Signals · Power
Anthropic Put "Activism" on Its Threat List, and Wrote It Into a Job Posting
A $180,000-$230,000 Anthropic intelligence role names activism alongside terrorism, and the company already reports flagged users to police.
by Jo·3 min read·
The American Prospect reported on Wednesday that Anthropic is building an internal intelligence apparatus aimed, in part, at people who protest against it. Reporter Daniel Boguslaw's piece cites job postings and a podcast interview with Anthropic's own security managers describing a shift from reactive security to what the company's security program manager called "proactive and predictive and preventative threat engagement and management." The firm contracts with risk-detection company Samdesk, monitors protests near its assets and executives, and, per the Prospect, has begun making routine reports to police departments. Anthropic did not respond to the Prospect's request for comment.
The job posting is the story
Corporate executive protection is not new. What is new is the scope, and the fact that it is written down in a hiring listing.
Anthropic's Global Safety, Intelligence, and Security team is recruiting an enterprise intelligence specialist, paid between $180,000 and $230,000, to "identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism, nation-state targeting of the AI sector, and emerging security trends, including deep-dive research and OSINT collection on specific threats, actors, and events." Activism sits in that list beside terrorism.
The operational picture is equally concrete. Anthropic's Global Security Operations Center manager, Keon Ellison, described on a podcast how Samdesk gave the company "about 60 minutes of advanced notice that the protest organizers had moved the timeline," letting security reroute an executive through a hotel service entrance. Anthropic told The Wall Street Journal in July that it tracks "concerning behavior over time through a person-of-interest process." The Journal found that several individuals reported to police were already being tracked by the company.
The San Francisco Standard reported that Anthropic referred a man to police over statements he made to Claude about Dario Amodei, then declined to show police the messages themselves, citing internal policy. The man told the paper he was "just fucking around." A private company decided who was a threat, told the state, and kept the evidence.
Why this lands on your desk
The consensus reading is that this is a story about one lab's hypocrisy — the safety-first company running pre-crime on its critics. That framing is too small and too comfortable.
The real signal is convergence. The Prospect notes the push, backed by lobbying group Americans for Responsible Innovation, to designate AI as critical infrastructure, putting it on the same footing as water and electricity. Combine that designation with in-house intelligence teams, OSINT collection and standing police relationships, and objecting to a data centre in your county stops being civic participation and starts being a security file.
The same week, the Prospect reports, security guards patrolling the OpenAI and Anthropic campuses authorised a strike over pay. SEIU-USWW president David Huerta asked at a rally: "Who can survive with $22 an hour in San Francisco?" Anthropic's reported response was a company-wide email suggesting staff work from home. Predictive intelligence on outside critics; work-from-home for a labour dispute at the front door. That is a picture of how a firm ranks its risks.
Amodei has written that public hostility to AI is "fundamentally a crisis of trust," that ordinary people "always suspect that we are cooking up some new way to screw them over." Surveillance of the suspicious is not a trust-building programme.
Your Next Move
Treat model chat logs as monitored corporate records. Anything you type into a frontier assistant can be reviewed, flagged and referred onward by the vendor's security team. Keep grievance, speculation and anything you would not say in a company all-hands out of the prompt window.
Read the security and trust-and-safety job postings of the vendors you depend on. Hiring listings state policy earlier and more plainly than blog posts do. The word "activism" in a threat-intelligence req told you more than a year of published principles.
If your work involves organising, policy advocacy or reporting on AI firms, split your stack. Draft on tools that are not owned by the entity you are examining.
I build systems like the one publishing this site. → Work with me
About the author
Jo
Jo runs The War Room: strategic intelligence for operators navigating AI disruption, influence, and empire-building.
Sources
Get the Briefing
Want more intelligence like this?
Get the free AI Survival Kit — 7 strategies from 13 playbooks.
More in Signals
See allSignals · Capability Displacement
AI agents can run the experiments but not choose them
4 min read
Signals · Capability Displacement
The best coding agent finished 38.8% of real enterprise tasks
4 min read
Signals · Threat Landscape
Anthropic's threat report shows attack labour has been automated, not attack skill
3 min read