AI 기업 앤스로픽이 AI 급속 개발에 반대하는 활동가들을 감시하기 위해 광범위한 모니터링 시스템을 구축하고 있으며, 사전 예측을 통해 사건 발생 전에 경찰에 신고하는 '프리크라임' 방식까지 도입한 것으로 드러났습니다. 이는 '책임 있는 AI 기업'을 표방해온 앤스로픽의 이미지와 정면으로 배치되며, 시민 자유 침해 우려를 불러일으킨다는 점에서 중요합니다.
번역된 본문
채용 공고와 앤스로픽 고위 보안 책임자들의 인터뷰에 따르면, 이 프론티어 AI 연구소는 AI의 급속한 개발에 반대하는 활동가들을 감시하기 위한 광범위한 모니터링 시스템을 구축하고 있다. 앤스로픽 임원 근처의 활동가를 감시하고 앤스로픽 물리 자산 인근 시위를 추적하는 것 외에도, 이 회사는 사건이 발생하기 전에 예측하려는 '프리크라임(pre-crime)' 방식도 구현하고 있다. 경우에 따라 범죄가 발생하기 전에 용의자를 경찰에 신고하는 것을 의미하기도 한다. 앤스로픽은 더 프로스펙트(The Prospect)의 논평 요청에 응답하지 않았다.
앤스로픽의 반대자 감시 계획은 '책임 있는 OpenAI의 대안'으로 자신을 포지셔닝하려는 회사의 노력과 배치된다. 올해 초, 국방부와 앤스로픽은 국내 대규모 감시 및 자율 무기에 앤스로픽 도구 사용을 허용하지 않겠다는 앤스로픽의 거부를 두고 공개적인 갈등을 빚은 바 있다. 그러나 앤스로픽이 '국가 안보 영업' 직책 채용을 진행하며 군사 계약을 재개하려 함에 따라 이 긴장은 완화된 것으로 보인다. 국내 반대 세력에 대한 위협 모니터링 강화는 국가 안보에 대한 재집중과 맞닿아 있다.
앤스로픽의 감시 체계 일부는 작년 앤스로픽 글로벌 보안 운영센터(GSOC) 매니저 키온 엘리슨(Keon Ellison), 보안 운영 매니저 잭 멜빈(Zach Melvin), 그리고 앤스로픽이 위험 탐지 용역을 계약한 회사인 샘데스크(Samdesk)의 CEO 제임스 뉴펠드(James Neufeld) 간의 팟캐스트 인터뷰에서 드러났다. 위협 모니터링과 분석에 관한 폭넓은 대화에서 이 인터뷰는 활동가 감시도 다룬다.
엘리슨은 "작년에 한 임원이 대도시로 출장을 갔을 때 계획된 시위에 관한 정보를 샘데스크를 통해 받았다"고 말했다. 원래 예정됐던 시위는 허가 문제로 앞당겨졌다. 엘리슨은 "샘데스크가 시위 주최 측이 일정을 앞당겼다는 사실을 약 60분 전에 알려줬다"고 설명했다. "그 한 시간이 결정적이었다. 그렇지 않았다면 우리 임원들은 회의를 마치고 곧장 소란의 한복판으로 걸어갔을 것이다." 엘리슨에 따르면 앤스로픽은 이 데이터를 활용해 해당 임원을 위한 우회 경로를 마련하고 호텔의 서비스 출입구로 안내했다. 그는 "고스트레스 상황이 될 수 있었던 일이 샘데스크를 통한 조기 탐지 덕분에 실질적으로 완화됐다"고 말했다.
앤스로픽은 전국 경찰서에 위협에 관한 정기 보고를 시작했으며, 7월 월스트리트저널에 "'관심 인물(person-of-interest) 프로세스'를 통해 우려되는 행동을 시간의 흐름에 따라 추적해 격화 패턴을 조기에 포착할 수 있다"고 밝혔다. 월스트리트저널에 따르면 "경찰에 신고된 사건에 관련된 여러 개인은 이미 앤스로픽 보안의 추적을 받고 있었다."
지난달 샌프란시스코 스탠다드(The San Francisco Standard)는 앤스로픽이 클로드(Claude)에게 자신이 AR-15 반자동 소총을 구매했으며 CEO 다리오 아모디(Dario Amodei)를 '조준하고 있다'고 말한 남성을 샌프란시스코 경찰에 신고했다고 보도했다. 해당 남성은 신문에 연락받았을 때 "그냥 농담한 것"이라고 말했다. 그런데 앤스로픽이 불만을 품은 클로드 사용자를 경찰에 신고하는 데는 신속했지만, 스탠다드는 핵심적인 세부 사항도 보도했다. 앤스로픽은 내부 정책을 이유로 경찰에 실제 메시지 공개를 거부했다. 요컨대, 앤스로픽은 플랫폼 내 발언을 이유로 사용자를 신고한 뒤 실제 잘못에 대한 증거는 경찰에 제공하지 않은 것이다.
이러한 적법 절차 없이 권장되는 프리크라임 경찰 활동은 프로스펙트가 검토한 팟캐스트에서 앤스로픽 보안 프로그램 매니저가 명시적인 목표로 언급했다. 그는 "목표는 대응적 정보 수집에서 벗어나 능동적·예측적·예방적 위협 대응 및 관리로 운영을 전환하는 것"이라며 "그것이 모든 산업에서 고가치 표적을 보호하는 데 합리적인 운영 성숙도"라고 덧붙였다. 앤스로픽의 노력은...
Job postings and interviews with senior security officials at Anthropic show that the frontier AI lab is building out an extensive monitoring system to keep tabs on activists who oppose the rapid development of artificial intelligence. In addition to monitoring activists in the vicinity of Anthropic executives and keeping tabs on protests near physical Anthropic assets, the firm is also implementing a “pre-crime” approach, attempting to predict incidents before they happen. In some cases, that also means reporting suspects to police before a crime occurs. Anthropic did not respond to the Prospect ’s request for comment. Anthropic’s plans to surveil dissent are at odds with the firm’s efforts to cast itself as the responsible alternative to OpenAI. At the beginning of the year, the Department of Defense and Anthropic engaged in a high-profile dustup over Anthropic’s refusal to allow the military to use its tools for mass domestic surveillance and autonomous weapons. That tension seems to have eased as Anthropic hires for “national security sales” positions, seeking to restart military contracts. The increase in threat monitoring of domestic opponents fits with a renewed focus on national security. More from Daniel Boguslaw A piece of Anthropic’s surveillance architecture was revealed in a podcast interview from last year between Anthropic Global Security Operations Center Manager Keon Ellison, Security Operations Manager Zach Melvin, and James Neufeld, CEO of Samdesk, a company Anthropic contracts with for risk detection. In a wide-ranging conversation about threat monitoring and analysis, the interview also touches on monitoring activists. “Last year we had an executive travel into a major city when we received some intelligence through Samdesk about a planned protest,” Ellison said. The originally scheduled protest was moved up due to permitting issues. “Samdesk gave us about 60 minutes of advanced notice that the protest organizers had moved the timeline,” Ellison explained. “That extra hour was critical. Without it our executives would have departed their meetings, they would have ran right into the heart of the disruption.” Ellison said that Anthropic used this data to devise an alternate route for the executive and funnel them to a service entrance at the hotel. “What could have been a high-stress situation,” he said, “was really mitigated through early detection through Samdesk and giving us that information.” Anthropic has begun making routine reports to police departments across the country for threats, and told The Wall Street Journal in July, “We track concerning behavior over time through a person-of-interest process, allowing us to catch escalation patterns early.” According to the Journal , “several individuals involved in incidents reported to police were already being tracked by Anthropic security.” Last month, The San Francisco Standard reported that Anthropic had reported a man to San Francisco police for telling Claude that he had bought an AR-15 semiautomatic rifle and had CEO Dario Amodei “in his sights.” When the Standard contacted the man in question, he told the newspaper he was “just fucking around.” But while Anthropic was fast to call the cops on a frustrated Claude user, the Standard also reported a key detail: Anthropic refused to show police the actual messages, citing Anthropic’s internal policy. In short, Anthropic reported a user for in-platform speech, and then refused to provide police with evidence of actual wrongdoing. This kind of pre-crime policing, encouraged without due process, is referenced as an explicit goal by Anthropic’s security program manager in the podcast reviewed by the Prospect . “The goal would be transforming operations from reactive information to gathering proactive and predictive and preventative threat engagement and management,” he said, adding, “That’s the kind of operational maturity that makes sense for protecting high-value targets in any industry.” Anthropic’s effort to build a predictive security apparatus extends beyond the C-suite to its Global Safety, Intelligence, and Security (GSIS) team, according to a job posting from last month detailing Anthropic’s search for an enterprise intelligence specialist who “will investigate specific threats, actors, and events, produce finished assessments, and help keep Anthropic’s employees ahead of a rapidly evolving threat landscape and in a defensible position.” Part of that role, compensated at between $180,000 and $230,000, will be to “identify, assess, track, and investigate global threats including geopolitical instability, terrorism, crime, activism , nation-state targeting of the AI sector, and emerging security trends, including deep-dive research and OSINT collection on specific threats, actors, and events” (emphasis added). The expansion of Anthropic’s intelligence-gathering to a national and even global scale tracks with recent efforts to heighten the labeling of AI and the infrastructure powering it, including data centers and power supply. A critical infrastructure designation would put artificial intelligence on the same footing as water, electricity, and broadband. And indeed, AI’s boosters like Americans for Responsible Innovation (ARI) have urged the Trump administration to make the change. Per ARI’s telling, AI is “so vital to the United States that the incapacity or destruction of such systems and assets would have a debilitating impact on security, national economic security, national public health or safety, or any combination of those matters.” Enshrining frontier labs in the hardened cloak of national security would not only give Anthropic, OpenAI, and Google even more access to intelligence products generated by federal law enforcement and intelligence agencies; it would also embolden these companies to shape how federal agencies view threats to their bottom line, now transformed as “critical infrastructure.” It’s not hard to imagine how civic engagement by the same bipartisan coalition opposing data centers could turn its focus onto AI, only to be branded in the same instant as extremists or, even worse, terrorists. Anthropic’s answer to this problem has been to work even harder at producing artificial intelligence that can deliver services that can’t be brushed aside by the public. “I do agree that the public has a negative view of AI (and that this is a big problem), but I don’t think it is primarily caused by me or any other AI leader warning about AI’s risks,” Anthropic CEO Dario Amodei wrote on Twitter last month. “I think it is fundamentally a crisis of trust … I think that ordinary people don’t trust companies, governments, or the tech industry and always suspect that we are cooking up some new way to screw them over.” As Anthropic ramps up its efforts to monitor dissent with in-house intelligence teams and real-time protest tracking powered by AI, it will have to contend with the increasing economic desperation that plagues human beings outside its Bay Area towers. Last week, the security guards who patrol the campuses of OpenAI and Anthropic announced that they had authorized a strike over stalled pay negotiations. In response, Anthropic sent a company-wide email telling employees that it was best if they worked from home. “Who can survive with $22 an hour in San Francisco?” David Huerta, president of SEIU-USWW, the union representing security guards in the Bay Area, said at a rally last week. Around him, security guards chanted: “Shame.” Related Daniel Boguslaw Daniel Boguslaw is an investigative reporter based in Brooklyn. More by Daniel Boguslaw