Disclosure first: this show is made with Claude, built by the company at the center of this story. Anthropic has no involvement in it, and the voice is a text-to-speech model from another vendor. In September 2026 The American Prospect reported that Anthropic is building a system to monitor anti-AI activists. Anthropic answered once, to CNET: it is not, and has never said it is, building a predictive surveillance system to monitor activists; this is a physical-security function, the same as any large company. This episode reads the documents instead of the adjectives. Start with two requests for the same three facts. A Chinese state security bureau asked Claude for a protest's gathering point, route and end time; Anthropic banned the account and filed the case in the surveillance chapter of its own threat report. Three months earlier, at a sponsored webinar the coverage called a podcast, Anthropic's managers described a vendor warning them that a protest near a traveling executive had moved up an hour. Same information, two different files. What is public: that webinar, two job postings, one police report. The August 18th posting asks an analyst to track "geopolitical instability, terrorism, crime, activism." It came down August 25th, fifteen days before the story ran, and the word was never removed. Ordinary for the trade. What is unusual is the brand. The tension is not a legal contradiction. The Usage Policy binds people who use Claude; Anthropic's own security team lives under other documents entirely. The fourth column, covering the vendor watching the sidewalk, is blank. Nothing public says what may be collected, on whom, for how long, or who decides. The reasons are real and dated — a co-founder expelled by his own group, an attempted-murder charge in April, a man in the lobby with an envelope five days later, an AR-15 message in August. So is the precedent: Amazon, Facebook's be-on-the-lookout list, TigerSwan, Monsanto. Six cases, two fines — both for paperwork. And the ledger nobody prints: Meta's proxy puts Mark Zuckerberg's security program at $25,125,903. The guards at the door work for a contractor at about $22 an hour. The hunger striker's letter to Dario Amodei reached the company through one of them. Plus what California law lets you ask for, in 45 days, free — and three dated calls. RELATED EPISODES AI Deanonymization: How Claude Identifies Writers from 125 Words What's Inside Anthropic's 186-Page Risk Report The Regulation Anthropic Asked For CHAPTERS 00:00 Two requests, one route 01:29 The word in the posting is activism 01:55 Disclosure, and how this episode is bounded 02:42 Anthropic's only answer 03:21 The documents everyone calls a leak 05:12 The two postings, read in full 07:27 The one police referral we can read 09:35 Four dated reasons the file exists 11:34 How big the threat picture actually is 13:31 Three rulebooks, and a blank fourth 14:52 Who each rulebook actually binds 16:45 Anthropic's own words about mass data 19:16 This has been written six times before 22:02 The ledger: two fines, both for paperwork 23:22 Two ends of one lobby 24:40 The office emptied before the vote 26:54 What the law lets you do about it 29:41 Our ledger, and three dated calls 31:08 The missing page SOURCES The American Prospect, Sept 9, 2026: https://prospect.org/2026/09/09/anthropic-artificial-intelligence-surveillance-system-monitor-activists/ CNET — Anthropic's only statement: https://www.cnet.com/tech/services-and-software/have-you-protested-ai-recently-anthropic-may-be-watching-you-for-precrimes/ Anthropic threat report, Sept 10, 2026 (vendor on page 84): https://www-cdn.anthropic.com/e50be2e51e7695dc4b1366a37a245a597377d3b5/Anthropic-Detecting-and-countering-091026.pdf The Aug 18, 2026 posting: https://jobs.accel.com/companies/anthropic/jobs/90264650-enterprise-intelligence-specialist SF Standard — the August 14th message and police referral: https://sfstandard.com/2026/09/04/anthropic-threat-claude-sfpd/