Knowledge Commons
HomeAboutGuidesPopularContact

Anthropic's Activist Monitoring System

The Panopticon's Doorkeeper

Author: Oğuz Demirkapı
Anthropic's Activist Monitoring System

The Panopticon's Doorkeeper

Anthropic's activist monitoring system, the same week's three documents, and the strike of the security guards working for $22 an hour

Dear Young Comrades,

This week, while reading Anthropic's 2030 scenarios, we named techno-capitalism's three mechanisms, and of the third we said this: the digital panopticon is the thing the model squeezed under the heading "transition frictions"; Palantir is that thing itself. That sentence aged in two days. The panopticon had not been subcontracted to Palantir; the "responsible" wing had set up its own monitoring team. This piece was written to correct that sentence, and in correcting it to set three documents from one week side by side.

At the end of the piece we will come to an event no one saw inside all this apocalyptic noise: the strike decision of the security guards who hold the doors of the Anthropic and OpenAI buildings. That is the week's only organised workers' action, and as luck would have it the journalist who wrote the surveillance story ended his piece with it.

What Happened?

On the morning of 10 September the viral news account Globe Eye News shared a post: "Anthropic is building a comprehensive surveillance and intelligence system to monitor activists and protests opposing AI." By evening the post had been viewed 720,000 times. The source was Daniel Boguslaw's investigative report published the day before in The American Prospect.

On this blog, when we relay a story, we put the evidence down first and add the commentary after; that is the only way to meet the reader's "they're exaggerating" objection at the start. Boguslaw's story does not rest on a leaked document or an unnamed source; it sets four public sources side by side.

The first is a podcast published last year. The speakers are Anthropic's Global Security Operations Center Manager Keon Ellison, Security Operations Manager Zach Melvin, and James Neufeld, CEO of Samdesk, the company Anthropic contracts with for risk detection. Ellison tells a story: an executive travels to a major city, a planned protest is moved up because of permitting issues, Samdesk gives "about 60 minutes of advanced notice that the protest organizers had moved the timeline," and the security team routes the executive by an alternate path to the hotel's service entrance. "That extra hour was critical. Without it our executives would have departed their meetings, they would have ran right into the heart of the disruption." In the same recording the security program manager defines the goal: transforming operations from "reactive information" to "proactive and predictive and preventative threat engagement and management."

The second is an August job posting. The Global Safety, Intelligence, and Security team is hiring an "enterprise intelligence specialist," at $180,000–230,000 a year. The role: "identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism, nation-state targeting of the AI sector, and emerging security trends, including deep-dive research and OSINT collection on specific threats, actors, and events." The story's strongest piece of evidence is this sentence. "Activism" has been written in, as a threat category, between terrorism and crime.

The third is the company's own statement to the Wall Street Journal in July: "We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early." According to the Journal, several people involved in incidents reported to the police "were already being tracked by Anthropic security."

The fourth is the San Francisco Standard's report of 4 September. On 14 August a Claude user wrote in a chat that he had bought an AR-15 and had Dario Amodei "in his sights." Anthropic reported him to the police five days later, saying the person had bought a gun "with the intention of killing everyone at Anthropic"; but when the police arrived at headquarters a company employee refused to show the messages, "per company policy." The user told the paper he was joking; the account was closed, and no further action was taken. Boguslaw's comment is apt: the company reports in-platform speech to the police, then does not give the police the evidence. There is no judge, no prosecutor; there is a person-of-interest file.

What Is Not Evidence?

Let us be honest. The label "pre-crime system" is the journalist's frame; it is inferred from the security manager's words "predictive and preventative." Which groups are being monitored is not named in the story. What Samdesk collects (most likely open social-media scanning) is not explained. Globe Eye News's phrase "comprehensive intelligence system" overshoots the concreteness of the source. Not a single activist or civil-liberties organisation speaks in the story. Anthropic did not respond to a request for comment.

Let us also record the company's rationale, because it is real. On 11 April a twenty-year-old tried to set fire to Sam Altman's San Francisco house with a Molotov cocktail; on him was a manifesto advocating "the killing of AI CEOs and investors." Days later someone entered Anthropic's lobby with threats. According to the threat-intelligence firm Liferaft, digital threats against AI executives rose sevenfold between February and May. The executives are afraid, and part of their fear is well founded.

But it is precisely here that we have to return to that single word in the job posting. Between the person who threw a Molotov and sixty-nine-year-old Wynd Kaufmyn, who went to prison over a sit-in in front of OpenAI in February 2025, between Stop AI members on hunger strike and an attacker who wrote thirty-four messages on Discord, there is a legal and moral gulf. To write "activism" onto the same list as terrorism is to close that gulf with a single word. The problem is not that the threat is real; the problem is that this is being done even though the threat is real.

The Same Week's Three Documents

Now step back and look. From the same company, in the same week, three documents came out.

On Monday night the alignment researcher Evan Hubinger wrote that he puts the probability of AI wiping out humanity within a decade above 10 percent; the next day Jacob Coxon resigned, saying "they are gambling with our lives" (we wrote about it). On Tuesday the economics team published the scenarios page that calculates, in the extreme scenario, labour's share of national income falling from 60 percent to 45 percent and knowledge workers' wages falling 11 percent (we wrote about it). On Wednesday it emerged that the security team was monitoring, under the heading "threat," those who would react to these two stories.

If you read this as three separate stories you see a company's inconsistency: it warns with one hand, scales with another, monitors with a third. If you read it as a single process you see a division of labour. The economics team calculates the size of the discontent; the alignment team gives the discontent a legitimate language ("we are worried too"); the security team puts the carriers of the discontent on file. Capital models in advance the reaction it will itself produce, and files it in advance. This is not a contradiction; it is a mature form of management.

Recall Amodei's diagnosis of 15 August: "ordinary people don't trust companies, governments, or the tech industry and always suspect that we are cooking up some new way to screw them over… this is fundamentally a crisis of trust." The company reads the distrust as a misunderstanding. But the thing that produces the distrust sits in its own economics team's table: the share will go to capital. The company chooses to manage not this cause, but the carriers of the cause. Hiring an intelligence specialist as the answer to a crisis of trust is treating the fever, not the disease.

One further detail: Anthropic's own Usage Policy forbids customers from using Claude for "predictive policing." What is forbidden to the customer has been written into the job posting as the company's own security doctrine. This is the plainest example of what we called, in the human-rights piece, "ethics notices added under the code": ethics is a product feature sold outward; inside, other rules apply.


From Palantir to Anthropic: The Same Bloc, the Same Tool

In August, while reading Palantir's manifesto, we said "the tools have changed, the class purpose has remained the same." We positioned Palantir as the hard face of the monopoly bloc, Anthropic as the "responsible" face. This story shows the following: even the tool is the same. Open-source intelligence, person-of-interest files, predictive threat management, routine information-sharing with the police: these are a scaled-down in-house version of the service Palantir sells to the state. The difference is scale and customer, not logic.

The next step Boguslaw points to is more important. The AI lobby wants the Trump administration to designate data centres and AI infrastructure as "critical infrastructure," the same status as water, electricity, and communications. If that happens, two things happen at once: the companies gain access to federal intelligence products, and anyone who opposes the infrastructure is drawn into the definition of a "threat to critical infrastructure." In the United States today there are bipartisan coalitions forming in towns against data centres; ordinary people fighting over water use, electricity bills, and land. Critical-infrastructure status turns those people into extremists with a single word.

This is a mechanism young comrades reading from Turkey know very well. With the expansion of the definition of "terror," first armed action, then verbal support, then a social-media post, then a municipal council seat, then the trustee went into the same sack. The expansion of a definition looks like a legal technique; its function is to narrow the legitimate field of opposition. The AI monopolies' demand for "critical infrastructure" is the digital form of the same technique, and tomorrow a neighbourhood association that opposes a data centre may find itself inside that definition.

The Panopticon's Doorkeeper

Now let us come to the week's least-discussed story; the story Boguslaw saved for the last paragraph of his piece.

On 2 September in San Francisco, the SEIU-USWW union, representing fourteen thousand security guards, held a strike-authorization vote (KQED). These workers guard the buildings of Anthropic, OpenAI, Google, Nvidia, Salesforce, and Cisco through contractors such as Allied Universal and Securitas. Their hourly wage is $22; their demands are $30, employer-paid family health insurance, and a pension. The employer's offer: a total raise of 25 cents over four years, with three of those years at zero. Union president David Huerta asked at the rally: "Who can survive with $22 an hour in San Francisco?" The guards chanted "Shame!" When the strike threat arrived, what did Anthropic do? It closed the building and sent employees an email telling them to work from home.

Let us read this table once more, slowly. Two hundred and thirty thousand dollars a year for an intelligence specialist to keep the executive away from protesters. Twenty-two dollars an hour for the worker who actually protects the executive, who is the first to meet the man who enters the lobby with a threat, who holds the door. The intelligence specialist is hired; when the door guard unionises, the building is closed. The panopticon sees the protester an hour in advance but does not see its own doorkeeper's strike; because the panopticon is built to look outward, not at the class relation inside itself.

This is the company-scale form of the asymmetry we named for the state in the İHD report piece: present in the square, absent in the factory. Against the activist outside, the company is proactive, predictive, preventative; against the worker inside, 25 cents. In Marx's words, capital sees every threat directed at itself and does not see only its own relation of production; because that relation is not a threat, it is capital itself.

And notice this: inside all this week's noise — a 10 percent extinction probability, 32 percent growth, a superintelligence ban bill, the filing of activists — the only organised workers' action is this. Activists go on hunger strike, a researcher resigns, a senator drafts a bill; none of them could close a building. The strike vote of fourteen thousand door guards did. A clearer lesson in where class power sits is hard to find.

In the Same Week, Who Did What, and What Happened?
SubjectActionThe company's responseResult
Alignment researcher (Coxon)Resignation, public warningSilenceThe narrative did not change; the seat was filled
Activists (Stop AI, Pause AI, local groups)Protest, hunger strike, sit-inMonitoring, person-of-interest file, police reportWritten into the "threat" category
Politicians (Sanders and others)Announcement of a superintelligence ban billSilenceNo one addressed labour's share
Claude userThreatening language in a chatReported to police; evidence not sharedAccount closed
Security guards (SEIU-USWW, fourteen thousand workers)Strike-authorization voteBuilding closed, everyone sent homeThe company effectively stopped

The table's last row is, by itself, the thesis of the piece.

Our Class Position

First, we reject violence against executives, and we say so as a matter of principle. A Molotov is not class struggle; it is the greatest gift to those who want to throw class struggle into the sack labelled "terror." It is precisely this kind of action that legitimises capital's surveillance apparatus.

Second, we oppose the writing of "activism" as a threat category. A company's securing itself and its categorically filing social opposition are different things, and the job posting does the second. This is not only the problem of AI opponents; it is the problem of anyone who will tomorrow oppose a data centre, a rise in the electricity bill, a layoff.

Third, we expose the "critical infrastructure" move now, in advance. If AI infrastructure is genuinely critical, then that critical infrastructure sitting in the hands of a private monopoly is the problem itself; the solution is not to terrorise opposition, but to bring the infrastructure under public and democratic control. What we defend for water and electricity holds for the data centre as well.

Fourth, we reject once more the "responsible monopoly" narrative. The same company's economics team, alignment team, and security team are departments of a single enterprise; the honesty of one does not change the function of the other. The difference between Palantir and Anthropic is a difference of style.

Fifth, and most important: this week we saw where power sits. What closed the building was not a resignation, not a hunger strike, not a bill; it was the door guards' union. The subject of the struggle against the AI monopolies is the workers who actually run those monopolies' buildings, data centres, supply chains, and code. The alliance between the computing worker and the door guard — what we called, in the Computing Worker's Handbook, the "alliance ring" — is not a wish; it is this week's concrete lesson.

Concrete Tasks

There is some work for the young comrades who read this piece. First, follow SEIU-USWW's strike process and tell people around you about it; this is one of the first examples, in the AI debate, of a workers' action stopping a monopoly, and it needs to be known. Second, in your own workplace or your own room, ask for the "security policy" and "threat definition" documents; look at where the word "activism" appears, because this language is imported. Third, follow under what legal status data-centre investments arrive in Turkey; a designation of "critical infrastructure" or "strategic investment" is the first step in the narrowing of opposition. Fourth, when you speak with AI-opposition movements, insist on nonviolence and on a class axis; a movement that targets property rather than the machine is also more resistant to being put on file. Fifth, read this piece together with the scenarios piece; one tells where the share will go, the other what will happen to those who object to the share.


Dear Young Comrades, Bentham's panopticon was a prison design in which a watchman could see everyone and no one could see the watchman. The digital panopticon does the same thing with software: it sees the protester an hour in advance, carries the user's chat to the police, writes the activist into the same column as terrorism. But every panopticon has a doorkeeper, and the doorkeeper is also a worker. This week that doorkeeper reminded us that he works for $22 an hour, and the building closed. The one thing the watchman could not see was who was holding his own door.

Knowledge belongs to everyone.


Sources

Earlier Knowledge Commons pieces on which this piece is built:

Related Posts