0 min read

Every sentence Claude writes now carries a mark you cannot see

What Anthropic switched on this month, why the law made it happen, and the one exemption that decides what it means for your business.

What Anthropic switched on this month, why the law made it happen, and the one exemption that decides what it means for your business.

Something changed this month that most people will never notice, which is precisely the point.

From August 2026, text produced by Claude carries an invisible watermark. Not a disclaimer, not a footer, not a badge on the page. A machine-readable signal woven into the text itself — one that leaves the meaning and the readability completely intact, and that a human reader cannot see at all.

It survives copy and paste. It holds through moderate editing. And it applies everywhere, not only in Europe.

If your organisation uses AI to draft anything, this is worth ten minutes of your attention. Not because it creates a problem, but because most of the panic about it is aimed at the wrong thing.

Every sentence Claude writes now carries a mark you cannot see

The report that arrived on a Tuesday

Imagine a analyst called Priya finishing a market summary. She drafted it with Claude, rewrote about a third of it, checked the numbers herself, and sent it to her director.

Nothing about that is improper. It is how a great many people now work, and the output is better for the tool having been involved.

What is new is that the file she sent carries a signal saying some of this text passed through an AI system. She did not add it. She cannot remove it by pasting into a different application. She may not know it is there.

Nobody has been caught doing anything. But a fact about how the document was made now travels with the document, and that fact is no longer hers to disclose or withhold.

That is the change. Not surveillance, not enforcement, not a scarlet letter. A property of the file that used to be invisible and unverifiable is now invisible and verifiable — and those are very different things.

The teaching: "The shift is not that AI writing is detectable. It is that the evidence now travels inside the document rather than in someone's memory of how it was made."

The report that arrived on a Tuesday

What Anthropic actually did

The mechanism is more elegant than the coverage suggested, and understanding it prevents most of the wrong conclusions.

A language model does not write one inevitable sentence. At every step it has many acceptable ways to continue, and it picks among them. Watermarking works by making that choice slightly non-random in a pattern only a detector knows to look for — a bias so small it does not degrade the writing, but consistent enough that across enough text a statistical fingerprint emerges.

That gives it three properties worth knowing.

It is imperceptible. There is no hidden character, no zero-width space, no metadata field to strip. The signal is in the word choices themselves.

It is robust to ordinary handling. Copy and paste carries it. Moving between applications carries it. Moderate editing leaves enough intact to detect.

And it is statistical, not forensic. It needs a reasonable quantity of text to be confident. Anthropic says so plainly: reliability degrades under heavy editing, and short outputs may not carry a strong enough signal to detect reliably.

That last admission matters more than anything else on this page, and we will come back to it.

The teaching: "It is not a tag attached to the text. It is a pattern inside the text, which is why you cannot remove it by moving the words somewhere else."

What Anthropic actually did

Why now, and why everywhere

The date is not a coincidence.

The transparency obligations in Article 50 of the EU AI Act took effect on 2 August 2026. Anthropic's watermarking applies to models released on or after that same date.

Article 50 requires providers of AI systems that generate synthetic content to mark their outputs in a machine-readable format, detectable as artificially generated. The wording is pragmatic rather than absolute — solutions must be effective, interoperable, robust and reliable as far as is technically feasible, taking account of content type, cost and the state of the art.

That is a law asking for the best available answer, not a perfect one.

The more interesting decision is geographic. The regulation is European. The marking is worldwide — every supported model, every user, every country.

There is no mystery to that. Running two versions of a model, one marked and one not, means building a second pipeline, deciding which users belong to which, and defending that boundary. Marking everything is simpler, cheaper, and impossible to get wrong. It is the same logic that made GDPR privacy notices appear on American websites.

The teaching: "When compliance is cheaper to apply globally than to apply selectively, one region's law becomes everyone's default. This is the second time we have watched it happen."

What the mark proves, and what it does not

This is where most of the commentary went wrong, and where the business risk actually sits.

A positive detection means this text passed through an AI system. That is all it means.

It does not mean nobody wrote it. It does not mean it was not checked, edited, verified or improved. It does not identify the person. And a negative result does not mean text is human — it may be from another model, or heavily rewritten, or simply too short to carry the signal.

So the mark evidences processing, not authorship. Those get conflated constantly, and the conflation is what generates the fear.

The failure most likely to hurt someone is not detection. It is a false accusation built on a misunderstanding — a student, a job applicant or a supplier accused of dishonesty because a tool returned a positive on text they wrote and merely polished. The tool did its job correctly. The person reading the result drew a conclusion the result does not support.

If your organisation is going to use these detectors, that distinction needs writing into the policy before anyone uses it in a decision about a human being.

The teaching: "A watermark answers 'did this pass through a model'. People will hear 'did a human write this'. Those are different questions, and only one of them is being answered."

What the mark proves, and what it does not

The exemption that decides what this means for you

Here is the part worth taking to whoever owns your AI policy.

Article 50's obligation to mark falls on the provider — Anthropic, OpenAI, Google. It is their job, and they have now done it. Your organisation does not have to implement watermarking to comply.

The obligations that reach you are about disclosure, and they are narrower than the headlines imply. And there is a specific carve-out: AI-generated text that has undergone editorial control, with a person or organisation holding editorial responsibility for the publication, sits outside the disclosure requirement.

Read that again, because it is the whole story for a business.

The law is not trying to stamp AI involvement onto every document in Europe. It is drawing a line between content published with nobody accountable for it, and content that a named person reviewed and stands behind. Where a human takes responsibility, the position changes.

Which means your compliance question is not how do we detect the watermark or how do we hide it. It is: can we show that a person reviewed this and took responsibility for it?

That is a governance question with a governance answer, and it is the same answer as everywhere else in this field. Who checked it. Who owns it. What happens when it is wrong.

The teaching: "The law does not ask whether a machine helped. It asks whether a person is accountable for the result. Those organisations that can already answer that have very little to do."

The exemption that decides what this means for you

What to do about it on Monday

Four things, in order of how much they matter.

Stop treating detector output as proof of misconduct. If you use one, write down what a positive result actually means before anybody acts on it. The tool evidences processing. Only a conversation establishes authorship.

Find out where AI text leaves your organisation unreviewed. Customer emails, tender responses, published copy, reports to regulators. The watermark does not create risk there — but it does mean the fact is now discoverable by anyone who cares to check, which changes the calculus on content nobody reads before it goes out.

Write down who holds editorial responsibility for published content. That single sentence is worth more to your regulatory position than any tooling. It is also, conveniently, the thing you should have had anyway.

Do not build a workflow to strip watermarks. Beyond the obvious problem of deliberately defeating a transparency measure, it does not work reliably, and being seen to have tried is far worse than the disclosure you were avoiding.

None of this is an emergency. What changed this month is smaller than the headlines and more permanent than a policy — a fact about how a document was produced now travels inside it, quietly, everywhere in the world.

The organisations that will find this uncomfortable are the ones publishing things nobody has read. That was already a problem. It has simply become a visible one.

On Every sentence Claude writes now carries a mark you cannot see · 0 comments
Comments are moderated

No comments yet — be the first to add to the discussion. Comments appear after they’re reviewed.

Comments are read before they appear.

Enjoyed this article?

Want more insights?

Subscribe to get the latest articles delivered straight to your inbox.