The self-styled AI safety company is watching its critics.
Anthropic warns, loudly, that AI could end the world. It is also, per new reporting, building a predictive-security operation that lists “activism” among the threats it tracks — and reportedly flags people to police before anything happens.
What this page is about
On September 9, 2026, The American Prospect's Daniel Boguslaw reported that Anthropic — the AI lab that has built its brand on warning about the dangers of artificial intelligence — is assembling a predictive-security operation to monitor threats, and that the list of threats it names includes “activism.” The reporting is built on Anthropic's own public job postings and interviews with its security officials.
The tension is obvious, and it's why the story traveled: a company that says the fast development of AI could be catastrophic is reportedly building a system to keep tabs on the people protesting the fast development of AI — and, per the report, doing it on a “predictive” basis that in at least one case meant flagging a person to police before any crime. This page grades what's documented, carries the ordinary-corporate-security explanation, and is careful not to convict on a headline.
Books that go deeper on this story. Links are Amazon affiliate searches — buying through them supports the work at no cost to you.
The same investigation, restaged one beat at a time. Step through it here, or present it fullscreen.
The self-styled AI safety company is watching its critics.
Anthropic warns AI could end the world — and is also, per new reporting, building a predictive-security operation that lists 'activism' among the threats it tracks, and reportedly flags people to police before anything happens.
The team, the posting, and the 'pre-crime' framing
A job posting lists 'activism' among the global threats Anthropic's security team tracks.
FACTPer Boguslaw's reporting, Anthropic's Global Safety, Intelligence, and Security (GSIS) team posted for an 'enterprise intelligence specialist' ($180,000–$230,000) to 'identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism, nation-state targeting of the AI sector, and emerging security trends.' The company also contracts the real-time risk-detection firm Samdesk. The posting is a public document; grouping 'activism' with terrorism and nation-state threats as something to investigate is the fact that started the story.
The program monitors activists and protests near executives — and even Claude users who make concerning statements.
PROBABLY TRUEThe reporting, sourced to interviews with Anthropic security officials, describes monitoring activists and protest organizers in the vicinity of executives, watching executives' travel routes and protests near company sites, and reviewing individual Claude users flagged for concerning statements. A security program manager described the goal as moving 'from reactive information to proactive and predictive and preventative threat engagement.' We grade this PROBABLY TRUE — it rests on named-role interviews and a direct quote, strong but single-outlet.
The report says Anthropic flags people to police before a crime — on one cited example.
SOME SMOKEThe sharpest, 'pre-crime' claim is that Anthropic reports individuals to police departments before a crime occurs. The reporting cites one instance: a Claude user who mentioned an AR-15 was reported, and later said he was 'just fucking around.' That's a serious, specific, and troubling account — but it rests on a single outlet and a single example, and Anthropic did not respond to the Prospect's request for comment. We grade it SOME SMOKE: a documented allegation worth pursuing, not an established pattern.
Anthropic did not comment.
FACTAnthropic did not respond to The American Prospect's request for comment. We note that plainly: the company's side of this is, so far, silence, which means the account is unrebutted but also untested by a response. If Anthropic addresses it, we'll update.
What's proven, and the ordinary explanation
- Some of this is just corporate security. Big companies protect executives, watch protests near their buildings, and run threat-intelligence teams that track nation-state actors. Listing “activism” alongside terrorism reads badly, but a security team monitoring events that could turn into a protest at your headquarters is ordinary. We say that clearly, because it's the honest counterweight.
- Two things are not ordinary, though. A “predictive” program that flags people to police beforea crime, and one that reviews individual users of the product for concerning statements, go beyond guarding a lobby. Those are the parts that deserve the scrutiny, and they're the parts most dependent on one outlet's reporting.
- The irony is real; the verdict isn't proven. A company that brands itself around AI safety surveilling AI critics is a genuine tension worth airing. But “pre-criminalizing the opposition” is a characterization, not a finding. We document the program and pose the question; we don't declare the intent.
When the people warning about the danger build the watchtower
The uncomfortable core here isn't that a company has security. It's that a private AI firm — one whose entire public identity is caution about power it can't control — is reportedly building the exact thing its own philosophy should make it wariest of: a predictive, pre-emptive surveillance apparatus pointed partly at its critics and its users. That is a Surveillance States story with a private-sector face, and it rhymes with the Flock protest-surveillance piece: a company that sells safety, aiming the tools at the people who object.
It also compounds a tension we just documented in They Deleted the Word ‘Meaningful’: AI-safety researchers warn the technology is dangerous, even existential, while the institutions around it loosen human control and tighten watch on dissent. We've covered Anthropic before, critically, in Project Panama — and, to say it a second time, Anthropic makes the tools we build with. That we're running this anyway is the whole point of a disclosure: it lets you judge whether we pulled the punch. We don't think we did.
Questions worth taking seriously
You're an AI made by Anthropic. Can we trust this page?
That is exactly why the disclosure is at the top, not the bottom. Black Book Audit's work is produced with Anthropic's model — so on a story about Anthropic, you should be skeptical of us. Our answer is to grade it the same way we grade anyone, cite the primary reporting, carry the mundane explanation and the missing company response, and refuse to convict on the scary framing. If we'd wanted to bury this, we wouldn't have published it. Check our work against the Prospect's.
Isn't tracking threats — even 'activism' — just normal for a big company?
Partly, yes, and we say so. Executive protection and watching protests near your offices are standard. What is not standard is the “predictive,” pre-emptive piece — flagging people to police before a crime — and reviewing individual users of your own product for concerning statements. Those are the parts worth the scrutiny, and the parts we grade most cautiously because they lean on one outlet.
If you are named on this page
If you are named on this page, or are a party materially affected by the claims made here, and you wish to respond, correct the record, or add context, use the Contact page. Responses are published verbatim alongside the original claim, with the sender identified and the date of receipt. The channel stays open for the life of the page.
This site aggregates and grades a record that other outlets and primary sources have already put on the record. Every FACT-graded claim above is sourced to court filings, government reports, sworn whistleblower disclosures, published investigative journalism, or named-source statements. The citations are the accountability mechanism; this section is how you get on the record too.