Marking Is Not the Story
Anthropic marked Claude's output worldwide this week. The argument since has been about removing it. That is the small story. The bigger one is that a right every person held by default just got answered by an obligation routed through 190 companies.
Anthropic switched on invisible marking for Claude's output this week, worldwide, and the argument since has been about whether you can strip it out. That is the small version of this story. The mark cannot prove you wrote something. It cannot prove you didn't.
Anthropic's marking approach settles nothing and guarantees only that the question gets asked, years from now, under rules nobody has written yet.
The mark records processing, not authorship
Read Anthropic's own language carefully. A detected mark signals that content was processed by Claude. Not generated by it. Processed, whatever that means.
Generation and processed are different categories and that gap is where most working operators like you and me live. You write a paragraph. You ask a model to tighten it. You take back a cleaner version of your own sentence. Under the mark, that paragraph is indistinguishable from one the model wrote from nothing. Same signal. Same artifact. No mechanism separates the two.
The company says as much. Anthropic states that a detected mark provides a signal that content was processed by Claude but is not fully conclusive, and that marks may be absent if content was edited, paraphrased, or generated by models released before marking shipped. This is a one-way disclosure likely using something similar to the Gumbel Softmax scheme developed, at least in part, by Scott Aaronson.
The failure mode that protects the model provider is the story that gets published: marks can go missing. The failure mode that exonerates a writer does not.
There is no published false-positive rate. There is no published algorithm. If you want to know whether your own work carries a mark you did not intend, you cannot find out.
That asymmetry is not an oversight. It is the shape of the entire regime.

What the law actually says
The statute does not say 'watermark'. Article 50(2) of the EU AI Act requires that providers of systems generating synthetic audio, image, video or text ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Marking is the category. Watermarking is one implementation of it, alongside metadata, cryptographic provenance, and fingerprinting. Everyone online is using the proxy term.
The word people are arguing about is not the word in the law.
To be fair, the timeline is also softer than the coverage suggests. Article 50 applies from 2 August 2026, but the European Commission is explicit that systems already on the market get until 2 December 2026 to meet the marking obligation, and that content generated before 2 August does not need to be labelled retroactively. Penalties reach 15 million euros or 3 percent of worldwide annual turnover, whichever is larger.
Note what that means for a US operator. Anthropic has chosen to make European obligations global. Compliance chose the widest possible surface because maintaining two output streams costs more than marking everyone. Nobody in Seattle voted on this, and nobody in Seattle had to.
The exemption you can't reach
The statute carves out the exact case I described at the top. Article 50(2) does not apply where a system performs an assistive function for standard editing, or where it does not substantially alter the input data or the meaning of it. Tightening your own paragraph is that carve-out almost word for word.
But, you cannot get to it... marking is applied at the model level, upstream of any distinction between writing a paragraph and cleaning one up. By the time your edited sentence exists, the signal is already in it.
The exemption is in the law and not in Anthropic's product.
Legislators debated this case, wrote an exception for it, and published the text. Then the obligation was implemented in a way that ignores the exception, and the implementation is what actually governs your work. That gap was a deliberate choise and is the entire argument of this piece, sitting in one subclause.
Nobody can check it

About 190 organizations signed the Commission's Code of Practice on Transparency of AI-Generated Content by the end of July. Google, Meta, Microsoft, Mistral and OpenAI all appear on the provider section, which covers machine-readable marking and detection. xAI was the only major model builder to stay out, though staying out of a voluntary code does not exempt anyone from the law underneath it.
One of those 190 has explained how it is meeting the obligation.
Google is expected to introduce measures under the code, but has not set out how the requirement applies to text produced by Gemini. OpenAI has not said how it will mark text or whether it will use the same method. The company taking the most criticism this week is the only one that said what it was doing. That is an uncomfortable finding.
It gets worse for verification. The Code requires providers to supply a free detection tool. Anthropic has said it plans to publish technical documentation so third parties can detect its marks, but until that documentation arrives no developer can build detection into their own pipeline.
So the mark is live and the checker is not. For now the only party who can read the signal is the party who wrote it.
The right this displaces
I wrote about the mechanics of owning what you build in IP Guardian, and the line that matters most now is one I wrote almost in passing:
copyright is automatic, and it does not require disclosure of how the work was made.
Both halves matter. It attaches the moment you create something. It attaches to everyone, without application, without negotiation, without a signature from a senior executive. And it never once asked you to declare your method.

That is what a right looks like. Granted by operation of law, to every person, by default.
Marking reverses both. It is not automatic to you, it is applied to you. Not granted to constituents, negotiated with providers. A right that every person held by default has been answered by an obligation routed through about a hundred and ninety companies.
Filing a patent creates competition as often as it prevents it, because filing means disclosing. You hand your method to the world in exchange for a claim.
Marking asks for the disclosure and hands back nothing. No exclusivity. No claim.
You declare provenance and receive a signal you cannot read, cannot verify, and cannot remove.
Doubt without resolution
The obvious rebuttal is that a non-conclusive mark is a weak mark, and a weak mark cannot support anyone's claim against you. That rebuttal has the logic backwards.
A conclusive mark would be survivable. It would say this was machine-generated or it was not, and you would plan around the answer. What exists instead is a permanent signal that raises the question of authorship and cannot answer it. It travels with the text. It survives copy and paste. It will still be attached in 2031, when someone with an interest in the answer goes looking, under a legal regime that does not exist yet.
Doubt without resolution is worse than either certainty.
Certainty you can price. Doubt you carry.
For the person who has spent a year building a harness, that is the exposure. Not that a provider will claim your work. Their terms say the opposite and courts do not let parties reach back and un-assign rights already granted. The exposure is that you now hold an asset with a permanent question attached to it, and the question gets adjudicated by people who were not in the room when the mark was designed.

The same pattern, twice, in the same month
The EU regime is not the only place this happened this summer. It is not even the clearest example.
On August 4th the White House convened the major labs to review a completed framework for evaluating frontier models before public release, and then declined to publish it. The details stay with the companies that may choose to participate. Chris McGuire of the Council on Foreign Relations called that decision "baffling" and wrote that we cannot have secret, voluntary rules governing the most important technology in the world.

The framework defines a covered frontier model as closed-source with state-of-the-art capabilities and national security risks, and offers no clear definition of what counts as state-of-the-art or as a national security risk. Open models are excluded outright.
Now the part that should bother you regardless of your politics.
Congress writes law. The executive enforces it. Courts interpret it. A pre-release review process for the most consequential technology of the decade is the kind of thing that goes through Congress, and this one did not.
The defense is that the framework is voluntary, and the executive order explicitly disclaims any mandatory licensing or pre-clearance requirement. That defense is correct and it is the problem. Voluntary is the legal architecture that keeps the program inside executive authority. It is also what strips out every accountability mechanism that attaches to real rulemaking. No notice and comment. No judicial review. No congressional oversight. A gate on frontier releases, built to be immune to the checks that apply to gates.
I wrote in The Inverse Bailout that the government needs the labs more than the labs need the government. This is what that dependency produces. Two governments, one month, both routing decisions of enormous public consequence through private negotiation with a handful of firms, because the firms are where the capability lives and the legislature is nowhere near ready.

The strongest case against me
The best argument for mandatory marking is not about slop. It is about collective action.
In April 2023 OpenAI surveyed its own users about watermarking. Roughly 30 percent said they would stop using ChatGPT if OpenAI deployed watermarks and a competitor did not. Internal documents rated the tool it had already built at 99.9 percent effective when applied to enough generated text. OpenAI shelved it. This month it signed the European code requiring the thing it shelved.
That is the case for the law. Marking was commercially impossible for any single provider to adopt unilaterally, because the 30 percent walks to whoever does not mark. Only a rule binding everyone at once makes it survivable. The regulation exists precisely because the market failed to produce the outcome, and pointing at the market as the better mechanism ignores that the market already answered and the answer was no.
I accept the mechanism. It is real and the number proves it.
What marking does not establish is the work being defended. That argument justifies universal marking. It says nothing about whether the mark should be unreadable, whether its false-positive rate should be private, whether the detection tool should ship after the mark goes live, or whether the obligation should be negotiated with providers rather than legislated with a public record. A collective action problem is an argument for a rule. It is not an argument for that rule being opaque.
And the 30 percent points somewhere else too. Those users were not all bad actors. Some of them were people who understood that a permanent, unreadable signal on their work was a risk they had not priced. They were early.
What this EU regulation can't reach
Open weights are not exempt. That surprises people. The AI Act's open-source carve-out explicitly excludes Article 50, and the Commission's final guidelines confirm open-source systems are covered, with the territorial trigger being where output is used rather than where the company sits.
But, the obligation still cannot reach them. It binds providers who place a system on the EU market under their own name. Pull weights down and run them on your own hardware and there is no provider in the loop to bind, which is why self-hosted models and providers outside the EU may simply emit unmarked content, leaving no mark to read.

This is the DRM story again, beat for beat. Twenty-five years of copy protection, cracked continuously the entire time, and it still shaped every compliant product in the market. Strippable and durable were never opposites. The control does not have to work on everyone to work on the people who follow rules.
So the burden lands on exactly one group. Not the bad actors, who route around it in an afternoon. The operator running a licensed model inside a real business, the one who built the harness and pays for the seats and would never think to strip anything.
There is a smaller irony sitting inside the larger one. The Commission's guidelines exempt source code, which means agentic developer tooling produces unmarked output while the paragraph explaining the code carries a signal. Your build is clean. Your README is marked.
Who decides what you can claim
I am not moving off these tools. I use them daily for argument, research, survey design, automation, and most of the operating work of a small company, and the productivity is not in question.
What changed is that provenance is now a design decision.
Which work passes through which system, and when, and what that leaves attached to it. I never had to ask that before. Copyright never asked how I made anything.
The timing here is arguable and I will not pretend otherwise. Older models have until December. The detection documentation may land next month and answer half of this. What is not arguable is the direction. Capability now sits with a small number of organizations, governments have discovered that regulating those organizations is faster than legislating for everyone, and the mechanism they reached for first was one that attaches a permanent signal to your work and hands you no way to read it.
The question the next decade settles is not whether AI content gets labeled. That is done.
The question is who gets to decide what you are allowed to claim as yours, and whether that decision is made in a chamber with a public record or in a room with about a hundred and ninety signatures and no minutes.
Marking was the easy one. Low stakes, broad sympathy, a problem most people agree exists. That is what you pick when the point is to prove the mechanism works. Whatever comes through that channel next will not be a watermark, and it will not need a new argument.




