The archive

LibraryThe daily read10 min read

The mark that survives the paste

Every Claude model launched since August 2 weaves an invisible watermark into the text it generates, worldwide, and it travels when the text is copied and pasted. The detector that reads it has not shipped yet, which means for now the mark is a liability you carry and not a check you can run.

AI-generated text is copied between documents while an invisible digital watermark remains embedded.

A procurement team can subscribe to an AI text detector for a couple hundred dollars a year, run your proposal through it, and get back a number that is closer to a coin flip than anyone selling the subscription will say out loud. Anthropic just put something better inside the text itself. Every Claude model launched on or after August 2 now weaves a statistical watermark into the words as they are generated, at the model level, worldwide, and the mark travels with the text when somebody copies and pastes it somewhere else. The tool that reads the mark has not shipped yet. The mark is already sitting in whatever your team drafted last week, or some of it, and there is currently no way for you to tell which.

What actually got shipped

Anthropic published a support article on how Claude marks AI-generated content on Tuesday, and the news is not the announcement, it is the scope.

Two techniques, doing different jobs. Text gets an imperceptible statistical watermark woven into the model's token choices as it writes, which is the important detail: it is not metadata sitting next to the text, it is the text. There is no header to strip, no file property to clear. Files that Claude produces, .svg and .png and .jpg, get signed provenance metadata following the C2PA standard, the same content credentials scheme camera makers and Adobe have been pushing for years. That one records that a file passed through Claude and reveals whether it was tampered with afterward.

The scope lines deserve a second read. Marking is applied at the model level, so it does not matter which product the words came out of. The API, the chat app, Claude Code, Cowork, and the Slack integration all inherit it. It survives the cloud resellers, so routing through AWS, Google Cloud, or Microsoft Foundry does not launder it off. And Anthropic says marking applies to output from supported models "wherever Claude is offered, worldwide," not only inside the jurisdiction that caused it.

That last line is what turns a European compliance story into a story about your business. Anthropic signed the EU's Article 50(2) Code of Practice, an instrument the Commission and the AI Board confirmed as an adequate way to demonstrate compliance with obligations that became applicable on August 2. Around 190 organizations had signed by the end of July. Building one marked inference path for Europe and a second clean one for everybody else costs more engineering than marking everything once, so everything gets marked. This is how EU technology rules have worked for a decade. It is why a plumbing company in Ohio now has a European statute sitting quietly in its content workflow.

One precision matters more than the headline. This covers models launched on or after August 2. Models released before that date are in a transition period and Anthropic says it is working on adding support to them. So the honest state of your own archive is that part of it is probably marked, part of it probably is not, and you cannot tell from the outside which part is which. You would need a detector to find out, and the detector is the one piece that is not here yet.

Where the mark lands in a normal week

Think about where text you generated actually ends up, because that is the whole story.

The RFP response you assembled Thursday afternoon, which goes to a procurement team whose job includes asking how the work gets done. The job description you posted, which sits on a jobs board that is under pressure from candidates to flag AI listings. Product descriptions on a marketplace whose seller policy already has an AI clause nobody enforced because enforcement was impossible. Grant applications. Contract language you drafted and sent to somebody else's attorney. The blog post on your own site. The customer email macro your service team pastes forty times a day.

Then there is the case that will actually cause the first argument, and it is not the one anyone is bracing for. A customer sends you three paragraphs. You paste them into Claude to tighten the wording. The tightened version comes back marked. The customer wrote every idea in it, the structure is theirs, and the document now carries a signal saying a model was involved. Anthropic is direct about this in the limitations section: a detected mark means the content "may have been processed by Claude," and processing includes proofreading, translating, summarizing, and format conversion. Authorship is not what the mark measures. It never was.

That gap between what the mark actually says and what people will assume it says is where the next two years of unpleasant conversations live.

There is a real upside sitting on the other side of it, and it is worth naming, because it is the reason to care rather than just to worry. If you pay an agency for copy, a freelancer for a case study, or a contractor for documentation, you have never had a defensible way to know how the work was made. You have had opinions, and you have had detector tools that produce a confident percentage from nothing you can inspect. A vendor-published watermark with vendor-published detection is a materially better artifact than a black-box score. It tells you one narrow thing, and it tells you honestly, which is more than the current market offers. Anthropic says it will support users and third parties in detecting the marks and will publish technical documentation. Until that lands, the capability is one-directional: the signal is in your work, and the ability to read it is not in your hands.

The obligation that is yours and not Anthropic's

Read the Code of Practice's structure and you find something a small business can actually act on. It has two sections. Section one is rules for providers, which is Anthropic's problem. Section two is rules for deployers, which is you, and it covers labelling of deepfakes and of AI-generated text publications that inform the public on matters of public interest.

The carve-out in that second one is the useful part. A publication is exempt when it "has undergone a process of human review and is subject to editorial responsibility." That is not a technology requirement, a vendor purchase, or a consultant engagement. It is a named person who read the thing and owns it, and a record that this happened. If you publish anything that touches a topic of public interest, and small businesses do this more than they realize when they write about local regulations, health, safety, hiring, or money, the compliant version of your workflow is a review step and a byline. That costs an hour to set up. The EU even published a set of icons for deployers who want to label content rather than route around the obligation.

We covered the deployer side of Article 50 here on August 4, when the chatbot disclosure duty came due. This is the same statute reaching a different desk. That one was about the bot on your website telling people it is a bot. This one is about the words themselves carrying a signal you did not put there and cannot see.

The honest take

Three things are wrong with this, and they are not small.

The mark shipped and the reader did not. Anthropic has committed to detection and promised documentation, with no date attached. So today the arrangement is asymmetric in exactly the wrong direction for a small business: your output carries a signal that a large institution with a compliance budget will eventually be able to check, and you cannot check anything, including your own files. Every party in this transaction gets the capability at a different time, and the small operator gets it last. That is not malice, it is just how shipping order works, and it is worth being clear-eyed that the gap is real and open right now.

The watermark does not survive an adversary, and it was never going to. Sean Goedecke's walk-through of why text watermarks are trivial to remove is the clearest treatment of this: because a statistical watermark lives in subtle vocabulary choices, running the text through any other model and asking it to paraphrase strips the signal. Even a small local model can do it. And the Code of Practice pushes providers toward interoperable, published techniques, which is close to the opposite of the security-by-obscurity that text watermarking quietly depends on. So the marking regime catches the honest and misses the motivated. A vendor that lies to you about how the deliverable was made will keep lying and now has a five-second laundering step. A vendor telling you the truth carries the mark. Watermarking, in its current form, taxes candor.

And the mark will be read as proof of something it does not prove. Anthropic says plainly that a detected mark is a signal, not a conclusion, and that absence of a mark proves nothing either, since short passages, heavy edits, translation, older models, and screenshots all break it. Nobody downstream is going to read the limitations section. A procurement officer who gets a positive result on your proposal is going to hear "you did not write this." This is not speculation about human nature. OpenAI has reportedly held a text detector at very high accuracy for about two years without releasing it, and the stated reasons include exactly this: false accusations, and the way detectors get pointed at students and non-native speakers first.

Two more things worth having in your head. This is not going to stay an Anthropic quirk you can dodge by switching models. Google signed the same code in July and said it is working with Apple, ElevenLabs, Kakao, NVIDIA, and OpenAI on interoperable watermarking through SynthID. Marked output is becoming the default across the industry, so "use a different tool" is a workaround with roughly a six month shelf life, not a plan. And in month three the failure mode is contractual rather than technical: somebody's master services agreement already says no AI-generated content, that clause has been unenforceable and therefore ignored, and the first time it looks enforceable is the first time it gets enforced. On work you already delivered.

What is worth doing this week

Write your own disclosure before somebody else writes it for you. One paragraph in your statement of work, in plain language, saying how AI is used in the work you deliver and what a human does to it. Define "AI-assisted" yourself, in your words, while it is still a positioning choice. Once a detector result lands on a client's desk, the definition belongs to whoever is holding the report.

Stop using Claude as a silent copy editor on anything you will later describe as entirely human. Not because it is wrong to use it that way, it is a good use, but because the mark does not distinguish between drafting and polishing and you will be the one explaining the difference. If a human wrote it and a model tightened it, say so. That sentence costs you nothing today and quite a lot in a year.

Go read the AI clauses in the contracts you have already signed. Most people have never looked. Find out now whether you are already promising something you are not delivering, and if you are, raise it yourself rather than waiting.

If you publish anything on a topic of public interest, put a named reviewer on it and keep a record. That is the carve-out, written into the code, and it is cheaper than any tool anybody will try to sell you for this.

And do not buy an AI detector. The one that will matter has not shipped, it will come from the vendor whose model made the text, and the ones for sale today are the thing this whole regime exists to replace.

The strange part about a watermark is who it actually catches. Not the people lying about their work, who will paraphrase it out in a single pass and go on with their afternoon. It catches the people who never thought there was anything to lie about.

Sources

Every claim above traces back to one of these. Go read them yourself.

  1. 01
    How Claude marks AI-generated content

    Anthropic / support.claude.com / retrieved Aug 13, 2026

  2. 02
    Code of Practice on Transparency of AI-generated Content

    European Commission / digital-strategy.ec.europa.eu / retrieved Aug 13, 2026

  3. 03
    Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems

    Future of Life Institute / artificialintelligenceact.eu / retrieved Aug 13, 2026

  4. 04
  5. 05
    Text AI watermarks will always be trivial to remove

    Sean Goedecke / seangoedecke.com / retrieved Aug 13, 2026

  6. 06
  7. 07
    Anthropic says it will watermark text generated by its AI models

    TechCrunch / techcrunch.com / retrieved Aug 13, 2026