· Solveion · Perspectives  · 6 min read

Someone else's compliance, inside your output

Claude now embeds an invisible watermark in everything it generates, worldwide, with no opt-out. The good case is real. The bad case is that you did not choose it. The ugly case is that the mark proves a machine touched the text, not that a machine wrote it.

Claude now embeds an invisible watermark in everything it generates, worldwide, with no opt-out. The good case is real. The bad case is that you did not choose it. The ugly case is that the mark proves a machine touched the text, not that a machine wrote it.

Anthropic announced this week that models released from 2 August onward embed an imperceptible watermark in the text they generate. It survives copy and paste, may survive some editing, and covers essentially every surface: the API, the consumer app, Claude Code, Cowork, and Claude accessed through AWS, Google Cloud and Microsoft Foundry. Anthropic intends to publish detection details and offer a detection tool.

There is no opt-out, including for paying customers.

The trigger is Article 50 of the EU AI Act, whose transparency obligations became enforceable on 2 August. The response is global — not geofenced to Europe.

It is worth taking each part of this seriously, because the reflexive readings in both directions are wrong.

The good

Provenance is a genuine problem and nobody has solved it. The web is filling with text of unknown origin, and the tools claiming to detect it are mostly unreliable in ways that have already cost students and writers real harm. A robust, machine-readable signal at the point of generation is a far better mechanism than a classifier guessing after the fact.

Applying it worldwide rather than only in Europe is also, we think, the more honest choice. The alternative — a marked product for regulated users and an unmarked one for everyone else — would make the safety claim into a compliance costume. If provenance matters, it matters everywhere.

And it is being done in the open, with published detection, rather than as a hidden capability retained by the vendor. That is meaningfully better than the version of this that stays secret.

The bad

Now the part that deserves the objection our clients keep raising.

This landed on the API. That is not a consumer safety feature; it is a change to the supply chain of every product built on Claude. If you ship software whose output is partly generated, that output now carries a mark you did not choose, cannot remove, and did not disclose to your own customers, and you found out about it from a blog post.

It applies globally because of a regulation most affected users are not subject to. Whatever one thinks of the EU AI Act, a Canadian firm serving Canadian clients has now had a European transparency rule applied to its production systems, through a vendor acting as an involuntary compliance intermediary. There was no seat at either table.

And the no-opt-out point matters more than it sounds. Enterprise agreements exist precisely so that large customers can negotiate terms. Here there is nothing to negotiate.

The ugly

The most quoted line in this week’s coverage is the important one: the mark proves processing, not authorship.

Think about what that means in practice. You write a paragraph yourself and ask Claude to tighten the grammar — watermarked. You paste in your own document and ask for a summary — watermarked. A translation of text you wrote, a reformatted table, a cleaned-up transcript of your own words: all carry the same signal as text generated wholesale from a prompt.

The mark cannot distinguish between those cases, but the people running detectors will not make that distinction either. “AI-generated” is how the result will be read by a university, a publisher, a procurement team, or a client. The signal says one thing and will be heard as another.

Set that beside two admitted facts. An Anthropic engineer has said plainly that it is not perfect and can be edited out. And the technical implementation has not been published, so nobody can independently verify how well it works or how easily it fails.

That combination produces the worst possible asymmetry. Anyone motivated to defeat the mark — the plagiarist, the content farm, the actual bad actor — will run the output through a paraphraser and be fine. Everyone who was not hiding anything, who used the tool the way it was meant to be used and copied the result straight out, keeps the mark. The measure is weakest against the people it was designed for and strongest against the people it was not.

Who actually decided

We think the framing of “an AI company made this decision for you” is close, but not quite right, and the accurate version is more uncomfortable.

The decision was made by a regulator, in a jurisdiction many affected users do not operate in, and implemented by a vendor who applied it globally because running two variants is expensive and awkward to defend. Nobody in that chain acted unreasonably. And the result is still that a capability you rent was reshaped, on a few days’ notice, by a process you had no way to participate in.

That is the actual lesson, and it is more general than watermarking. Anything you rent can be changed underneath you: the price, as we have written; the default reasoning effort, as happened earlier this year; and now the properties of the output itself. Watermarking is simply the most visible instance so far of a permanent condition.

Where this leaves the argument for owning your models

This is the part we care about most, and we want to make the case honestly rather than opportunistically.

Self-hosted open-weight models do not carry this obligation in practice. The marking requirement in Article 50 attaches to providers placing a generative system on the market, not to an organization running weights on its own infrastructure for its own purposes. So yes — running your own model means the decision about whether your output is marked stays with you.

But we would be selling something false if we stopped there. Owning the model does not exempt you from the rules; it changes who implements them. Article 50 also places disclosure obligations on deployers who publish certain AI-generated content, and those follow you regardless of whose weights you used. If you are publishing synthetic content into the EU, you have obligations either way.

The honest claim is narrower and, we think, more persuasive: owning the model does not buy you an escape from regulation. It buys you the ability to decide how you comply, on what timeline, and with what trade-offs — rather than discovering the decision in a vendor announcement and having to explain it to your customers afterwards.

That is the whole argument for self-reliance, and it has never depended on the vendors behaving badly. It only depends on them being someone else.

Back to Blog