All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Anthropic has spent years positioning Claude as the safer, more responsible AI chatbot. Now, new reporting raises uncomfortable questions about who the company considers a threat.
Anthropic Security Operations Manager Zach Melvin has described the company’s goal as moving from reactive security toward “proactive and predictive and preventative threat engagement and management,” according to an interview.[1]
A recent Anthropic job listing says its security analysts are expected to “identify, assess, track, and investigate” threats including terrorism, crime, nation-state activity — and “activism.”[2]
Anthropic also tracks some Claude users
You can’t predict a crime that hasn’t happened yet
Is Anthropic spying on protesters with Claude?
Think twice before treating an AI chatbot like a diary
Anthropic’s security team is tracking ‘activism’
Large companies routinely monitor protests, threats, and other events that could affect employees or facilities. But when does legitimate protest become a security threat?
The American Prospect reports that Anthropic already uses outside intelligence tools to monitor events around its executives.
In one example described by Anthropic security officials, risk-detection company Samdesk reportedly alerted the company that organizers had changed the time of a planned protest involving an Anthropic executive.
Anthropic received roughly an hour of warning and rerouted the executive through a service entrance.
Anthropic also tracks some Claude users
Anthropic previously told The Wall Street Journal that it tracks concerning behavior over time using a “person-of-interest process” designed to identify escalating behavior.
The company said several people involved in incidents eventually reported to police had already been monitored by its security team.
One particularly striking case was reported by The American Prospect. Anthropic contacted San Francisco police about a Claude user who allegedly told the chatbot he had purchased an AR-15 and had CEO Dario Amodei “in his sights.”
When contacted by the San Francisco Standard, the user reportedly said he was “just f**king around.”
Threats involving firearms are obviously different from criticizing an AI company or attending a protest. Companies have legitimate reasons to respond to credible threats involving firearms, but the incident shows that what you tell Claude may not remain between you and the chatbot.
You can’t predict a crime that hasn’t happened yet
There’s a fundamental problem with “predictive” security: you’re judging people based on what you think they might do, not what they’ve actually done.
That becomes especially troubling when activism is part of the equation. Peaceful protest, political organizing, and criticizing a company are protected forms of expression, but treating them as potential warning signs can put people under scrutiny before they’ve done anything wrong.
And the prediction may never come true.
That alone can limit free expression. People who know their lawful activities could attract scrutiny may decide that speaking up, organizing, or protesting simply isn’t worth the risk.
Nobody has to explicitly ban speech for surveillance to silence it.
Anthropic hasn’t demonstrated that it uses an algorithm to predict which activists will commit crimes. But “predictive” security necessarily means judging who poses a threat before that person has actually done anything threatening. Including activism in that calculus risks turning lawful dissent itself into evidence of future wrongdoing.
Is Anthropic spying on protesters with Claude?
There’s no evidence of that yet.
The protest-monitoring example involved Samdesk, a third-party risk intelligence company, rather than Claude. Anthropic restricts customers from using its technology for certain surveillance purposes.
Anthropic’s safeguards operation also uses monitoring and detection systems to identify policy violations. The company says it may warn, suspend, or terminate users when it detects violations.
These are separate from Anthropic’s corporate security operation. They nevertheless show that Anthropic monitors activity across several parts of its business for behavior it considers potentially dangerous.
Think twice before treating an AI chatbot like a diary
Users should reconsider the assumption that talking to an AI assistant is the digital equivalent of thinking out loud. Anything you type into a cloud-based AI service is information you’ve handed to a company. Depending on the service, its policies, and what you say, automated systems analyze that information and escalate suspicious activity.
That matters well beyond Anthropic.
Avoid feeding AI chatbots passwords, financial account information, private medical records, confidential work documents, or other information you wouldn’t want stored on someone else’s servers.
And if you’re discussing politically sensitive activity, protests, or other deeply personal subjects, remember the simplest privacy rule of all: You can’t lose data you never handed over in the first place.
[1] Anthropic Is Building a Predictive Surveillance System to Monitor Activists
[2] Enterprise Intelligence Specialist Job Listing