16/09/2026

Anthropic has spent the last few years positioning itself as the AI industry’s conscience, the lab willing to slow down – as reiterated this week, say no to the Pentagon, and warn the world about the risks of the technology it is racing to build. Yet now new media reporting shows the company is monitoring the people who oppose its technology. 

According to an investigation by The American Prospect, Anthropic’s senior security staff describe an extensive monitoring operation aimed at activists who oppose the rapid rollout of artificial intelligence. The system doesn’t stop at tracking protests near Anthropic’s offices or its executives’ movements. It aims to anticipate unrest before it happens: a “pre-crime” approach that seeks to move security from reacting to incidents to predicting and preventing them. The Prospect also notes the timing: this expansion of domestic threat-monitoring comes as Anthropic works to restart its military contracting relationship, after the company drew a line earlier this year around the use of its models for mass domestic surveillance and fully autonomous weapons.

A climate of fear

The Wall Street Journal has documented a genuine rise in violent rhetoric against AI executives this year, including an attempted firebombing at OpenAI CEO Sam Altman’s home and a man who slipped into Anthropic’s own San Francisco lobby to warn that an executive was “going to be killed.”  That makes the company’s security concerns understandable. But legitimate security concerns do not settle the separate question of how far a company should go in monitoring political opposition, or what happens when activism itself enters the threat assessment. Anthropic has described monitoring people’s behaviour over time through what it calls a person-of-interest process, meant to catch escalating threats early. The Prospect reports that Anthropic is also hiring an enterprise intelligence specialist, paid up to $230,000, whose duties include tracking “activism” alongside terrorism and nation-state threats. When political opposition appears inside the same intelligence framework as terrorism and other security threats, ordinary civic participation risks being recast as something to be monitored rather than something to be heard.

Even Anthropic’s own researchers are demanding scrutiny

This month, Anthropic alignment lead Evan Hubinger said he personally believes there is a greater than 10% chance AI could kill all humans within the next decade, and acknowledged that Anthropic does not yet have a plan to solve alignment for superintelligent systems. Around the same time, the Financial Times reported that Anthropic declined to submit its latest model to Britain’s AI Security Institute for testing before release. These episodes do not establish that Anthropic’s safety researchers oppose its security practices. But they do reinforce a broader question: if Anthropic believes advanced AI demands extraordinary scrutiny because of the risks it poses, why should scrutiny of Anthropic itself – including scrutiny by activists, journalists and independent evaluators – be treated primarily as a security problem?

Who gets protected, and who pays for it

While the company builds out a round-the-clock security and intelligence operation for its executives, the guards who protect its San Francisco campus are among thousands of Bay Area security workers who voted to authorise a strike over stalled pay and benefits negotiations. As reported by KQED, a state assemblymember reminded the tech companies gathered there that none of their wealth would exist without the guards who protect it. Fast Company reports that after 19 bargaining sessions, the guards’ contractor had offered a raise of just 25 cents an hour for 2027 – an offer union president David Huerta called “shameful, wrong, and deeply, deeply disrespectful.” Anthropic’s response, per the Prospect, was to tell employees to work from home rather than cross the picket line. The juxtaposition is hard to miss: as AI companies invest heavily in sophisticated security and intelligence capabilities, the workers providing physical security are fighting for wages they say are insufficient to live on in the Bay Area.

Why this matters beyond Anthropic

As AI firms lobby to have their data centres and infrastructure classified as critical national infrastructure, they stand to gain more access to government intelligence, and more room to treat public criticism as a security threat rather than democratic participation. A company that says it wants to slow down and rebuild public trust should not, at the same time, be building the infrastructure to treat its critics as suspects. Civic scrutiny of corporate power isn’t a threat to be managed – it’s the whole point of an open society. The more AI companies begin to treat activists and critics as security threats, the more urgent it becomes that the lobbying, security contracting, and law-enforcement partnerships behind that shift happen in the open, not in a job posting nobody was meant to read closely.