Knowledge Commons
HomeAboutGuidesPopularContact

"We Stopped Them All": A Monopoly's Grammar of Self-Absolution

Reading Anthropic's Threat Intelligence Report Announcement Through a Class Lens

Author: Oğuz Demirkapı
"We Stopped Them All": A Monopoly's Grammar of Self-Absolution

"We Stopped Them All": A Monopoly's Grammar of Self-Absolution

Reading Anthropic's threat-intelligence report announcement through a class lens

Dear Young Comrades,

On the evening of 10 September 2026 Anthropic published a four-paragraph statement on X and announced its 154-page threat-intelligence report. The statement was viewed more than thirty-five million times.

The next day in Turkey only one detail was discussed: the Istanbul-based company named in the report, and its operation aimed at the Malaysian elections.

We wrote about that detail separately yesterday. Today we will do something different. We will look not at the report, but at the announcement of the report. Because these four paragraphs are almost a textbook example of how monopoly capital absolves itself. And learning to take texts of this kind apart is a more lasting gain than learning any single case.

A warning to begin with: the criticism below is not a defence of the company that manipulated voters in Malaysia. That a structure producing voter profiling, an army of fake accounts, and fabricated intelligence dossiers has been stopped is a good thing. Our problem is not the act of stopping, but who holds the authority to stop, and how that authority is narrated.


I. The text

First the statement itself. Four paragraphs, about one hundred and thirty words:

"We're publishing our most detailed threat intelligence report to date. The report describes people's attempts to misuse Claude — for cyberattacks, influence operations, surveillance, biology, and weapons development — and how we found and stopped them.

We disrupted every operation in the report and used the lessons we learned to strengthen our safeguards. Where appropriate, we shared our findings with authorities and other AI companies.

These cases aren't typical: we're highlighting some of the most sophisticated misuse we've seen. But they're especially important to discuss, because they show us where AI misuse is heading, where our safeguards work, and where they need to improve.

We're publishing this report so that others can spot the same activity on their own platforms, and so that we can offer the public a clearer view of how emerging threats are developing."

Now let us look at the grammar of this text. Because ideology is usually hidden not in the claims, but in how the sentence is built.


II. "Misuse": Who draws the line?

The key word in the statement is "misuse." An innocent-looking word. Yet every concept of "misuse" logically presupposes a "proper use." And the real question is this: who draws that line?

The answer is plain: the company. Alone. Without the approval of any public body, any international institution, any workers' organisation, or any representative organ of users.

This unilateral power to draw the boundary condemns the five items on the list (cyberattack, influence operation, surveillance, biology, weapons) while quietly legitimising everything that is not on the list. The report counts "surveillance" as a category of misuse; but the same company's contracts with defence and intelligence agencies appear not in the threat report, but on the balance sheet. Software that performs the same function becomes either a "threat" or an "enterprise solution," according to who the customer is.

This is not an inconsistency. It is the natural result of property. Whoever draws the line also decides which side of the line they stand on. We saw the same mechanism when we wrote about the Palantir manifesto: the tool is the same tool; the difference is in the licence.


III. "We found them and we stopped them": A one-person rule of law

Attend to the second sentence: "how we found and stopped them." And the second paragraph: "We disrupted every operation in the report."

There is a subject here, and that subject is the agent of every verb: the one who finds, the one who investigates, the one who decides, the one who punishes, the one who announces the result, and again the one who confirms that the announcement is true.

The five-hundred-year gain of modern law — the separation of the accusing authority from the deciding authority — is absent here. The company is at once police, prosecutor, judge, executioner, and press office. The ledger in which the account is kept is also its own ledger.

I am not saying this as "the company is ill-intentioned." What I am saying is structural: a private company's becoming, on a global scale, the final and unappealable decision-maker over who may use which tool is private sovereignty. And private sovereignty, however well-intentioned its use, is arbitrary because it is closed to public oversight. The mechanism that today shuts down a voter manipulator can tomorrow shut down a strike organiser; there is no difference of procedure between them, only a difference of preference.


IV. "Every operation": The epistemology of statistics

The sentence "We disrupted every operation in the report" reads as if it were announcing one hundred percent success. Look carefully, though: in the report. That is, all of those they were able to detect.

This is statistics' oldest trick: to pronounce on a ratio in a place whose denominator you cannot see. What you could not detect is, by definition, not in the report. "We caught all of those we caught" is a tautology; its information value is zero, but its rhetorical value is high.

The report itself is more honest than the announcement on this point. There is a sentence in the text: "Our visibility into these operations ends once it's live." And they say that for verification they rely on "open-source research, cross-platform industry data, and public reporting."

That is: the company sees the construction stage on its own platform; it does not see the result. This is a real limitation, and it is written honestly in the report. In the announcement that limitation has vanished, and in its place stands the victory of "we stopped them all."

This is how corporate communication works: the report goes on the record, the announcement is read. Thirty-five million people saw the announcement; how many opened the report's 154 pages?

Incidentally, when we read TÜİK's labour-force figures we used exactly the same method: the gap between the narrow definition and the broad definition gave away the ideological function of the statistic. The number does not lie; the frame of the number does.


V. The condition of seeing: The panopticon

Now let us come to what the statement does not say, but is obliged to say.

What is required in order to detect that someone has set up a fake news site, profiled electoral constituencies along axes of race and religion, and prepared a fabricated intelligence dossier? You have to read what they wrote. In the report's own words: "Actors use AI to plan their campaign, choose their targets, and write the material. Those types of tasks produce signals that our systems are trained to detect."

Read the sentence the other way round: The systems have been trained to classify what users are doing. This is not a side function; it is the architecture itself.

Ordinary users' first reaction in the replies beneath the announcement was exactly this: "So our data wasn't as private as we thought." That reaction is not naïve; it is correct. The report is as much an inventory of surveillance capacity as it is the announcement of a security success.

And here we need to connect this to a week earlier. The news of Anthropic's activist monitoring system and this report came out in the same month. The two do not contradict each other. They are two faces of the same apparatus. On one side, "systems that detect malicious actors"; on the other, the monitoring of trade unionists who will protest in front of the company's own building. Technically the same job: turn behaviour into a signal, classify the signal, intervene according to the classification.

The difference is in the intention, not in the architecture. And intention changes when property changes; the architecture remains.

The digital panopticon we named in the frame of The Expropriation of the General Intellect is precisely this: not knowing whether you are being watched is enough to regulate behaviour as if you were being watched.


VI. "We shared them with the authorities": Private accumulation, public coercion

"Where appropriate, we shared our findings with authorities and other AI companies."

There are two separate things in this sentence, and both matter.

First: the authorities. Which authorities? The authorities of the jurisdiction in which the company sits. That is: intelligence gathered on a global scale flows to the institutions of a single state. This is the most classical schema of the imperialist epoch: the private company supplies accumulation, the state supplies coercion, and between the two there is a constant circulation of information and personnel. The only new thing is that this flow can be presented under the name of a "security report," and as a virtuous gesture.

Second: other AI companies. Regular intelligence-sharing among rival firms. Competition in the product market, coordination in the field of security. Writing on Coxon's resignation we said "the pacing agreement is in fact a cartel." The same logic holds here: the sector's developing a common definition of threat, a common blacklist, and a common practice of exclusion is not a technical collaboration; it produces a barrier to entry. Who will count as a legitimate actor in this market is decided by the actors already in the market.


VII. "These cases aren't typical": A caveat with a double function

The caveat in the third paragraph looks at first glance like humility. It is not. It does two jobs at once:

It protects the product. To say "not typical" is to say "the millions of people who use Claude are ordinary people; our product is safe." The report strengthens the product's reputation instead of damaging it.

It inflates the threat. To say "the most sophisticated misuse we've seen" is to announce that the danger is extraordinary. Extraordinary danger requires an extraordinary watchman.

When the two work together, this is what comes out: security is a second commodity sold alongside the model. The firm that describes the threat and the firm that says it will protect you from it are the same firm. Imagine a market in which the insurer keeps its own fire statistics; that is exactly what is happening here.

We can apply here the four questions we used when we read the GPT-6 Astra launch: What is being sold? From whom was it taken? To whom is it being sold? Who pays the cost? What is being sold in this report is reliability. The place it was taken from is users' conversations. The place it is sold is regulators and corporate customers. Those who pay the cost are the user who loses their privacy and the low-waged moderation worker who sifts the content.


VIII. "A clearer view for the public": The people as spectator

The subject of the last paragraph is again the company; the public is the object: a "clearer view" is offered to it.

Attend to this form of transparency. The people here are neither regulator, nor party, nor overseer. They are a spectator. How much they will see, which cases will be told, which code-name will be given, which customer's name will not appear: the company behind the scenery decides.

This is not transparency; it is a performance of transparency. Real transparency is the owner of the information being obliged to give it. Here the information is given at the giver's discretion and on the giver's timetable. The difference is the difference between bread begged for and wages earned.


IX. The missing category: The company itself

The report recounts nine influence operations: actors sourced from Russia, Iran, Turkey, the Gulf, South Asia, and Africa; plus a France-based advertising agency (about seventy fake news sites, more than 8,900 articles in twenty languages) and a French hacktivist. On the cyber side, Russian intelligence, Chinese undergraduate students, ShinyHunters affiliates.

The list cannot be reduced to a simple West/East split — the French cases are named as well. But there is a structural gap, and it needs to be named: states in the position of customer cannot be on this list. Because they do not "misuse"; they buy. Defence and intelligence contracts are not the subject of the threat report; they are the subject of the income statement.

A threat report is, by definition, a map of the outside. It cannot map the inside. This does not mean the report is a lie; it means it cannot be complete. And the direction of the incompleteness is not random: it always points outward from the boundary drawn by property and by contract.


X. The image in the mirror: BBS and Anthropic

The most instructive part of the report is the resemblance it establishes without noticing.

The marketing language of Istanbul-based BBS Bilişim was this: "military-grade, AI-driven, real-time political operations ecosystem." About a thousand fake accounts, a fake news site called "Malaysia Pulse," the profiling of 222 constituencies along the race-religion-monarchy axis, fabricated dossiers against the opposition, a request on a dashboard for "one million artificial views in favour of the sitting prime minister." Anthropic counted this operation as Category Two on the Breakout Scale: it appeared on more than one platform, but there is no evidence that it reached a genuine audience.

Now set the two companies side by side. One sells the capacity to operate on a population without a licence; the other sells the same capacity under licence and then adds a "safe use" layer on top. The difference between them is not qualitative; it is legal. BBS is the unlicensed dealer.

This is also how we see part of what a threat report is for: market discipline. Liquidating the unauthorised seller consolidates the position of the authorised seller. This does not mean that stopping the operation was not a good thing; it means that the act of stopping was at the same time a market move.


XI. A finding that deserves its due

Criticism is not blindness. One finding in the report deserves to be taken seriously, and it cuts against the company's own marketing:

Most of the influence operations described did not reach a genuine audience. The French agency's 8,900 articles drew almost no engagement; the Malaysia operation stayed in Category Two. That is: artificial intelligence collapsed the production cost of fake content, but it did not solve the problem of credibility and distribution. What got cheaper is content; what remains scarce is trust.

This is solid evidence against both the panic that "AI is ending democracy" and the industry's own apocalyptic discourse that feeds that panic. As we said in the piece on the 2030 scenarios: a disaster narrative is the cheapest way to inflate the importance of the product being sold. Even the data of its own threat report does not fully confirm that narrative.


XII. Two columns: What the statement says, and what it says in class terms

What the statement saysWhat it says in class terms
"People's attempts to misuse Claude"The owner draws the boundary of proper use with no public oversight. Everything not on the list is legitimised.
"How we found and stopped them"Police, prosecutor, judge, and press office are a single private company. Private sovereignty is arbitrary because it is closed to public oversight.
"We disrupted every operation"All of those detected were detected — a tautology. The report itself says "our visibility ends once it's live."
"Signals that our systems are trained to detect"The condition of detection is the continuous classification of user behaviour. A security success is at the same time a surveillance inventory.
"We shared our findings with the authorities"Private accumulation on a global scale flows into a single state's apparatus of coercion. The classical schema of the imperialist epoch.
"Shared them with other AI companies"Competition in the product, coordination in security. A common blacklist produces a barrier to entry — cartel logic.
"These cases aren't typical"It protects the product and inflates the threat. Together they turn security into a second commodity.
"The most sophisticated misuse"Extraordinary danger requires an extraordinary watchman. The insurer is keeping its own fire statistics.
"A clearer view for the public"The people are not the regulator; they are the spectator. Not transparency, but a performance of transparency.
"So that others can spot it on their own platforms"The sector's common definition of threat installs a regime in which existing actors decide who the legitimate actor is.

XIII. The labour inside this fight

And now let us come to the subject that never appears in this whole narrative.

Who wrote the file fake_news_3.py? A waged programmer. Who ran a thousand fake accounts? Shift operators. Who built the profiles of 222 constituencies? A data analyst. On the other side, who trained the classifiers that catch those signals? Trust-and-safety teams, largely on subcontract, most of them in Nairobi, Manila, Lisbon, low-waged workers who spend eight hours a day looking at humanity's worst content.

That is: there is waged labour on both sides of this conflict. Neither the attack apparatus belongs to those who attack, nor the defence apparatus to those who defend. Both belong to capital. And the data that trains the classifiers is, as we have written more than once, the general intellect expropriated from all of our collective mental labour. Our own crystallised labour is working as a detection apparatus turned against us, and we hold no share in it.

Let us close a misunderstanding: that a programmer worked on such a project does not make them innocent. Professional ethics is a real thing, and "I only wrote the code" is not a defence. But individual responsibility and structural responsibility must not be confused. A discussion that ends by shaming individual developers is exactly the discussion capital wants: a discussion in which the culprit is spoken of in place of the system. We insisted on this in The Computing Worker's Handbook — the only real condition of a computing worker's being able to say "no" is not conscience alone, but the organisation behind them.


XIV. Concrete tasks

For computing workers:

  1. Write the right of refusal into the contract. A clause of "refusal to work on an unethical project" turns individual heroism into a collective guarantee. There are examples in the statutes of international computing unions; it should enter the list of demands in Turkey.
  2. An in-house whistleblowing channel. What is needed is not the company's own "threat report," but an independent workers' channel. Without union legal protection, whistleblowing is individual suicide.
  3. Make trust-and-safety work visible. Moderation and security labour is the most invisible and the most damaged branch of computing labour. It should be taken into the centre of the organising agenda.

For unions and professional organisations:

  1. Demand that oversight be made public. A regime in which a company oversees itself is not accepted in workplace safety; it should not be accepted in digital infrastructure either. The demand for an independent, public oversight body with workers' representatives on it is a concrete political demand.
  2. Follow the definitions of "terrorism" and "critical infrastructure." How threat categories widen is also a warning of how union activity will be criminalised. These definitions are not technical; they are political.

For young comrades:

  1. The habit of reading corporate texts. When you read a company statement, ask three questions: Who is the subject of the sentence? Which category is missing from the list? Were they obliged to give this information, or are they boasting because they gave it? These three questions are enough for you to reproduce this entire piece on your own.
  2. Look at the report, not the announcement. The source text is always more honest than the corporate summary. 154 pages is long; but the sentence the announcement conceals is inside those 154 pages.

XV. Conclusion: Who appointed the watchman?

Most of the events this report recounts really happened. The operations that were stopped really were stopped. That a lock was put on the door of a company that profiled voters and produced fabricated dossiers is a good thing, and to deny this is not criticism but obstinacy.

But history taught us this: that a power is being used well does not abolish the question of who ought to hold that power. On the contrary, it makes the question more urgent. Because power that is used well becomes institutionalised; institutionalised power changes hands; power that changes hands does not look at whose hands it is in.

Today we face a monopoly that holds in private property an apparatus produced from the collective mental labour of billions of people, that decides alone what anyone may do with that apparatus, that accounts for its decisions in reports it prepared itself, and that narrates this situation as "offering the public clarity."

Our question is not "are they behaving well." Our question is this:

Who appointed the watchman? Who oversees the watchman? And why is the watchman's watchman never spoken of?

The answer to this question is not technical; it is political. And political questions are answered not by reports, but by organisation.

The product of labour belongs to labour. The general intellect belongs to everyone.

Knowledge belongs to everyone.


Sources

Related pieces from the blog:

Related Posts