By Michael Semer
What you’ll learn:
- What the mark actually establishes, and why detection might be misleading about how much Claude is in there
- Which edits kill the signal, and why its absence is almost worthless as AI evidence
- What belongs in an AI authorship policy for your marketing team
Anthropic has begun weaving an invisible, machine-readable watermark into text generated by Claude models. This ‘invisomark’ or whatever (which is not really a watermark, per se) travels with the text wherever it’s copied and pasted, can survive some editing, and applies everywhere across every surface Claude runs on, worldwide.
The watermark proves that the text passed through the LLM. It does not prove the model wrote it. That gap is what’ll promot the next collective spasm of LinkedIn arguments about AI, I’m pretty sure.
So, you ask Claude to write something. It writes it.
You copy the text into a document, clean it up, change a few lines, and send it on.
But now there’s something else in the text. *Cue spooky music.*
You can’t see it. But eventually, a detector will. Bet on it.
Anthropic is also applying provenance technology to generated images.
The issue is how this changes the bargain between the person using AI and the company providing it.
They didn’t sneak it in…exactly
The mechanism is embedded in generation itself rather than bolted on afterward as file metadata. Anthropic’s help center article says that marking happens at the model level, which means it doesn’t matter which product or interface the text came from. Generated files get a second treatment: signed C2PA provenance metadata on supported types like .png, .jpg, and .svg.
Anthropic began rolling this out on August 2, 2026, but didn’t publish documentation until nine days later, as reported by TechCrunch.
That’s annoying.
When a company changes the provenance of user-generated output before fully explaining what it’s changed, even a defensible policy can feel like a hidden redo of its contract with users.
Make what you will of the delay.
Content creators already had plenty of reasons to feel iffy about AI frontier labs. Adding an invisible marker first and explaining it later gives them one more.
The issue isn’t only the watermark itself, but the sense that creators and users are learning about the rules after the rules have already changed.
The watermark follows the work
A visible watermark is straightforward.
You generate an image. There’s a logo in the corner. Everybody knows it’s there.
An invisible text watermark works differently.
The reader sees ordinary prose. Detection software sees evidence that a particular generation process produced it. Anthropic plans to provide tools capable of finding those marks.
The company says the text watermark can persist through copy-and-paste and modest edits, although heavier rewriting, translation, or mixing with other material may weaken or remove it.
So consider a routine workflow:
- A marketer generates a first draft in Claude.
- An editor rewrites 30 percent.
- A subject-matter expert changes the examples.
- A manager trims two paragraphs.
- The company publishes it under an employee’s byline.
Is that AI-generated text?
Human-edited text?
AI-assisted text?
Something else?
The watermark may answer a much simpler question: Did this originate with the model?
That’s useful. It’s also a long way from answering who actually wrote the finished piece.
A sort-of-public policy
Calling it something like “covert watermarking” makes it sound as though Anthropic got caught hiding a tracking mechanism.
That’s not quite what happened.
The mark is covert in the literal sense that you can’t see it. But the policy itself finally got disclosed sort of publicly. Albeit without trumpets or fanfare. And with that nagging delay.
Anthropic’s move comes as the European Union begins enforcing new AI transparency requirements. Article 50 of the EU AI Act requires providers of generative AI systems to make synthetic text, images, audio, and video detectable in machine-readable form. Those requirements became applicable on August 2, 2026.
The European Commission’s guidance on AI-generated content spells it out plainly: providers are expected to support marking and detection of synthetic content.
(So much of web and digital regulation starts with the E.U., right?)
Anthropic isn’t alone. Google has already created SynthID, a watermarking system for AI-generated text and other media.
The larger story is not that one particular AI lab added a hidden signature.
It’s that invisible provenance may become part of generative AI’s basic infrastructure.
The good case for watermarking is pretty good
There are obvious reasons to want it.
- Someone generates 20,000 fake product reviews.
- A political operator floods social media with synthetic commentary.
- A student submits an untouched AI essay.
- A content farm fills the web with automated articles.
- A scammer manufactures convincing material at scale.
Being able to establish that content came from an AI system could help platforms, publishers, educators, researchers, and investigators understand what they’re looking at.
That’s the argument behind the EU rules: people should have better ways to identify synthetic material instead of guessing from prose style or relying on AI detectors that make probabilistic judgments. There’s a real distinction here.
An AI detector says, “This looks like AI.”
A watermark says, in effect, “This output carries a signal placed there during generation.” Those aren’t the same claim.
And actual provenance is usually better than just…vibes.
Watermarks also break
Even watermarking systems built to withstand small edits can lose their signal after major revisions. Anthropic admits that its watermark has limits, and Google’s SynthID faces similar constraints, especially with short text or heavily altered passages.
That creates an odd asymmetry. Someone trying to conceal large-scale AI generation may deliberately rewrite the output until the watermark disappears, while someone using AI innocently may leave the mark intact.
So the existence of a watermark can tell you something. Its absence may tell you very little. That distinction is going to get lost, probably often.
The real shift is provenance
For the last few years, the debate has been:
Can you tell whether AI wrote this?
That may be the wrong question.
The better question is:
Can you establish where this came from?
Photography is already heading this way with provenance standards like C2PA, which basically attach a history label to a digital file. Anthropic is reportedly using that kind of C2PA-based provenance for images, while handling text with a different watermarking approach.
That points toward a web where content carries more history with it. Not necessarily a big warning. Not a scarlet AI stamped across the page.
Something subtler, invisible. With machine-readable evidence underneath.
The European Commission’s Article 50 transparency guidance makes clear that machine-readable marking is becoming a regulatory expectation, not just an interesting research project.
Authorship just got messier
If your organization uses Claude, the urgent question isn’t how to strip a watermark. It’s what you’re prepared to say about AI assistance.
Who generated the idea. Who wrote the first draft. Who checked the facts. Who changed the argument. Who approved it. Who owns the result.
A watermark answers none of that. Your process does.
Companies that treat AI disclosure as a forensic problem will spend the next two years doing attribution math: 20 percent AI, 60 percent AI, mostly human, substantially revised. That’s not a policy. That’s a spreadsheet nobody believes.
A better policy assigns responsibility instead of measuring contribution.
Use AI where you’re allowed to. Verify what it hands you. Don’t submit generated work where generated work is prohibited. Disclose assistance where disclosure actually matters to the reader. And put a human name on something only when that human will answer for every claim in it.
None of this is new, incidentally. I’ve built executive thought leadership programs for years, and the executive has never been the one typing.
The executive supplies the argument, the judgment, and the accountability. Nobody called that fraud, because the byline was a statement of ownership rather than a claim about keystrokes.
AI didn’t break that model. It just made a lot of companies notice they never wrote the rule down.
Companies need an AI authorship policy before they need a detector
If your organization uses Claude, the urgent question isn’t how to strip a watermark.
It’s what you’re prepared to say about AI assistance.
Was the idea generated by a person? Was the first draft generated by AI? Who checked the facts? Who changed the argument? Who approved the final version? Who owns the result?
A watermark doesn’t answer those questions.
Your process does.
Companies that treat AI disclosure as a forensic problem are going to spend a lot of time scuffling about percentages: 20% AI, 60% AI, mostly human, substantially revised…
That’s not much of a policy.
A better policy defines responsibility.
Use AI if you’re allowed to. Verify what it gives you. Don’t submit generated work where generated work is prohibited. Disclose AI assistance where disclosure matters.
And put a human name on something only when that human is willing to take responsibility for what it says.
The question for writers, marketers, publishers, employers, and schools will change. It won’t just be:
Did you use AI?
It’ll be:
What did the AI do, what did you do, and who’s responsible for the result?
The watermark can identify a machine.
It can’t answer for you.
Got an answer for that?
FAQs
What should our AI disclosure policy say?
Assign responsibility rather than estimating percentages. Define who verifies facts, who owns the argument, where generated work is prohibited outright, and where assistance gets disclosed. A byline should mean someone will answer for every claim under it.
Do we have to disclose that we used Claude?
Usually not, and the marking obligation falls on Anthropic rather than on you. Article 50(4) of the EU AI Act puts a disclosure duty on organizations publishing AI-generated text to inform the public on matters of public interest, and it doesn’t apply where the content went through human review with a named person holding editorial responsibility. Most B2B marketing copy sits outside that category anyway. The catch is that the exemption depends on a documented review process, which is the thing most content teams don’t have written down.
Does a detected watermark prove AI wrote the content?
No. The mark indicates text was processed by a supported Claude model, which includes light uses like proofreading or translating a human-written draft. It establishes that the model touched the text, not that the model authored it.
Does the Claude watermark survive editing?
Sometimes. Anthropic says the mark travels with copied and pasted text and may persist through some editing, but heavy rewriting, paraphrasing, translation, or mixing Claude output with other writing can make it undetectable.
Does the watermark apply outside the EU?
Yes. The requirement comes from the EU AI Act’s Article 50 transparency code, but Anthropic applies the marking worldwide, at the model level, across the Claude Platform API, Claude, Claude Code, Claude Cowork, and Claude Tag.
Can we detect the watermark ourselves?
Not yet. Anthropic says it will publish technical details so users and third parties can check content for its marks. No public detection tool had shipped as of August 11, 2026.
By Michael Semer