Anthropic Is Predicting, Tracking, and Identifying Activists Before They Commit a Crime

In 2026, you're innocent until the algorithm says otherwise.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Anthropic has spent years positioning Claude as the safer, more responsible AI chatbot. Now, new reporting raises uncomfortable questions about who the company considers a threat.

Anthropic Security Operations Manager Zach Melvin has described the company’s goal as moving from reactive security toward “proactive and predictive and preventative threat engagement and management,” according to an interview.[1]

A recent Anthropic job listing says its security analysts are expected to “identify, assess, track, and investigate” threats including terrorism, crime, nation-state activity — and “activism.”[2]

In this article
Anthropic’s security team is tracking ‘activism’
Anthropic also tracks some Claude users
You can’t predict a crime that hasn’t happened yet
Is Anthropic spying on protesters with Claude?
Think twice before treating an AI chatbot like a diary

Anthropic’s security team is tracking ‘activism’

Large companies routinely monitor protests, threats, and other events that could affect employees or facilities. But when does legitimate protest become a security threat?

The American Prospect reports that Anthropic already uses outside intelligence tools to monitor events around its executives.

In one example described by Anthropic security officials, risk-detection company Samdesk reportedly alerted the company that organizers had changed the time of a planned protest involving an Anthropic executive.

Anthropic received roughly an hour of warning and rerouted the executive through a service entrance.

Anthropic also tracks some Claude users

Anthropic previously told The Wall Street Journal that it tracks concerning behavior over time using a “person-of-interest process” designed to identify escalating behavior.

The company said several people involved in incidents eventually reported to police had already been monitored by its security team.

One particularly striking case was reported by The American Prospect. Anthropic contacted San Francisco police about a Claude user who allegedly told the chatbot he had purchased an AR-15 and had CEO Dario Amodei “in his sights.”

When contacted by the San Francisco Standard, the user reportedly said he was “just f**king around.”

Threats involving firearms are obviously different from criticizing an AI company or attending a protest. Companies have legitimate reasons to respond to credible threats involving firearms, but the incident shows that what you tell Claude may not remain between you and the chatbot.

You can’t predict a crime that hasn’t happened yet

There’s a fundamental problem with “predictive” security: you’re judging people based on what you think they might do, not what they’ve actually done.

That becomes especially troubling when activism is part of the equation. Peaceful protest, political organizing, and criticizing a company are protected forms of expression, but treating them as potential warning signs can put people under scrutiny before they’ve done anything wrong.

And the prediction may never come true.

That alone can limit free expression. People who know their lawful activities could attract scrutiny may decide that speaking up, organizing, or protesting simply isn’t worth the risk.

Nobody has to explicitly ban speech for surveillance to silence it.

Anthropic hasn’t demonstrated that it uses an algorithm to predict which activists will commit crimes. But “predictive” security necessarily means judging who poses a threat before that person has actually done anything threatening. Including activism in that calculus risks turning lawful dissent itself into evidence of future wrongdoing.

Is Anthropic spying on protesters with Claude?

There’s no evidence of that yet.

The protest-monitoring example involved Samdesk, a third-party risk intelligence company, rather than Claude. Anthropic restricts customers from using its technology for certain surveillance purposes.

Anthropic’s safeguards operation also uses monitoring and detection systems to identify policy violations. The company says it may warn, suspend, or terminate users when it detects violations.

These are separate from Anthropic’s corporate security operation. They nevertheless show that Anthropic monitors activity across several parts of its business for behavior it considers potentially dangerous.

Think twice before treating an AI chatbot like a diary

Users should reconsider the assumption that talking to an AI assistant is the digital equivalent of thinking out loud. Anything you type into a cloud-based AI service is information you’ve handed to a company. Depending on the service, its policies, and what you say, automated systems analyze that information and escalate suspicious activity.

That matters well beyond Anthropic.

Avoid feeding AI chatbots passwords, financial account information, private medical records, confidential work documents, or other information you wouldn’t want stored on someone else’s servers.

And if you’re discussing politically sensitive activity, protests, or other deeply personal subjects, remember the simplest privacy rule of all: You can’t lose data you never handed over in the first place.

Take Control of Your Online Privacy
5.0
Editorial Rating
Claim Deal
On Incogni's website
2026 Editors’ Choice
Best Overall Data Removal Service
Privacy Protection
Incogni
PROMOTION: Get 55% Off Annual Plans With Code COOKIE
  • Top-rated data removal service that scrubs your info from 420+ data broker sites automatically
  • Independently verified by Deloitte, meaning removals are actually sent, confirmed, and not just claimed
  • The Unlimited plan extends coverage to 2,000+ additional sites with human-assisted custom removals

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Anthropic Is Building a Predictive Surveillance System to Monitor Activists

[2] Enterprise Intelligence Specialist Job Listing