AI Watermarks Are Here: The New Law for AI Content

AI Watermarks for Law: Law for AI visual featuring a laptop displaying an AI-generated watermarked seal next to scales of justice, legal books, and a printed contract.

Anthropic announced on August 11 that Claude will start marking everything it writes. Not just images, not just files. Text too. Every response, everywhere, worldwide. If your firm uses Claude for drafting, research summaries, or client communications, this is one of those updates that sounds small in a press release and turns out to matter quite a bit once you sit with it.

Here’s the thing. Most firms wrote their AI use policy assuming AI output was invisible, indistinguishable from anything a person typed. That assumption just got a little shakier. Not gone, but shakier. And it’s happening because the law for AI content is no longer a draft proposal sitting in committee somewhere. It’s live, it has penalties attached, and it’s already shaping how the biggest AI labs ship product.

What Anthropic Announced

Anthropic signed onto the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI Generated Content. That’s a mouthful, so here’s the plain version: AI companies operating in the EU committed to labeling content their models generate, so people can tell what came from a machine. It’s a concrete example of what the law for AI transparency really looks like once it moves from statute text into a shipped product.

Anthropic’s approach has two parts. Claude models launched on or after August 2, 2026 embed an invisible watermark directly into generated text. Separately, when Claude generates a file, like an SVG, PNG, or JPG, it attaches signed provenance metadata using the C2PA standard, the same open framework a lot of the industry already uses for content credentials.

 

What stood out to me reading Anthropic’s own explanation of how the marking works is how upfront the company is about the limits. Anthropic says flat out that a detected mark is a signal, not proof. It tells you content may have passed through Claude. It doesn’t tell you who came up with the ideas, and it definitely doesn’t confirm nothing changed after the fact. That kind of honesty is refreshing, though it also means the compliance story here is messier than a press release headline makes it sound.

Older Claude models aren’t left out forever, either. Anthropic says it’s working on retroactive marking support for models released before August 2, so this isn’t a one-time snapshot. It’s the start of an ongoing shift in how the law for AI transparency gets implemented at the model level, not just in a policy document nobody reads.

How the Watermark Works

The text watermark is woven into the output at the model level, so it doesn’t matter which Claude product you’re using: the API, Claude.ai, Claude Code, Claude Cowork, Claude Tag, all of it. You won’t see anything different in the response. The wording, the quality, none of that changes.

Anthropic says the mark travels with the text through copy and paste, and it can survive some editing. Some, not all. Heavy rewriting, translation, or blending Claude’s output with your own writing will likely weaken or erase it. Short passages don’t carry enough signal either, so a two-sentence email probably won’t hold a reliable mark even if Claude wrote every word of it.

Files work a bit differently, and honestly, more solidly. The C2PA metadata is cryptographically signed, which is a stronger guarantee in some ways: either the signature checks out or it doesn’t, and tampering breaks it visibly. But it can also be stripped outright through a screenshot, a format conversion, or just resaving the file in a different program. Nothing here is bulletproof. It’s layered, imperfect, and very much still being built out.

How to Check for the Watermark Right Now

This is the part everyone wants to know, so let’s be straight about it: it depends on what kind of content you’re looking at.

  • For images and files, this works today. Claude’s C2PA provenance metadata can be verified right now using standard C2PA tools, like the open source c2patool or a Content Credentials viewer. Upload the file, and if it carries a valid, unaltered signature, the tool will show you it was processed by a supported Claude model. This is the same verification ecosystem several major platforms are building into search and browser tools, so it’s not some obscure workaround. It’s becoming fairly mainstream, fairly fast.
  • For text, it’s not available yet. Here’s where I’d manage expectations. There is no public tool today that can read Claude’s embedded text watermark. Anthropic has committed to supporting third party detection and says it will publish technical documentation, but as of this writing that documentation hasn’t shipped.

 

If you see a product online claiming it can detect “Claude’s watermark” in a block of text, be skeptical. What it’s doing instead is running a general AI writing classifier, the same kind of pattern matching tool that’s been guessing at AI generated text for a couple of years now, with the usual false positive and false negative problems. That’s not the same thing as reading Anthropic’s real signal, and right now nobody outside Anthropic can do that.

So, for the moment, if a document lands on your desk and someone asks whether AI touched it, the honest answer is this: you can check the files, but you can’t yet check the words. Keep that distinction straight when you’re advising a client or reviewing your own team’s work, because it’s an easy detail to gloss over under deadline pressure.

The Law for AI Content Is Article 50, and It's Already Live

The law for AI generated content isn’t hypothetical anymore. Article 50 transparency obligations took effect August 2, 2026, and the penalties for getting it wrong are not small: up to fifteen million euros or three percent of global turnover, whichever is bigger.

For law firms, the practical question isn’t really about Anthropic’s engineering choices. It’s about what your own disclosure obligations look like now that the underlying law for AI transparency has real teeth behind it. If your firm produces client facing content, marketing material, or work product using Claude, you’re operating inside a framework that increasingly assumes AI involvement should be knowable, even if the tooling to prove it isn’t fully built yet.

There’s also a flip side worth thinking through opposing counsel or a regulator asking whether a document was AI generated. Right now, a “no mark detected” answer proves less than it sounds like it does. Absence of a detectable watermark doesn’t mean AI wasn’t involved. It might just mean the passage was too short, too heavily edited, or produced by an older model that predates marking support. Firms that already treat AI risk mitigation as an ongoing discipline, rather than a one-time policy memo, will handle that conversation a lot more comfortably than firms scrambling to explain a gap after the fact.

Why This Matters Even If You Never Touch the EU

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident

Providing Smart security

I'd guess a good number of firms reading this aren't EU regulated and are tempted to file this under "not my problem." I get the instinct, but I don't think it holds up here.

 Anthropic applied this marking globally, not just to EU traffic. That’s a deliberate choice, and it tells you something: transparency requirements written for one jurisdiction are quietly becoming a baseline expectation everywhere, the same way GDPR reshaped privacy practices well outside Europe. State AI laws in the US are moving in a similar direction and more will follow. Treating this as a European compliance footnote is, I think, a mistake most firms will end up regretting.

It’s also worth remembering that watermarking is a downstream fix for an upstream governance gap. If your firm doesn’t already have clear guardrails around what data goes into tools like Claude or Copilot in the first place, a watermark on the output doesn’t solve the harder problem underneath it.

What Your Firm Should Do This Week

A few concrete steps, none of which require waiting on Anthropic’s detection tooling to ship.

  • First, revisit your AI use policy and ask whether it assumes AI output is invisible by default. If it does, that assumption is aging fast, and the law for AI disclosure is only going to tighten from here.
  • Second, build a habit of checking file level provenance where it’s available now, particularly for anything client facing or filed with a court or regulator. It’s a five-minute check that costs you nothing.
  • Third, don’t treat watermark detection, current or future, as a substitute for actual data governance. A mark tells you something touched Claude. It doesn’t tell you what data went in, who reviewed the output, or whether client confidence was handled properly along the way. That’s a policy and process question, not a technical one, and no watermark solves it for you. This is the same blind spot we’ve flagged before when it comes to [ agentic AI tools operating inside a firm’s environment: the technical signal and the actual governance discipline are two different things, and firms that confuse one for the other tend to find out the hard way.
  • Fourth, keep an eye on Anthropic’s forthcoming technical documentation on text detection. When it ships, the calculus here changes again, and firms that already have a governance framework in place will adapt faster than the ones scrambling to build one from scratch.

The law for AI transparency is moving quickly, and watermarking is just the latest piece of it, not the last one. Firms that treat this as a compliance checkbox will miss the bigger shift underneath it: AI provenance is becoming a standing question in professional responsibility, not a one-time technical update you handle once and forget about.

As TechCrunch’s coverage of the announcement  notes, Anthropic almost certainly won’t be the last major lab to make a move like this, and the law for AI content will only get more detailed from here. Getting ahead of it now beats catching up later.

If you’re not sure whether your firm’s current AI governance holds up against where this is heading, that’s worth a real look before it becomes a real problem. Start with an AI Readiness Assessment and get a clear picture of where the gaps are.

Recent Posts

Have Any Question?

Call or email Cocha.  We can help with your cybersecurity needs!

About the Author:

Picture of Steve Combs

Steve Combs

Co-Founder & Managing Director, Cocha Technology

Steven is a fractional CIO/CISO with 30+ years of enterprise IT and security leadership. He has built AI governance frameworks for organizations with 1,700+ users, led enterprise Microsoft Copilot deployments, and conducted security assessments across law firms, energy companies, financial institutions, and PE-backed manufacturers.