Anthropic’s public brand is the careful lab — the one that spent early 2026 in a standoff with the Pentagon over mass surveillance and autonomous weapons. The American Prospect’s Daniel Boguslaw reports that the same company is building an intelligence operation aimed at the people who oppose rapid AI development. Anthropic did not comment.

The reporting draws on the company’s own job postings, a podcast interview with Anthropic’s security staff, company statements to the Wall Street Journal, and local coverage of police reports:

  • Protest tracking through a vendor. Anthropic contracts Samdesk for real-time event monitoring. Security manager Keon Ellison described getting about 60 minutes’ warning that a planned protest had moved up its schedule, which let the company reroute an executive and send them in through a hotel service entrance.
  • Person-of-interest files. Anthropic told the WSJ it tracks “concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early.” Several people in reported incidents were already being tracked before police were called.
  • Police reports without evidence. After a Claude user wrote that he had bought an AR-15 and had CEO Dario Amodei “in his sights,” Anthropic called San Francisco police — then declined to show officers the messages, citing internal policy. The man told reporters he was “just fucking around.”
  • A job posting that names activism. An $180,000–$230,000 enterprise intelligence specialist role lists “activism” among the threats to identify, assess, track, and investigate, including OSINT collection — open-source intelligence gathering — on specific actors and events.

The company’s own framing of the program is predictive. Anthropic’s security program manager describes moving from reactive reporting to “proactive and predictive and preventative threat engagement and management” — pre-crime, in plain language, with no due-process scaffolding attached to it.

Why it matters beyond one company: if AI and its infrastructure — data centers, power supply — get designated critical infrastructure, labs inherit standing access to federal intelligence products and a role in defining who counts as a threat. Civic opposition to a data center becomes a security matter, and the company helps decide who is an extremist.

There’s a class dimension in the same week. The guards who patrol Anthropic’s and OpenAI’s campuses authorized a strike over $22/hour wages in San Francisco; Anthropic’s response was a company-wide email suggesting employees work from home.