# The Watermark Is on the Tool, Not the Work
> [!metadata]- Metadata
> **Published:** [[2026-08-11|August 11, 2026]]
> **Tags:** #🌐 #artificial-intelligence #anthropic #ai-policy
![[00 - Meta/Attachments/anthropics-watermark-is-eu-compliance-theatre-hero.jpeg]]
Anthropic [confirmed this week](https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/) that Claude now weaves an invisible mark into the text it generates. There is nothing to look at. The signal sits in the word choices themselves, readable by machine, and it survives being copy-pasted into your email client. Generated files get separate treatment, with signed C2PA provenance metadata attached to PNG, JPG and SVG output. It covers the Claude app, the API, Claude Code, Cowork and Tag — everywhere Claude is sold.
The reason is Article 50 of the EU AI Act, which came into force on August 2 and requires providers of generative systems to mark synthetic output in a machine-readable way. Anthropic signed the Commission's Code of Practice on Transparency, and rather than ship one Claude for Europe and another for everyone else, it applied the European rule to the entire planet. Non-compliance runs to €15 million or 3% of global turnover, so the arithmetic isn't complicated.
I want to be precise about what I'm objecting to, because "I don't like watermarks" is a lazy position and I don't hold it. I'm not against provenance. I've argued before that [[Truth, Trust and the Evidence Dilemma|demanding evidence is the whole point]], and if there's a way to make published claims verifiable I'm interested. What I object to is this particular mechanism, sold as a fix for a problem it cannot reach — and the habit of governance that produced it.
This also isn't a reflexive swipe at Brussels from someone who'd wave through the American version. California passed a stricter provenance law than Europe's, starting the same day, and deliberately kept text out of it. I went looking for the American equivalent expecting to find one, and the absence turned out to be most of my argument.
## Nobody Asks Which App You Used
When someone shares a deck, nobody asks whether they built it in PowerPoint, Keynote or Google Slides. Nobody expects Grammarly to stamp the sentences it repaired, or Lightroom to own up to an exposure adjustment. The work gets judged as work.
The obvious objection is that PowerPoint doesn't write your slides. That's fair, and it's where the analogy starts earning its keep, because what Anthropic is marking isn't authorship. It's contact with the product.
Read the company's own [support page](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content). A detected mark "does not, on its own, confirm the full provenance of the content," because "Claude may not be the original author" and "the content may have changed after Claude processed it." That is the vendor telling you, in its own documentation, that the signal answers *did this text pass through our product* and not *who wrote this*. Which is the PowerPoint question, and I don't think anyone should be obliged to answer it.
## The Law Exempts what the Product Marks
[Article 50(4)](https://artificialintelligenceact.eu/article/50/) carves out an exemption where the system performs "an assistive function for standard editing" or "does not substantially alter" the input. The Commission's final guidelines list grammar correction, spellchecking, minor stylistic polish, and, added in the last revision, translation. Fix my typos, and the law says no mark is required.
But Anthropic marks at generation. Paste your own paragraph, ask Claude to tighten it, and what comes back is generated text. Your own sentences return carrying a machine-readable signal a detector will read as *Claude* — the exact scenario the company's caveat concedes in advance.
Anthropic hasn't published a specification, so I can't tell you where its threshold sits, or whether short edits fall below the detection floor. That opacity matters, and I'll get to it. What's already visible is the shape of the mismatch: a rule written with a sensible carve-out, implemented by a product that can't easily honour it, because a mark applied at the token level has no idea whose tokens came first.
## It Doesn't Work, and Everyone Involved Knows it
The stronger objection is that the mechanism fails on its own terms.
Text is a compressed medium. You cannot change a sentence in a way a reader won't notice, which is why image watermarking works and text watermarking is a much harder trick. The approach everyone seems to be converging on — Kieran Healy [reads Anthropic's vagueness the same way](https://bsky.app/profile/kjhealy.co/post/3mssgebulec2y) — is token biasing: at each step the model quietly prefers words that score well under a secret function, and a detector later checks whether a passage's aggregate score is improbably high. It's clever and cheap to run, and fragile in one specific way.
The fragility is that the signal lives in word choice, so replacing the words removes it. ETH Zurich researchers tested Google's deployed SynthID-Text and found ordinary paraphrasing tools [stripped the mark in over 90% of attempts](https://www.implicator.ai/anthropic-eu-watermarking-claude-worldwide/). DeepMind says plainly that SynthID "isn't a silver bullet." Anthropic's own page lists the escape routes: text that has been "heavily edited, paraphrased, translated, or mixed into other writing," and for files, metadata "stripped through format conversion, re-saving, screenshots, or other means." Open-source C2PA strippers already exist, as [Roopika Risam pointed out](https://bsky.app/profile/roopikarisam.bsky.social/post/3mssib53cps2d) within hours of the announcement.
There's a trap in the regulation itself, too. Article 50 requires marks to be interoperable and detectable by other systems, which means the scheme has to be published. Sean Goedecke's [argument](https://www.seangoedecke.com/text-ai-watermarks/) is that publishing it dissolves the security-by-obscurity the whole approach depends on, since once the function is known, removing the mark is a scripting exercise. For now nobody outside Anthropic can evaluate any of this, because as [Marcus Schuler noted](https://bsky.app/profile/marcus-schuler.com/post/3mssnpiqv562q), no technical specification or detection tool has been released for researchers to test. We are being asked to trust a transparency measure that is not itself transparent.
## Everyone Else Drew the Line at Images
The coverage keeps treating "AI transparency law" as one undifferentiated thing, which is how I nearly missed the most interesting part of this.
California's [AI Transparency Act](https://www.dataprotectionreport.com/2024/09/california-and-artificial-intelligence-watermarking-law/), SB 942 as expanded by AB 853 last October, is the most demanding provenance law in the United States. Covered providers must embed a hidden machine-readable disclosure in what they generate, offer users a visible label, and maintain a free public detection tool so anyone can check. From January 2027 the duty extends to large platforms, which have to read that provenance data and surface it to users. From 2028 it reaches camera manufacturers. It's a serious, well-built regime, and California deliberately moved its start date to August 2 to line up with Brussels.
And its obligations [apply only to image, video, or audio content](https://www.troutmanprivacy.com/2025/10/california-ai-transparency-act-amendments-signed-into-law/). Not text.
That isn't an oversight. California ran this exact argument two years ago. AB 3211, the Digital Content Provenance Standards bill, was the broader swing, putting watermarking obligations on providers and labelling duties on platforms with penalties attached. It cleared the Assembly 62–0 and drew [public support from OpenAI](https://thejournal.com/Articles/2024/08/27/California-AI-Watermarking-Bill-Supported-by-OpenAI.aspx), whose chief strategy officer framed it as helping people "avoid confusion between human-generated and photorealistic AI-generated content." Note the word *photorealistic*. The bill's own definitions section defined synthetic content as ["information, including images, videos, and audio, that has been produced or significantly modified by a generative AI system"](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB3211), with no text-specific provision anywhere in it. Even the maximalist bill, with the industry behind it, drew the line where the technology actually holds. It died in Senate Appropriations anyway, parked on the inactive file at the end of the 2024 session.
The rest of the American map tells the same story from a different angle. The state laws people file under "AI disclosure" are mostly a different species. Utah's SB 149 says that if you're being handled by a generative system you're entitled to be told, and Colorado's SB 24-205 requires systems built to interact with consumers to say what they are. Texas carries its own disclosure duties in TRAIGA. That's disclosure of an *interaction*, which is honest and cheap and works, because a chatbot announcing itself doesn't depend on a signal anyone can rewrite away. Then there's the election and non-consensual-imagery legislation, which targets synthetic media: again pictures and audio, where a watermark survives a re-encode and where the harm is impersonation of a real person.
Going by the state-by-state trackers, no US jurisdiction requires a watermark in generated text. The American laws either mark the media where marking holds, or disclose the interaction, or do both, and stop there. Some legislatures considered going further and scoped it out. One passed the maximalist version through a chamber and then let it die. The EU is out on its own — not because it saw something the others missed. It was the only one that didn't stop to ask whether the mechanism does what the mandate assumes.
There's a smaller irony inside this. California's law demands a free public detection tool as a condition of the marking regime, so that the claim can actually be checked. Anthropic has shipped the mark and says detection details are coming in "forthcoming technical documentation." So the half of the scheme that inconveniences users is live, and the half that would let anyone verify it is still a promise.
## Who it Actually Catches
The best counter I've read comes from novelist Lincoln Michel, who [points out](https://bsky.app/profile/thelincoln.bsky.social/post/3mssotzwjxk2r) that most people are lazy. He still sees chatbot prompts left in emails and student assignments, so even trivially removable friction would trip up the worst spammers. That's a real argument and I take it seriously.
I just think it gets the ledger backwards, because friction costs the two groups very differently. A spam operation generating ten thousand listings runs one cheap rewrite pass and pays nothing, and a phishing crew does the same. The people who actually get caught are the ones who weren't hiding: the student who used Claude to fix their grammar, or the non-native speaker who asked it to make an email sound less stiff. None of them are what Article 50 was written to catch. They're what it will catch.
Healy called it an authentication arms race, and in his thread he lands on where that goes, which is weirder prose and ever-higher levels of paranoia. That sounds about right to me. Being detectable starts to mark you as naive, avoidance becomes a skill, and we all get a bit more suspicious of each other's writing for no gain in truth.
## Two Governments, One Missing step
I keep noticing that this is the second time this year a government has reached into the tools I work in without doing the homework.
In June, the US Commerce Department [[The US Government Killed Anthropic's Fable 5 Sight Unseen|killed Fable 5 for the entire planet]] over a jailbreak claim it never reproduced or published — three days after launch, on a rival's say-so. In August, the EU mandated a marking scheme its own research community had already demonstrated paraphrasing defeats. Opposite instruments, same missing step: nobody stress-tested the remedy against the thing it was supposed to remedy.
There's a difference worth granting. Article 50 went through years of drafting and consultation, which the Fable 5 directive plainly did not, and that makes the outcome stranger rather than better. A hasty decision landing badly is ordinary. Years of consultation arriving at a mechanism the literature says doesn't hold is harder to explain. Somewhere in the drafting, "we must be seen to require marking" outran "does marking work."
I also can't fall back on nobody having known better, because the comparison is sitting right there. Legislatures with the same evidence, lobbied by the same companies, kept text out. The debate was available and Brussels didn't have it.
## Brussels Has Run This Play before
This isn't the EU's first swing at a transparency mandate that shipped its mechanism ahead of its evidence.
The cookie banner is the obvious precedent. The ePrivacy Directive in 2009, reinforced by GDPR in 2018, aimed at a genuine harm, since people had no idea who was tracking them. What it produced was a web where everyone clicks "accept all" without reading, trained by sheer volume to treat consent as an obstacle. The Commission now [concedes](https://www.osborneclarke.com/insights/digital-omnibus-reshapes-eu-cookie-rules-leaves-banner-fatigue-largely-intact) that "consent fatigue and proliferation of cookie banners" is a problem whose regulatory fix is "long-overdue." Sixteen years to admit the instrument backfired — and the Digital Omnibus meant to unwind it is itself being [attacked by privacy advocates](https://www.techpolicy.press/the-eus-digital-omnibus-must-be-rejected-by-lawmakers-here-is-why/) as a gift to Big Tech.
The shape repeats. You name a real harm, prescribe a mechanism visible enough to point at, and ship it, because doing something legible is politically cheaper than doing the hard thing. Then you spend a decade finding out the mechanism mostly taught everyone to route around it.
And because Anthropic chose one global implementation over a European carve-out, the rule now applies to me in Toronto, and to you wherever you are, decided by a body none of us voted for. That's the Brussels Effect working exactly as designed: one jurisdiction writes the rule and the rest inherit it through the product rather than through their own legislatures. California decided text was out of scope, twice — and its residents get the mark anyway, because a company in San Francisco found it cheaper to satisfy Brussels everywhere than to maintain two versions of Claude. The narrower, better-reasoned law loses to the broader one by default, and nobody votes on that. It's a fine outcome when the rule is good and a bad deal when the rule is theatre.
## Judge the Work
Content should be king. If a piece of writing is accurate, useful, and says something worth saying, the toolchain behind it is a matter of craft rather than disclosure. If it's wrong or empty, a watermark won't rescue the reader, who needed a better editor and not a better detector.
There is a good instinct buried in Article 50, and it isn't the marking. The regulation's public-interest-text duty falls away where a human holds genuine editorial responsibility. That's the right idea: put the obligation on the person who publishes and can be held to account, not on the instrument they typed with. Cryptographic signatures on published artifacts, attribution attached by whoever hits publish — those survive a paraphrase precisely because they were never hiding inside the words.
I've spent [[18 Months of Learning to Build Software with LLMs|the better part of two years building most of my software with these tools]], and I have no interest in pretending otherwise. Say so when it matters. Own what you publish. A norm like that holds weight in a way that a signal you can erase with one rewrite pass never will.
What we got instead is a mark on the hammer.
---
**Sources:**
- [Anthropic says it will watermark text generated by its AI models](https://techcrunch.com/2026/08/11/anthropic-says-it-will-watermark-text-generated-by-its-ai-models/) — TechCrunch
- [How Claude marks AI-generated content](https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content) — Anthropic
- [EU compliance delivered globally: Anthropic to watermark Claude's output worldwide](https://www.euronews.com/next/2026/08/11/eu-compliance-delivered-globally-anthropic-to-watermark-claudes-output-worldwide) — Euronews
- [Anthropic adds invisible watermarks to Claude-generated text](https://cyberinsider.com/anthropic-adds-invisible-watermarks-to-claude-generated-text/) — CyberInsider
- [Article 50: Transparency Obligations](https://artificialintelligenceact.eu/article/50/) — EU Artificial Intelligence Act
- [Guidelines on AI transparency obligations](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations) — European Commission
- [Text AI watermarks will always be trivial to remove](https://www.seangoedecke.com/text-ai-watermarks/) — Sean Goedecke
- [Watermarking AI-generated text and video with SynthID](https://deepmind.google/blog/watermarking-ai-generated-text-and-video-with-synthid/) — Google DeepMind
- [Anthropic brings EU watermarking to Claude worldwide](https://www.implicator.ai/anthropic-eu-watermarking-claude-worldwide/) — Implicator
- [California and artificial intelligence watermarking law](https://www.dataprotectionreport.com/2024/09/california-and-artificial-intelligence-watermarking-law/) — Data Protection Report
- [California AI Transparency Act amendments signed into law](https://www.troutmanprivacy.com/2025/10/california-ai-transparency-act-amendments-signed-into-law/) — Troutman Pepper Locke
- [AB 3211: California Digital Content Provenance Standards](https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB3211) — California Legislative Information
- [California AI watermarking bill supported by OpenAI](https://thejournal.com/Articles/2024/08/27/California-AI-Watermarking-Bill-Supported-by-OpenAI.aspx) — THE Journal
- [AI disclosure and transparency laws by state](https://www.ailawsbystate.com/tools/ai-disclosure-tracker) — AI Laws by State
- [Digital Omnibus reshapes EU cookie rules but leaves banner fatigue largely intact](https://www.osborneclarke.com/insights/digital-omnibus-reshapes-eu-cookie-rules-leaves-banner-fatigue-largely-intact) — Osborne Clarke