First, understand what it actually is

On 11 August 2026, Anthropic announced that all of its models launched from 2 August onwards embed a statistical watermark in the text they generate. The measure implements the Code of Practice on Transparency of AI-Generated Content, attached to the EU AI Act and signed in July 2026 by roughly 190 organisations — including every major model provider. With no reliable way to restrict the mechanism to Europe, Anthropic applies it worldwide.

Despite what the word "watermark" suggests, there is nothing in the text. No invisible characters, no metadata, no signature hidden between the lines. The marking is purely statistical. As Claude writes, it constantly makes low-stakes micro-choices: "however" or "nevertheless", "essential" or "critical", one phrasing rather than another. The technique it uses — SynthID-Text, published by Google DeepMind in 2024 and building on an idea Scott Aaronson proposed in 2022 — drives the randomness of those choices with a secret key and the preceding words. Each choice, taken alone, is unremarkable. Across a few hundred words, the sequence of choices becomes verifiable by anyone who holds the key. Readers see nothing: internal tests and DeepMind's own found no measurable difference in quality or readability.

You also need to understand what the watermark does not do. It doesn't mark code (too few interchangeable choices), short texts (too few decisions to form a signal), or factual answers with only one correct wording. It survives light editing, fades as rewriting intensifies, and disappears if every word is replaced. Above all, it doesn't prove what people will inevitably claim it proves: Anthropic itself acknowledges that detection establishes only that "Claude probably participated in the content". It cannot tell "Claude wrote this" apart from "Claude fixed the spelling of this". It says nothing about other AI systems, or about the human share of the text.

The point that changes everything: the watermark proves a text passed through Claude. It doesn't prove who wrote it, or in what proportion. Every cost that follows flows from this nuance — one that most people running detection will ignore.

What it costs writers

The presumption of fraud, first. Anthropic has announced a detection API. The day it opens, employers, clients, newsrooms and schools will be able to submit any text. The result will be a binary signal — "Claude probably participated" — where reality is a continuum. The writer who has Claude tighten a text that is entirely her own will be flagged exactly like someone publishing raw generations. In client relationships already tense around AI, that nuance-free signal installs suspicion by default — and it's the writer who will have to justify themselves.

The cost of working around it, next. Three strategies exist, all expensive. Rewrite deeply: you lose the very time AI was supposed to save — with a delicious paradox, since the watermark fades precisely as the text stops being AI's (Anthropic says it itself: if every word has been replaced, can you still call the text AI-generated?). Flee to unmarked models: temporary relief at best, since the Code's signatories will all follow. Run the text through an automatic paraphraser: an arms race in which quality degrades with every pass, and you pay a second tool to undo what the first one did. In all three cases, the tax falls on the legitimate user; the industrial-scale fraudster will always find the exit.

The false comfort of detectors, finally. The absence of a watermark doesn't prove a text is human: models released before 2 August, competitors not yet equipped, rewritten text. Its presence doesn't prove cheating. But institutions will treat the signal as proof — we've seen the false accusations that style-based "AI detectors" produced in universities. This time the signal will carry a "cryptographic" aura, and therefore feel incontestable. It may be incontestable as a measurement; it is not incontestable as an interpretation.

What it costs Claude (and Anthropic)

Trust. The backlash was immediate: furious Reddit threads, subscription cancellations claimed on X. The message sent to professionals paying for a writing tool is harsh: your deliverables are now flaggable. Let's be honest about the facts — the watermark encodes nothing about the user: no identifier, no organisation, no trace of the conversation; the key leads back to no one. But in matters of trust, perception rules, and the perception that "my tool snitches on me" has already taken hold among part of the user base.

The first-mover's premium. In the short term, sensitive usage will migrate to pre-August-2 models, local open source, or less zealous providers. Anthropic is playing the regulatory game first and globally, when the text only demanded European compliance — and is therefore paying a pioneer's premium its competitors haven't yet provisioned. That distortion will fade as others follow; until then, it's a real, accepted cost.

The operating cost of doubt. Keeping the marking robust against paraphrasers, running a detection API, governing its use — who gets to test whose text? — and absorbing the disputes born of misreadings: Anthropic becomes, de facto, the involuntary referee of millions of attribution conflicts that are none of its business. That may be the most durable cost of all: having created a signal that others will brandish in its place, to make it say what it does not say.

What real transparency would look like

The transparency readers need isn't covert marking; it's an owned declaration. Three building blocks already exist. C2PA metadata, first: Anthropic already applies it to images Claude generates — a signed, explicit, verifiable credential attached to the file rather than hidden inside the content. The text equivalent would be declared provenance, carried by the document, that the author chooses to show. The usage statement, second: "written with the help of…" says more than any watermark, because it says who stands behind the text. Internal policies, third: in the teams I train, I recommend writing down in black and white what may be generated, what must be reviewed, and who signs. A hidden watermark satisfies a regulator; a usage declaration builds trust. Don't wait to be "detected": own the co-writing, and keep the human review that makes a text yours.

Transparency, then: this article was co-written with Claude — research, structure, phrasing — then directed, reviewed and owned by me. It may even carry the watermark it describes. The difference is that you didn't need a key to know that: I told you.

Sources