
August 12, 202610 min read
Should you worry about the new AI watermark on your content?
Thom Van Dycke · Van Dycke Strategic Business Architecture
Probably not. The watermark records where text came from, not whether the work behind it is honest. If you direct the thinking, review what comes back, and tell people you used AI, you were already doing what the regulation asks for. The real exposure sits with people who did none of that.
What did Anthropic actually do?
They put a mark in the text that nobody can see.
Claude now embeds an imperceptible watermark in generated text, and attaches signed C2PA provenance metadata to generated files like PNGs and SVGs. It runs automatically. It covers models launched on or after 2 August 2026, with older models being retrofitted, and it applies across every Claude product worldwide, including the API and the cloud platforms that resell it. Anthropic's own documentation lists no way to switch it off (Anthropic Help Center).
The announcement landed badly with a good chunk of the internet, mostly on consent grounds (Forbes). I understand the instinct. I don't share it, and I'll get to why.
The part almost nobody is reading is Anthropic's own limitations section, which says something the panic doesn't. A detected mark tells you Claude processed the text. It does not tell you Claude wrote it, and they say so directly: people use Claude to proofread, translate and summarise, and the output carries a mark even when the ideas underneath came from somewhere else. It works in the other direction too. Heavily edited text, short passages, and files whose metadata got stripped in a format conversion may carry no detectable mark at all.
So the thing being built is a provenance signal, and a leaky one. Anyone reading it as a verdict on authorship has misunderstood what it measures.
Why did this happen now?
Because a deadline arrived.
The EU AI Act's transparency obligations under Article 50 became legally effective on 2 August 2026, the same date Anthropic's marking begins. Article 50(2) requires providers of generative systems to mark their outputs in a machine-readable format, detectable as artificially generated. The European Commission published a voluntary Code of Practice on Transparency of AI-generated Content in June 2026 as the practical route to demonstrating compliance, and roughly 190 organisations signed it before the obligations landed, Anthropic among them (European Commission). Systems already on the market get a transitional period and have until 2 December 2026, which is why older models are being retrofitted rather than switched over on day one.
That obligation belongs to the model provider. It isn't yours. Two others might be.
Which parts of this land on you?
Two, and only if you publish or automate.
Article 50(1) says that if a person is interacting with an AI system, they need to know at the point of first contact, unless it's already obvious from the context. A chat widget on your site, automated phone triage, an agent answering your support inbox — all of it counts, and none of it is as obvious to a customer as it is to you. Say so.
Article 50(4) says AI-generated text published to inform the public on a matter of public interest has to be disclosed. Then it names an exemption, and the exemption is the sentence worth reading twice: text that has undergone human review or editorial control, where a person holds editorial responsibility for it, does not need the label (Article 50, EU AI Act).
That exemption is the whole test, written down plainly. The regulation cares about accountability rather than authorship. It wants to know that somebody with a name is answerable for what the text says.
Who should actually be nervous?
Two groups, and you already know if you're in one.
Students, first. If you were asked to produce original work and you produced a prompt instead, that's cheating. It was cheating before the watermark and the watermark makes it findable. I'm not going to dress that up.
Second, anyone publishing machine writing under their own name as though it were their own thinking, with no person in the loop, in a context where they're being graded or paid for the thinking specifically. That's the group with a genuine problem. The watermark didn't create it. It made it checkable, which is a different thing, and it arrived faster than most people expected.
Everyone else is fine. Not "probably fine, consult a lawyer" fine. Fine.
What does honest AI use actually look like?
Boring, mostly. Here is my own, since I'd rather show the working than describe a standard.
This piece started as me talking into a microphone. I dictated the whole argument, then asked Claude to turn a pile of half-finished sentences into something with a shape. Every idea in it is mine. I didn't ask it to research anything, invent anything, or have an opinion on my behalf. What I needed was structure, and I'm not embarrassed to have needed it.
I already disclose, and I have for a while. The emails I send say whether the image is AI-generated or artwork I made years ago and am reusing, along with a rough percentage of how much of the text was machine-drafted, how much I edited, and how much is straight from me. The percentage is arbitrary and I know it. It's become a bit of a running joke with people who read them. I'd still rather over-disclose than have anyone wonder.
And I never use it without me in the room. It drafts emails; I read every one before it sends, and half the time the tone or a detail is wrong and I fix it. For longer pieces, it produces a draft and then interviews me, so the examples and the positions are actually mine rather than a plausible-sounding average. Client content works the same way: it comes out of interviews I do with the client, not out of me guessing what a company like theirs might want to say.
None of that is a compliance strategy. It's just what it takes to make the writing any good.
Why is "write in my voice" the wrong instruction?
Because voice is the last thing that gets built, not the first.
Hand a model twenty of your old posts and ask it to sound like you, and you get a costume. The rhythm comes out right and nobody is home. That's the version worth being uncomfortable about, and you don't need a watermark to catch it. Readers feel the emptiness long before a detector confirms it. Then your name sits at the bottom of a page arguing for something you never actually decided.
The useful instruction runs the other way. Give the model your thinking and let it handle structure. Make it interview you. Feed it what you've already written so the new piece stands on the old ones instead of floating free.
Which exposes the real problem for a lot of businesses. If you don't know what you believe about your market, a model cannot fake it for you, and the piece comes out hollow in a way no editing pass repairs. That's an architecture problem wearing an AI costume, and it predates the watermark by about a decade. Content is downstream of positioning. It always was.
Will there be a watermark war?
Yes, and the research is already there.
Text watermarks come out. In a 2024 EMNLP paper, Saksham Rastogi and Danish Pruthi showed that an attacker who reverse-engineers a watermarking scheme's token list from roughly 200,000 tokens of output can then paraphrase around it, dropping detection true-positive rates below 10%. Their phrasing: "rendering the watermarking schemes unusable" (Rastogi and Pruthi, EMNLP 2024).
Two honest qualifications, because the paper is more careful than the headline. They broke two specific schemes, and a third one they tested held up far better, losing only about ten percent of its detection rate under the same attack. Anthropic hasn't published which approach it uses, so nobody outside can say where its watermark sits on that spectrum. What the research establishes is that robustness has to be argued rather than assumed, not that every watermark falls over.
So a scrubbing industry is coming. It will be sold as a privacy tool and bought as a laundering service, and it will do fine. I find I don't care very much, because it only solves a problem you have if you were hiding something in the first place.
So should you worry about the watermark?
Only in proportion to what you're hiding.
An honest admission first: it makes me faintly anxious. Not because I think I'm doing anything wrong, but because a new compliance layer shows up and the reflex is to wonder whether you've got every part of it right. That feeling is real and I'd rather name it than perform being above it.
It passes quickly once you look at the actual test. Is a person directing this? Did a person read it? Does the reader know? Three questions, answerable today, without a lawyer.
Disclose more than you're required to. It costs nothing, and it's a better way to work.
Putting it to work
Take the last three things you published under your own name. A blog post, a newsletter, a LinkedIn piece, a proposal. Then answer three questions about each one, out loud, to somebody who doesn't work for you.
Whose thinking is this? Not whose words. Whose argument, whose examples, whose position. If the honest answer is "the model's, based on what it guessed I'd say," you've found something, and it isn't a compliance issue.
Who read it before it went out? All the way through, with the authority and the willingness to change it. If nobody did, you don't have editorial control in any sense the AI Act would recognise, and more to the point you don't have it in any sense a reader would recognise either.
Does the reader know? If your answer depends on nobody checking, that's your answer.
Then do the small version of the fix. Add one sentence of disclosure to your next published piece. Not a legal notice. A plain line saying what the machine did and what you did. Watch whether anybody minds.
In my experience nobody does. Some people write back to say thank you.
Sources
- Anthropic: How Claude marks AI-generated content
- EU AI Act, Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems
- European Commission: Code of Practice on marking and labelling AI-generated content
- Saksham Rastogi and Danish Pruthi, "Revisiting the Robustness of Watermarking to Paraphrasing Attacks," EMNLP 2024
- Forbes: Claude Will Put Invisible Watermarks On AI Text And Images
Frequently asked
Can the watermark be detected by anyone, or only by Anthropic?
Generated files carry signed C2PA provenance metadata, an open standard other tools can already read. Text detection is different: Anthropic has committed to supporting users and third parties in detecting its marks, as the Code of Practice requires, but says the technical details are still to come. So today it's largely Anthropic-side. Assume it becomes checkable by more people over time rather than fewer.
Does this mean AI content will be penalised in search?
Nothing in the AI Act or in Anthropic's announcement says anything about search ranking. These are transparency rules and they say nothing about quality. Search engines publish their own guidance on AI-assisted content, which is a separate question from this one. The thing that gets content penalised is being unhelpful, and that was already true.
Do I need a disclosure on everything I publish?
No. Article 50(4) applies to text published to inform the public on matters of public interest, and exempts anything with genuine human review and editorial responsibility. Most marketing copy isn't public-interest text and most of it has a person behind it. I'd still disclose, because the reason to do it isn't the regulation.
What should a disclosure line actually say?
Plain language beats legal language. Something like: produced with AI assistance, directed and edited by a person who is responsible for what it says. If images are involved, say whether they're generated or original. One sentence is enough, and burying it in your terms of service defeats the purpose, since the AI Act asks for disclosures that are clear and distinguishable.
Should I stop using AI for client work?
No, and if you're doing it well you should tell your clients you're doing it. Being able to serve people faster is a real benefit and there's nothing to apologise for. The line worth holding is that the thinking comes from real conversations with the client, and a person reviews everything before it carries anyone's name.
Ready to look at the architecture honestly?
If your content only holds together when a model is filling in what you believe, the watermark is not your problem. Positioning is, and it's the layer everything else sits on.
Book the conversation. We'll tell you what we actually see, and whether the work we do fits where you are.
Ready for some serious action?
It starts with a quick 20-minute call to come up with a plan.
Get the next one in your inbox
Occasional field notes on positioning, marketing, and building a founder-led business worth running. No spam, and you can unsubscribe anytime.



