1.
Starting this month, something quietly changed in the way Claude writes. On or after August 2, every piece of text generated by Anthropic’s newest Claude models carries an invisible mark woven into the language itself. It’s not a watermark you can see, not a hidden string of characters in the code, not a tiny dot in the corner of your screen. It’s a pattern embedded in the choices Claude makes between words that would all be perfectly fine in the same spot. If you copy a paragraph Claude wrote and paste it anywhere else, the mark travels with it. You don’t opt in, you can’t detect it with your eyes, and you can’t turn it off. Anthropic confirmed this on Tuesday and published a support page explaining how it works. The immediate trigger is Article 50 of the European Union’s AI Act, which went into effect on August 2, along with the broader Code of Practice on transparency of AI-generated content. Around 190 organizations signed the code, but only 82 signed the section that specifically covers marking. Anthropic, Google, OpenAI, Meta, Microsoft, and Mistral all signed that more serious section. The rules were written in Brussels, but because Claude is a global tool, the consequences land on everyone who uses it anywhere in the world. There’s something almost poetic about that: a regulation designed for one block of countries quietly resetting the default for millions of users who never voted for it and might never have heard of Article 50. That’s how the modern digital world works, for better or worse. A policy paper from the European Commission can end up shaping what an American student, a Kenyan freelancer, or an Indian startup founder experiences the next time they ask an AI to draft a message or refine an idea.
2.
The technology underneath this is more clever than most people realize, and also more limited than the hype suggests. When Claude writes a sentence, it is constantly choosing among dozens of words that would all fit grammatically and semantically. The watermark gently tilts those choices toward a statistically recognizable pattern. There’s no hidden message between the letters and no secret code in the spaces. The pattern is simply the way particular words get selected more often than chance would predict. That’s why the mark survives copy and paste: it doesn’t live in the font or the formatting, but in the vocabulary itself. Until now, claiming that a piece of writing was AI-generated was mostly a hunch. You could point to style, tone, rhythm, or a suspicious lack of typos, but it was all guesswork. This is different. This is a statistical test with a computable error rate. In principle, you can say not just “this looks like AI” but “the probability that this was written without Claude is one in a million.” That’s genuinely new. But there are two important caveats. First, a single sentence is too short to carry a reliable watermark. Claude needs enough text to build up a pattern, and a one-liner doesn’t give it room. Second, and this is the one the internet got confused about: if you ask Claude to fix punctuation in a paragraph you wrote, Claude has to reproduce your words almost exactly. There’s no room to insert its own pattern because the output is essentially human text with a few small corrections. Radio host Erick Erickson announced that he had “ditched Grammarly for Claude” for proofreading and worried that his own writing would now be watermarked as Claude’s work. But in most cases, minor proofreading and punctuation fixes don’t create enough new word choice to carry a watermark. You can tidy up a sentence without handing authorship to the machine.
3.
That doesn’t mean the watermark is harmless. The deeper problem is what the mark actually means. A watermark says that Claude modified the text, not that Claude authored it. Ask Claude to summarize or condense a memo you wrote yourself, and the output comes back marked, even though every idea in it is yours. The mark doesn’t distinguish between “written by AI from scratch” and “edited or reformatted by AI.” Beatrice Nolan, writing in Fortune, made a sharp observation: a flat AI label treats someone who generates a thousand fake news videos the same as a writer who cleans up a paragraph. Both get the same stamp, but they are not the same act. That matters because the mark is invisible and persistent. It won’t show up in a way that helps you understand how much human thought went into a piece of writing. It just tells you, or a future detector, that a Claude model was involved somewhere in the chain. Worse, the absence of a mark proves nothing. Older models, open-weight models, and other companies’ models all produce text that comes back “clean.” So if you’re trying to catch someone who’s pretending human labor is behind their content, the watermark only catches a slice of the problem. A person determined to hide AI use can simply go to a model that doesn’t watermark. And a person who uses Claude helpfully, to polish their own genuine thoughts, ends up tagged alongside a spam factory churning out junk around the clock. That’s a blunt instrument being applied to a subtle reality. It’s like labeling all “vegetarian food” as “no animal products” and then selling honey yogurt under the same banner. The label isn’t false exactly, but it erases the distinctions that matter.
4.
People are already asking whether the watermark can be removed. The answer is more complicated than most workaround enthusiasts assume. Paraphrasing can degrade the signal, but it rarely erases it. The reason is that a rewrite keeps enough of the original wording, even after significant changes, to allow the statistical pattern to be rebuilt. Researchers who tested similar schemes found that watermarks remained detectable after a strong human paraphrase, as long as there was enough text to work with. That’s counterintuitive. Most people think that if you change a few words, you’ve escaped the mark. But the mark isn’t a sentence or a phrase; it’s a distribution over many choices across many sentences. Changing one word here and there doesn’t destroy the distribution. It just shifts it a little. To truly remove the mark, you’d need to rewrite so aggressively that you’d essentially be writing a new piece, at which point the question of authorship gets philosophically weird anyway. Meanwhile, Anthropic hasn’t actually shipped a detector yet. It hasn’t published a false positive rate, and it hasn’t said how many words are needed for a reliable result. The marks are going into text that nobody outside the company can read at the moment. But they don’t expire. That’s the part that should make everyone pause. A college essay submitted this fall is still marked three years from now, when the student is a junior and someone finally has a tool to read the watermark. A blog post you write today could be audited by a future employer or an academic integrity office that has access to a detector you don’t. The absence of a public detector today doesn’t mean the power to detect is gone; it just means the power is being held in reserve.
5.
Technical problems aside, it’s worth stepping back and asking what all this watermarked machinery is actually trying to accomplish. Chris Best, Substack’s CEO, made the point more eloquently than anyone in a July post that coined the term “Claudefishing.” He said: “The core problem is not people using AI, or the quality of its output. Not everything made with AI is slop, and not all slop is made with AI. The problem is when there is a mismatch between a reader’s expectation and reality, especially when they unwittingly invest their attention in something with no human thought on the other end. That’s Claudefishing.” That’s a real harm. It’s the harm of feeling tricked, of spending ten minutes reading something you think came from a human mind and discovering it was pasted together by an algorithm with no lived experience, no vulnerability, no stake in what it just said. That kind of mismatch corrodes trust. It makes people cynical about everything they read. It makes them wonder whether the person they’ve been following is actually a person at all. A watermark is supposed to prevent that by giving readers a way to know what they’re looking at. But here’s the limit: a watermark can’t tell slop from careful work. It can’t tell a thoughtful AI-assisted essay from a mindless content farm. It can only tell you that a model was involved. What that means depends entirely on how the model was used. A tool doesn’t have intentions. A person does. And a mark that can’t distinguish between those two things is a very crude answer to a very nuanced problem. It helps with accountability, maybe. It helps with provenance, maybe. But it doesn’t solve the deeper problem of attention being harvested by things that have no human on the other end. In fact, a watermark could make it worse, because it gives the illusion that the problem has been solved when it hasn’t.
6.
I’ll be honest with you: I use Claude, and I have mixed feelings about all of this. On one hand, AI use should be disclosed appropriately. If someone is publishing writing that was substantially generated by a machine, readers deserve to know. Transparency is a value, and watermarks are one way of honoring it. On the other hand, anyone who is determined to hide their AI use can still do so. They can use xAI, which currently puts no watermark on Grok. They can use open-weight models that carry no watermarks. They can use an older version of Claude. Or they can run a local model. The watermark only affects a slice of the AI marketplace, which means it will be most effective against the most honest people, the ones who aren’t trying to hide anything. That’s not a trivial concern. But I keep coming back to a simpler idea: judge the outcome, not the tool. I used Claude extensively in writing and researching this column. I told you that, because it’s true, and because I think the distinction between helping and handing off matters. The result is mine in the ways that count: I chose the arguments, I checked the facts, I shaped the sentences, and I take responsibility for every word. Claude was a collaborator, not a replacement. I’m pleased with how it turned out. But I know not everyone feels the same, and that’s fine. The question is whether we want a world where AI is always visible, always marked, always auditable, or a world where we trust people to be honest about their process. The watermark exists because trust has frayed. But no watermark can restore it. Only people can do that, one honest, careful, human choice at a time. Where do you stand?


