A major shift in the uses of AI — and it starts with Claude

SAMI
August 12, 2026 13 mins to read
Share

Claude watermarks everything it writes now. Read the limitations page first.

On 2 August 2026 the transparency obligations of the EU AI Act became applicable. Anthropic signed the European Commission’s Code of Practice on Transparency of AI-Generated Content and switched on machine-readable marking across every Claude surface, worldwide, not only in the EU.

The news traveled fast and the reactions were predictable: some people cheered because they think universities finally have a plagiarism detector, others cancelled their subscription in a huff. Both camps skipped the interesting part of Anthropic’s help page. It is not the watermark. It is the section titled Limitations, where the company explains, calmly and in writing, that a detected mark does not tell you who wrote the text.

I write in three languages and I use models to clean up my English. So this one is not abstract for me. Let me take it in three layers: what the law now requires, what Anthropic actually shipped, and what you should change in your own pipeline this month.

Layer 1: what became applicable on 2 August

The AI Act was adopted in 2024 and applies in stages. Article 50 is the transparency chapter, and it splits its duties between the people who build generative systems and the people who use them professionally.

Paragraph 1 covers chatbots. If your AI system interacts directly with a person, that person has to know they are talking to a machine, unless it is obvious to a reasonably attentive user given the context.

Paragraph 2 is the one everybody is talking about. Providers of AI systems that generate synthetic audio, image, video or text, including general-purpose systems, have to mark the output in a machine-readable format so it can be detected as artificially generated or manipulated.

Paragraph 4 moves the burden to the deployer. If you publish a deepfake, you disclose it. If you publish AI-generated or AI-manipulated text on matters of public interest, you label it. This one applies to your marketing team, your newsroom, your comms agency. No watermark that Anthropic ships will do this job for you.

Paragraph 5 says the disclosure has to be clear and reach the person at the latest on first exposure to the content.

Enforcement is not theoretical. Breaching the Article 50 duties exposes an organisation to fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The Act applies extraterritorially, so a company established outside the EU is in scope when its output reaches EU users. That sentence is the whole reason this article is relevant in Tunis.

The Code of Practice, and why “voluntary” is doing a lot of work in that sentence

The Commission published the Code of Practice on marking and labelling of AI-generated content on 10 June 2026, drafted by independent experts after a public consultation. It has two sections: one for providers of generative AI systems, covering provenance and detection, and one for deployers, covering visible labelling of deepfakes and of AI text on matters of public interest. You sign the sections that apply to you, and only those.

On 8 July the Commission concluded the Code was adequate for implementing Articles 50(2), (4) and (5). The AI Board agreed the next day. Final Guidelines followed on 20 July. Roughly 190 organisations had signed by the end of the month, across IT, telecom, education and retail, and about half of them were small or recent companies.

Signing is voluntary in the sense that nothing forces you. It is not voluntary in the sense that has no consequences. For signatories, the AI Office has said enforcement will focus on monitoring adherence to the Code. Everybody else keeps the full burden of convincing a national market surveillance authority, case by case, that whatever they invented instead is good enough. Declining to sign does not remove a single obligation. It removes the shortcut for proving you met them.

One detail that will save somebody a bad week: content generated before 2 August 2026 does not have to be marked retroactively. Nobody is asking you to go back and stamp last year’s archive.

Layer 2: what Anthropic actually shipped

Anthropic signed the Code as a provider of both generative AI models and generative AI systems. Both hats, which matters, because the obligations attached to each are not the same.

The commitment breaks down like this. Claude models launched in the EU on or after 2 August 2026 support machine-readable marking at launch. Models released before that date fall under the transition period the law allows, and Anthropic says retrofitting them is in progress. Marking applies to output from supported models across Claude Platform (the API), Claude, Claude Code, Claude Cowork and Claude Tag, and when those models are reached through AWS, Google Cloud or Microsoft Foundry. And it applies wherever Claude is offered, worldwide.

That last point deserves a pause. Article 50 governs AI systems placed on the EU market. It contains no mechanism that would compel an American company to mark an API call made from Tunis, Singapore or São Paulo. Anthropic applied the mark globally anyway. If you were waiting for a region flag to opt out of, there isn’t one.

Two techniques, because one is never enough

For text, a supported Claude model weaves an imperceptible watermark into the text itself. Anthropic says it does not change the meaning, quality or readability of the response, and because the signal lives in the text rather than in a file header, it survives copy and paste and, in the company’s own careful phrasing, “may persist through some editing.” Marking happens at the model level, so it does not matter which product or surface the text came out of.

For files, Claude attaches signed provenance metadata to supported types such as .svg, .png and .jpg. This follows C2PA, the open standard from the Coalition for Content Provenance and Authenticity, already used across the industry. A signed label tells you a file was processed by Claude and lets you check whether it was tampered with afterwards. Anthropic notes that signed metadata may not be supported on every cloud platform, since that depends on what each platform exposes.

Two techniques rather than one is not an implementation detail, it is the regulator’s expectation. The Code is explicit that no single marking method is sufficient on its own, which is why providers are pushed toward layering signed metadata, imperceptible watermarking, and fallbacks such as fingerprinting or logging.

The part that has not shipped

Detection. Anthropic has committed to letting users and third parties check whether a piece of text or a file carries a Claude mark, as the Code requires, and says technical documentation is coming. As of today it is not out. The company also has not published how the text watermark is embedded or how it is verified, so anything you read about the mechanism, including anything I might guess, is speculation.

So the current state of the world is a marking system that is live and a verification system that is announced. Hold that thought for the next layer.

Layer 3: what a detected mark actually proves

Anthropic’s own answer, paraphrased from the help page: a mark tells you the content may have been processed by Claude, and it is not fully conclusive on its own.

Read that again, because the gap between “processed by” and “written by” is where every downstream misuse is going to happen.

The company lists why. Claude may not be the original author, since people use it to proofread, translate, summarize and convert files, and the output carries the mark even when the ideas and the words came from a human. Content may also have changed after Claude touched it, through editing, excerpting, or mixing with other material.

The failure runs in both directions, and the second direction is the one that undercuts the enforcement fantasy. A lack of a detected mark does not mean the content is human. Anthropic lists the cases: text from a model released before marking was supported, text that has been heavily edited, paraphrased, translated or blended into other writing, passages too short to carry a reliable signal, files whose metadata was stripped by a format conversion, a re-save or a screenshot, and output from a platform or file type where that marking type was not supported.

Put those two lists side by side and you get a signal that is neither necessary nor sufficient. Present, it means something passed through Claude, probably. Absent, it means nothing at all.

Why this bothers me more than the privacy angle

The loudest complaint online was that paying customers should get unmarked output. I don’t find that argument interesting. Here is the one I do find interesting.

A student who wants to cheat runs the output through a paraphraser, a second model, or a round trip through another language, and the signal degrades or disappears. Cost of evasion: one extra step, maybe thirty seconds.

Meanwhile I write a post in French, paste it into Claude to fix my English, and publish text whose ideas, structure and errors are entirely mine, carrying a mark that a detector will read as AI-generated. Cost of my honesty: a flag I cannot remove and, until the detection documentation lands, cannot even inspect.

That asymmetry punishes non-native speakers, people with disabilities who use assistive drafting, and anyone who uses these tools the way they are actually useful, as an editor rather than a ghostwriter. Anthropic documented the limitation properly. The problem is that the limitation lives in a help centre article, and the people who will act on the mark are university administrators, HR screening tools and platform trust-and-safety systems, none of whom read help centre articles.

There is a second open question worth tracking: who gets to run detection. If verification ends up gated behind Anthropic or a short list of approved partners, then a student accused on the basis of a mark cannot independently check the claim, and neither can their institution’s appeals board. The Code requires providers to support third-party detection, so the intent points the right way. The mechanism is what we have not seen yet.

What it does not fix, despite the headlines

University plagiarism: not fixed, for the reason above. It raises the effort slightly and produces a new category of false accusations.

Deepfakes: barely touched. Images and video get C2PA metadata, and C2PA metadata dies the moment somebody screenshots the file, and screenshotting is exactly what happens to every image that goes viral. More importantly, the duty to disclose a deepfake sits on the deployer under Article 50(4), not on the model provider. That is a people and process problem in your organisation, and no vendor is going to solve it for you.

The checklist

This is the part I would actually act on. Split by who you are.

If you build on the Claude API

Anthropic states it plainly: if you deploy Claude in your own product, assess independently what Article 50 requires of your product. Their compliance is not your compliance. Concretely:

  • Work out which paragraphs bind you. A chat interface triggers 50(1) disclosure whatever the model does. Publishing generated text on matters of public interest, or synthetic media of real people, triggers 50(4) labelling on you.
  • Decide about the Code of Practice. Section 2 is the deployer section. Sign it and enforcement focuses on adherence, skip it and you carry the evidentiary burden yourself. Either choice is defensible, but make it a decision with a date and an owner, not a thing nobody looked at.
  • Inventory your models and surfaces. Marking behaviour depends on when a model launched and which surface produced the output. If you are pinned to a model released before August, do not assume its output is marked.
  • Do not put a Claude detector on your roadmap yet. The technical documentation is not published. Design the workflow so detection is a later addition, not a dependency.
  • Audit your pipeline for metadata destruction. Thumbnail generation, image optimisers, format conversion and re-saving all strip C2PA. If provenance matters in your product, test where it dies.
  • Get the labelling duty into your client contracts. If you build for an EU client, somebody has to own the 50(4) disclosure, and you want that written down before a regulator asks.

If you produce content

  • Keep your own provenance. Drafts with timestamps, prompt logs, editing history in a tool that keeps versions. When a false positive lands on you, your process is the defense, not the absence of a mark.
  • Assume translated and proofread text comes back marked. Decide per channel whether you care.
  • If you publish AI-assisted text on public-interest topics, label it yourself and stop waiting for the tooling.

If you sit in HR, education or editorial

  • Do not write a policy that treats a detected mark as proof of authorship. Anthropic’s own documentation contradicts that reading, and you can be shown the page.
  • Do not treat a clean scan as proof a human wrote it either. That inference is even weaker.
  • Write the appeal path before you need it, and decide who is allowed to run a check and on what evidence. Institutions that skip this step tend to discover their process in public, during the first dispute.

Where this goes next

Signatories are invited into two Commission task forces starting in September 2026, where implementation experience and industry practice get exchanged. Detection is the item to watch there, along with how far a provider’s mark travels before somebody downstream treats it as evidence.

Until that documentation exists, the honest reading of a Claude mark is a short sentence: something passed through Claude, probably, at some point, in some role. Anything more confident than that is not supported by the vendor who built it.

Sources

  • Anthropic, How Claude marks AI-generated content: https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
  • European Commission, Signing the Code of Practice on Transparency of AI-generated Content (FAQ): https://digital-strategy.ec.europa.eu/en/faqs/signing-code-practice-transparency-ai-generated-content
  • European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content: https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content
  • Reed Smith, on the adequacy decision and the final Article 50 Guidelines: https://www.reedsmith.com/our-insights/blogs/viewpoints/102nbz0/transparency-obligations-for-ai-generated-content-the-code-of-practice-adequacy/
  • Wilson Sonsini, EU Commission publishes AI transparency Code of Practice: https://www.wsgr.com/en/insights/eu-commission-publishes-ai-transparency-code-of-practice.html
  • Faegre Drinker, on adequacy, extraterritorial scope and penalties: https://www.faegredrinker.com/en/insights/publications/2026/7/eu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations
  • Tech Policy Press, The EU’s AI Transparency Code of Practice, explained: https://www.techpolicy.press/the-eus-ai-transparency-code-of-practice-explained/
  • Euronews, on global application and the penalty ceiling: https://www.euronews.com/next/2026/08/11/eu-compliance-delivered-globally-anthropic-to-watermark-claudes-output-worldwide

Leave a comment

Your email address will not be published. Required fields are marked *