Anthropic runs an internal "person-of-interest" tracking process on people its security team considers risks, including activists who protest the company, and pays a third-party intelligence firm to warn executives before a demonstration happens, according to a report The American Prospect published this evening. The story, built on the company's own statements to reporters and a podcast interview with two of its security managers, adds detail to a pattern Anthropic has confirmed piece by piece since July: it tracks people over time, has referred at least one to police, and is currently hiring for a role explicitly tasked with monitoring "activism" alongside terrorism and nation-state threats.

  • Anthropic told The Wall Street Journal in July it runs a "person-of-interest process" to "catch escalation patterns early," and said several people later reported to police had already been tracked by its security team.
  • On a podcast, Anthropic's Global Security Operations Center manager described getting about 60 minutes of advance notice from contracted vendor Samdesk after protest organizers moved up a demonstration timed to an executive's travel.
  • A live Anthropic job posting for an "Enterprise Intelligence Specialist," paying $180,000 to $230,000, lists "activism" alongside terrorism, crime and nation-state targeting as categories the role tracks and investigates.
  • In August, Anthropic reported a Claude user to San Francisco police over messages describing an AR-15 purchase and a threat against CEO Dario Amodei, but the responding officer noted the company "refused to show me the messages" under its own internal policy.
How Anthropic's activist-tracking pipeline reportedly works Flow diagram with four stages: protest and threat signals are picked up online and on site, fed to Anthropic through its contracted vendor Samdesk, logged in the company's internal person-of-interest file inside its Global Security Operations Center, and in some cases lead to a police referral or an executive travel warning before any incident occurs. The reported tracking pipeline SOURCE: THE AMERICAN PROSPECT, WSJ, SF STANDARD, SEP 2026 Protest and threat signals Samdesk contract intel feed GSOC person-of- interest file Police referral or exec travel warning online + on-site ~60 min advance tracks activists too before an incident Anthropic did not respond to the Prospect's request for comment on this pipeline. genztech.blog
Fig 1 Four stages link a protest signal to a police report or executive travel change, according to the company's own statements and podcast comments from its security staff.

What exactly is Anthropic tracking, and how?

Two systems, confirmed separately, appear to feed each other. The first is the "person-of-interest process" Anthropic described to the Journal in July: security staff log individuals over time so escalation patterns show up before they turn into something worse. The second surfaced in a podcast interview between Anthropic's Global Security Operations Center manager, Keon Ellison, its security operations manager, Zach Melvin, and James Neufeld, the CEO of Samdesk, the risk-detection firm Anthropic contracts with. Ellison described a specific example: an executive was traveling into a major city, and Samdesk fed the company intelligence that protest organizers had moved their timeline up, giving Anthropic about an hour's notice to adjust the trip. That is standard corporate executive-protection practice at plenty of companies. What makes it notable here is that a live Anthropic job listing folds "activism" into the same bucket as terrorism, crime and nation-state threats, meaning protest monitoring isn't a one-off travel precaution, it is written into a full-time analyst role.

RelatedChatGPT, Claude and Grok Go Down Together in Rare Outage

Why does a "person-of-interest" file matter if you haven't done anything illegal?

Because the reporting describes a predictive posture, not a reactive one: flagging people before an incident, not after. A security team logging genuine threats of violence is defensible and, per the AR-15 case below, has real cause behind it. The harder question is what happens when "activism" itself is the trigger for a file, which is exactly the category the Enterprise Intelligence Specialist posting names. Anthropic has spent two years marketing itself as the safety-conscious alternative to OpenAI and, as recently as February, publicly refused a Pentagon push to use Claude for tools closer to mass domestic surveillance. A company building a "who might become a problem" list on the people protesting its own offices sits awkwardly next to that pitch, and for a firm whose enterprise customers are increasingly betting on Claude for sensitive workloads, the gap between stated principles and internal security practice is the kind of story that shows up in procurement conversations, not just headlines.

What happened in the San Francisco police case?

On August 14, according to the San Francisco Standard, a Claude user wrote that he had bought an AR-15 and had Dario Amodei "in his sights," and separately said he intended to kill everyone at the company. Anthropic banned the account and reported it to the San Francisco Police Department on August 20. The responding officer's report includes an unusual line: the Anthropic employee who filed the report "refused to show me the messages due to Anthropic's company policy," even though the company was the one that called the police in. Anthropic told the Standard, "We banned this account, consistent with our standard practice, and referred the case to law enforcement. This is our safeguards process working as intended." Reached by phone, the user said he was "just fucking around," was embarrassed, and declined further comment; he was not arrested, charged, or named. Whatever actually happened in that chat, withholding the transcript from the officers investigating a death threat against your own CEO is a strange way to demonstrate a safeguards process is working.

How does this square with Anthropic's public safety image?

Not comfortably. The company has spent 2026 positioning itself as the AI lab that says no, most visibly in its February standoff with the Department of Defense over using Claude for tools the Pentagon wanted and Anthropic argued crossed into mass domestic surveillance and autonomous weapons territory. That refusal became a talking point about the company's values. Running its own predictive tracking process on activists, while declining to hand its own evidence to police in a genuine threat case, is a different kind of story about the same company, and it did not respond to the Prospect's request for comment before publication.

RelatedFacial Recognition Goes Live on the London Underground

AreaPublic positionReported practice
Domestic surveillancePublicly refused a Pentagon request tied to mass domestic surveillance, February 2026Runs its own person-of-interest tracking plus a paid protest-intelligence feed on activists
User safety claimsMarkets Claude's safeguards as working "as intended"Reported a death threat to police while declining to share the actual chat log
Who gets trackedSays the system exists to catch genuine escalation and violenceJob posting tracks "activism" as its own category, alongside terrorism and nation-state threats
  1. Feb 2026Anthropic publicly refuses a Pentagon request it says crosses into mass domestic surveillance and autonomous weapons use. Becomes a core part of the company's safety-first public image.
  2. Jul 2026Anthropic confirms to The Wall Street Journal it runs a "person-of-interest" tracking process. Says the process helps "catch escalation patterns early."
  3. Aug 14, 2026A Claude user sends messages describing an AR-15 purchase and a threat against CEO Dario Amodei. Anthropic bans the account.
  4. Aug 20, 2026Anthropic reports the user to SFPD, then declines to share the messages with the responding officer. Officer's report flags the refusal explicitly.
  5. Sep 4, 2026The San Francisco Standard publishes the SFPD case. Anthropic calls it "our safeguards process working as intended."
  6. Sep 9, 2026The American Prospect publishes the wider investigation into activist tracking. Anthropic did not respond to its request for comment.
What to watch
  • Whether Anthropic answers the Prospect's questions. Silence on a story this specific, naming its own staff and job postings, is itself a data point.
  • What the Enterprise Intelligence Specialist actually does once hired. The posting names "activism" explicitly; how that plays out in practice is the real test of the reporting's core claim.
  • Enterprise customer reaction. Companies buying Claude for sensitive workloads now have a concrete surveillance-practices story to weigh against Anthropic's safety marketing.
  • Whether other labs disclose similar security operations. Anthropic is not obviously unique among large AI companies in running executive-protection and threat intelligence; whether OpenAI, Google or Meta run comparable "person-of-interest" programs is untested territory.

Our take

Some of this is ordinary corporate security, not a scandal. Any company whose CEO gets a specific, credible death threat should report it to police, and Anthropic did. The part that doesn't hold up is the combination: building a predictive tracking file that explicitly folds in activism, then, in the one documented case where police actually got involved, refusing to hand over the evidence that would let officers assess the threat themselves. That is not what "safeguards process working as intended" looks like from the outside. Anthropic built its brand on being the lab willing to say no to ethically fraught uses of its own technology. Saying no to the Pentagon in public while building a quieter, less accountable version of the same capability internally is the kind of contradiction that costs more credibility than either fact would alone.

Primary sources

Original analysis by GenZTech, based on The American Prospect's reporting.