该职位的薪酬在 18 万至 23 万美元之间,其部分职责包括“识别、评估、跟踪和调查全球威胁,包括地缘政治不稳定、恐怖主义、犯罪、激进活动、国家对 AI 行业的针对,以及新兴安全趋势,其中包括对特定威胁、行为者和事件的深入研究及公开来源情报(OSINT)收集”(加重部分为原文强调)。
Anthropic 情报收集范围扩展至国家乃至全球层面,与近期加强 AI 及其支撑基础设施(包括数据中心和电力供应)标签的努力相一致。关键基础设施的认定将使人工智能与供水、电力和宽带等设施处于同等地位。事实上,像“负责任创新的美国人”(Americans for Responsible Innovation, ARI)这样支持 AI 的团体曾敦促:https://industrialcyber.co/ai/ari-urges-trump-to-designate-ai-as-critical-infrastructure-amid-growing-cyber-risks-across-critical-sectors/ 特朗普政府做出这一改变。根据 ARI 的说法,AI“对美国至关重要,这类系统和资产的失效或破坏将对国家安全、国家经济安全、国家公共卫生或安全,或这些因素的任意组合产生严重影响”。
将前沿实验室纳入国家安全的坚固保护伞中,不仅会让 Anthropic、OpenAI 和 Google 获得更多由联邦执法和情报机构产生的情报产品;还将鼓励这些公司影响联邦机构对其利润底线所面临威胁的看法,而这些底线现在已被转变为“关键基础设施”。
Job postings and interviews with senior security officials at Anthropic show that the frontier AI lab is building out an extensive monitoring system to keep tabs on activists who oppose the rapid development of artificial intelligence.
In addition to monitoring activists in the vicinity of Anthropic executives and keeping tabs on protests near physical Anthropic assets, the firm is also implementing a “pre-crime” approach, attempting to predict incidents before they happen. In some cases, that also means reporting suspects to police before a crime occurs. Anthropic did not respond to the Prospect ’s request for comment.
Anthropic’s plans to surveil dissent are at odds with the firm’s efforts to cast itself as the responsible alternative to OpenAI. At the beginning of the year, the Department of Defense and Anthropic engaged in a high-profile dustup over Anthropic’s refusal to allow the military to use its tools for mass domestic surveillance and autonomous weapons. That tension seems to have eased as Anthropic hires:https://prospect.org/2026/08/27/anthropic-reenlists-for-war-defense-department-ai/ for “national security sales” positions, seeking to restart military contracts. The increase in threat monitoring of domestic opponents fits with a renewed focus on national security.
More from Daniel Boguslaw :https://prospect.org/author/daniel-boguslaw/
A piece of Anthropic’s surveillance architecture was revealed in a podcast interview from last year between Anthropic Global Security Operations Center Manager Keon Ellison, Security Operations Manager Zach Melvin, and James Neufeld, CEO of Samdesk, a company Anthropic contracts with for risk detection.
In a wide-ranging conversation about threat monitoring and analysis, the interview also touches on monitoring activists. “Last year we had an executive travel into a major city when we received some intelligence through Samdesk about a planned protest,” Ellison said. The originally scheduled protest was moved up due to permitting issues. “Samdesk gave us about 60 minutes of advanced notice that the protest organizers had moved the timeline,” Ellison explained. “That extra hour was critical. Without it our executives would have departed their meetings, they would have ran right into the heart of the disruption.”
Ellison said that Anthropic used this data to devise an alternate route for the executive and funnel them to a service entrance at the hotel. “What could have been a high-stress situation,” he said, “was really mitigated through early detection through Samdesk and giving us that information.”
Anthropic has begun making routine reports to police departments across the country for threats, and told:https://www.wsj.com/us-news/the-ai-backlash-has-tech-executives-fearing-for-their-lives-30c43972 The Wall Street Journal in July, “We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early.” According to the Journal , “several individuals involved in incidents reported to police were already being tracked by Anthropic security.”
Last month, The San Francisco Standard reported:https://sfstandard.com/2026/09/04/anthropic-threat-claude-sfpd/ that Anthropic had reported a man to San Francisco police for telling Claude that he had bought an AR-15 semiautomatic rifle and had CEO Dario Amodei “in his sights.” When the Standard contacted the man in question, he told the newspaper he was “just fucking around.”
But while Anthropic was fast to call the cops on a frustrated Claude user, the Standard also reported a key detail: Anthropic refused to show police the actual messages, citing Anthropic’s internal policy. In short, Anthropic reported a user for in-platform speech, and then refused to provide police with evidence of actual wrongdoing.
Analysis that goes beyond the noise with in-depth, progressive reporting.
This kind of pre-crime policing, encouraged without due process, is referenced as an explicit goal by Anthropic’s security program manager in the podcast reviewed by the Prospect . “The goal would be transforming operations from reactive information to gathering proactive and predictive and preventative threat engagement and management,” he said, adding, “That’s the kind of operational maturity that makes sense for protecting high-value targets in any industry.”
Anthropic’s effort to build a predictive security apparatus extends beyond the C-suite to its Global Safety, Intelligence, and Security (GSIS) team, according to a job posting from last month detailing Anthropic’s search for an enterprise intelligence specialist who “will investigate specific threats, actors, and events, produce finished assessments, and help keep Anthropic’s employees ahead of a rapidly evolving threat landscape and in a defensible position.”
Part of that role, compensated at between $180,000 and $230,000, will be to “identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism , nation-state targeting of the AI sector, and emerging security trends, including deep-dive research and OSINT collection on specific threats, actors, and events” (emphasis added).
The expansion of Anthropic’s intelligence-gathering to a national and even global scale tracks with recent efforts to heighten the labeling of AI and the infrastructure powering it, including data centers and power supply. A critical infrastructure designation would put artificial intelligence on the same footing as water, electricity, and broadband. And indeed, AI’s boosters like Americans for Responsible Innovation (ARI) have urged:https://industrialcyber.co/ai/ari-urges-trump-to-designate-ai-as-critical-infrastructure-amid-growing-cyber-risks-across-critical-sectors/ the Trump administration to make the change. Per ARI’s telling, AI is “so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.”
Enshrining frontier labs in the hardened cloak of national security would not only give Anthropic, OpenAI, and Google even more access to intelligence products generated by federal law enforcement and intelligence agencies; it would also embolden these companies to shape how federal agencies view threats to their bottom line, now transformed as “critical infrastructure.”
It’s not hard to imagine how civic engagement by the same bipartisan coalition opposing data centers could turn its focus onto AI, only to be branded in the same instant as extremists or, even worse, terrorists. Anthropic’s answer to this problem has been to work even harder at producing artificial intelligence that can deliver services that can’t be brushed aside by the public.
“I do agree that the public has a negative view of AI (and that this is a big problem), but I don’t think it is primarily caused by me or any other AI leader warning about AI’s risks,” Anthropic CEO Dario Amodei wrote on Twitter last month. “I think it is fundamentally a crisis of trust … I think that ordinary people don’t trust companies, governments, or the tech industry and always suspect that we are cooking up some new way to screw them over.”
As Anthropic ramps up its efforts to monitor dissent with in-house intelligence teams and real-time protest tracking powered by AI, it will have to contend with the increasing economic desperation that plagues human beings outside its Bay Area towers. Last week, the security guards who patrol the campuses of OpenAI and Anthropic announced that they had authorized:https://www.fastcompany.com/91601758/the-security-workers-who-guard-openai-and-anthropic-could-go-on-strike a strike over stalled pay negotiations. In response, Anthropic sent:https://www.businessinsider.com/anthropic-san-francisco-staff-work-remote-office-security-strike-2026-8 a company-wide email telling employees that it was best if they worked from home.
“Who can survive with $22 an hour in San Francisco?” David Huerta, president of SEIU-USWW, the union representing security guards in the Bay Area, said:https://www.kqed.org/news/12098063/workers-guarding-san-franciscos-wealthiest-companies-vote-to-authorize-a-strike at a rally last week. Around him, security guards chanted: “Shame.”
We do things differently at the Prospect . We haven’t put up a paywall—we’re free for all readers regardless of their ability to pay—and we don’t run programmatic advertising.
To stay true to our values, we need you to support us. If you believe in our journalism and our independence, make a donation today.
Why? We believe that quality journalism should be available to everyone, even if they cannot afford a monthly subscription.
Everything we’re doing now and in the future at the Prospect centers around you, our readers. From the stories we write to the business model we use, we place you at the center of all our decision making.
Daniel Boguslaw is an investigative reporter based in Brooklyn. More by Daniel Boguslaw
Cut through the noise of daily news with in-depth, progressive analysis.
Sign in by entering the code we sent to , or clicking the magic link in the email.
情报判断
Aioga 编辑摘要
Aioga 编辑摘要:The American Prospect 依据职位招聘和高管访谈报道,Anthropic 正在建设监控系统以追踪反对 AI Aioga 将其归入「行业动态」方向,重点关注它对真实使用和行业竞争的影响。