that an Anthropic employee was not immediately concerned about safety and wanted the incident documented. The employee declined to show police the underlying messages, citing Anthropic policy.

The user told the Standard that he had been joking. He was not identified because he had not been arrested or charged. Anthropic banned the account and told the Standard that the referral was its "safeguards process working as intended."

Anthropic's policy for government data requests says customer information generally requires valid legal process, with an exception for emergencies involving imminent physical harm or death. The police report's account, including the employee's statement that there was no immediate safety concern, leaves Anthropic's threshold for a proactive referral unclear.

The monitoring also reaches beyond chatbot conversations. Anthropic told The Wall Street Journal in July that its security staff tracks concerning behavior over time through a "person-of-interest process" designed to detect escalation. The Prospect, citing the Journal, reported that Anthropic routinely sends threat reports to police departments around the country.

AI executives face documented threats, including an April incident in Anthropic's lobby and an attack involving a Molotov cocktail at OpenAI CEO Sam Altman's home. Corporate protection is an expected response to credible danger. Anthropic's system goes further by combining product monitoring, behavioral profiles, open-source protest tracking, specialist investigators, and police relationships under one intelligence function.

That structure puts Anthropic in the position Amodei has warned governments against occupying: using data and automated systems to assemble scattered signals into judgments about individual risk. The scale and legal authority are different. The central question is who Anthropic monitors, what evidence triggers escalation, and how a person can challenge a threat designation made inside a private intelligence process.

── more in #ai-policy 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/anthropic-builds-thr…] indexed:0 read:5min 2026-09-10 ·