What Claude’s watermark can’t tell you

I was scrolling TikTok when a video came up about Anthropic putting invisible watermarks in Claude’s text. The narrator was using the voice. Anyone who spends time on the app knows the one — the BREAKING NEWS cadence that turns a help-center update into a five-alarm fire.

The claim was that Claude now embeds a mark in everything it writes, and that a teacher will be able to run a submitted assignment and see it. Underneath, in the comments, people were trading ways around it.

Nobody in the video mentioned Article 50 of the EU AI Act, which is the reason the mark exists. Nobody mentioned that the mark cannot answer the question the video was asking of it. 

Who owes what

Article 50 became applicable Aug. 2, 2026. It assigns different obligations to two categories of actor, and most of the coverage I saw collapsed two of those obligations into one.

The first belongs to the provider — the company that builds the model, or has it built. Providers of systems that generate synthetic content have to mark their outputs in a machine-readable way. That is Anthropic’s announcement: a watermark the company says is woven directly into the text as the model generates it, and signed provenance metadata on supported files like .png, .svg and .jpg under the C2PA standard. Anthropic said the marking will apply worldwide, across the API, Claude Code, Claude Cowork and Claude Tag. Anthropic signed the Commission’s Code of Practice on Transparency of AI-Generated Content. Models launched on or after Aug. 2 support marking at launch, and the company said older models are still in progress. The technical documentation explaining how anyone detects a mark has not been published yet.

Existing systems do get more time, though less than the headlines suggested. The Digital Omnibus, Regulation (EU) 2026/1744, entered into force July 27, and it did not move the Aug. 2 date for Article 50. It added a four-month transition, out to Dec. 2, 2026, for the machine-readable marking duty — and only for generative systems already on the EU market before Aug. 2. Anything placed on the market on or after that date must comply immediately. Any Claude model launched from Aug. 2 onward must therefore support marking now. Models already on the market fall inside the transition period.

The second obligation belongs to whoever publishes. Deployers who put out AI-generated or manipulated text to inform the public on matters of public interest have to disclose that the text was artificially generated, unless the content went through human review or editorial control and a natural or legal person holds editorial responsibility for it.

That exception is narrower than it sounds, and the Commission’s guidance says so. Human review means deliberate examination of the substance by one or more people with relevant knowledge and professional judgment in the subject matter. Editorial control means a responsible editorial entity with the authority to approve, alter or reject the substance of the text on substantive grounds, including fact-checking and vouching for sources. Superficial or purely formal checks, spell-checking and grammar correction among them, are neither. And editorial responsibility is a separate requirement: a person or organization holding ultimate legal responsibility for the publication.

Which is what undoes the assumption behind the TikTok video. Article 50 does not treat the two mechanisms as interchangeable. Providers embed machine-readable marks. Deployers clearly label qualifying content for the people exposed to it. The mark is not the label, and the law was written by people who knew the difference.

What a mark shows

Anthropic’s own help page is candid about this. A detected mark does not mean Claude wrote the content, because people use Claude to proofread, translate, summarize and convert files. Because the mark is embedded in the text, Anthropic says it travels with copied text and may persist through some editing. Heavy rewriting, paraphrasing or translation can make it undetectable, and a short passage may not carry enough text for a reliable signal.

So a detected mark can show that Claude processed some text. It cannot show that Claude originated the argument, that a student broke a rule, or that the final draft was not rewritten line by line. A missing mark shows less than that.

And a conventional assignment submitted privately to a teacher is not a publication within Article 50(4), which covers text published to inform the public — content the guidelines read as accessible to an indefinite and relatively large number of readers. Academic-integrity policies still have to weigh conduct and evidence themselves. The law does none of that work for a teacher, and the students in those comments are solving a problem it never posed.

Written anyway

The Thread went out for the first time in December 2024. It was a weekly digital museum built out of obituaries — real names, real people, the primary obituary hyperlinked in every exhibit — on the premise that AI could find patterns across hundreds of lives no human editor would have time to read. The model did the clustering. I did the interpreting, and the fact-checking. Over the year I published 39 issues, 33 of them in the museum format, and closed the archive after a six-part finale.

The questions started after the first few issues. They came as email replies. One of them reached me through a reader who told me a friend of theirs had subscribed, the two of them had talked about the newsletter, and then the friend wrote to me to relay what the first person had said.

So in early 2025 I published a Member’s Guide — an FAQ, on its own page, so I would not have to keep defending the project one email at a time. It laid out why I used real names, why every obituary linked back to its source, what the AI did and what it did not do. On images: “I use AI-generated art in this newsletter, but never images of the people who passed away that I write about. Those stay in their original obituaries where they belong.”

The newsletter’s host was an AI persona called Echo Weaver, whose appearance I modeled on my cousin Yolanda, who died in 2017. Its About page says it in the third line: “Yes, I’m AI.”

Nobody made me write any of that.

Sometime in my MSc program at UCD — fall term, I think, though it may have been spring, I don’t remember — an assignment for a UX research class asked us to scope out a study rather than run one. I picked AI-generated voice deepfakes of dead people used in political advocacy, and I recommended ethical disclosure by platforms, informed consent from families before a voice is used, and industry-wide regulatory guidelines. It was never fielded. I have no findings, only a plan. Article 3(60) of the AI Act covers AI-generated or manipulated audio that resembles a real person and would falsely appear authentic, alongside image and video. So one of those recommendations — disclosure of synthetic political audio — now resembles an enforceable duty across 27 member states. Only one of the three. Nothing came of the consent protocols, and the duty in the law sits on deployers rather than on the platforms I was writing about. (The Act had already been adopted by then, so I can’t claim I got there first.)

Containers

The FAQ has a second half I had almost forgotten, on why the newsletter used AI art and never photographs of the dead. Copyright made permissions difficult, which is how it started. Then it turned into something I believed.

I cited Sarah Jeong’s piece in The Verge on Google’s Pixel 9, which argued that the era of a photograph working as a shortcut to reality was ending, and that the default assumption about any image was about to flip to fake. See a roach in your takeout, snap a picture. Document damage to a rental car. Photograph smoke over your neighborhood during a fire. Her point was that all of it stops functioning as evidence once anyone can edit reality on a phone.

That was two years before the C2PA half of Monday’s announcement, which is one attempt to answer that problem. A C2PA manifest can record capture, generation and later editing, and Anthropic’s signature indicates that Claude processed a file rather than that Claude created the image inside it. Imperfect, and strippable — re-save the file, convert the format, take a screenshot, and the manifest is gone. But a file is at least a container, and a production history can travel inside one.

Plain text has no durable container. A blog post is words in an order. It can be drafted by a model and rewritten by a person, drafted by a person and proofread by a model, or reported out by a journalist and passed through a model for translation or tightening. Any of those can leave a mark. Any of them can also end with no detectable mark at all, depending on what went through the model and how much changed afterward.

The arrangement

What Article 50 asks of a publisher is whether someone with relevant competence examined the substance of the work, and whether a person or organization holds ultimate legal responsibility for it. That is an arrangement between people. A disclosure page can document it. A disclosure page does not create it, and neither does a detector.

I wrote The Thread’s page in early 2025 because readers asked and I got tired of answering the same email one at a time.

The page is still up.

Ethan Ward

Award-winning journalist and product strategist focused on AI governance, algorithmic accountability, and responsible technology. AI Policy Certificate (Center for AI and Digital Policy). Master of Public Diplomacy (University of Southern California). MSc in Human-Computer Interaction (University College Dublin). His work has appeared in USA Today, NPR, Slate, Fast Company, and PBS SoCal. Founding editor of INHERITANCE. Founder, HEATDRAWN.

https://iamethanward.com
Next
Next

The Labels Wrote AI Chart Rules. The Charts Don’t Pay Anyone.