Skip to content
← all posts
·6 min read·by Dru Edwards·#ai #claude #anthropic #policy #provenance

I'm For the Claude Watermark. It's Still Dangerous.

Anthropic is now weaving an invisible mark into everything Claude writes. Provenance is the right instinct. But this mark proves a tool was used, not who did the work, and it is going to get swung like a verdict against the people who need the tool most.

A watermark on a twenty dollar bill tells you the bill is real. Anthropic just put a watermark on your sentences, and people are going to treat it like it tells them who you are. Those are not the same thing. The whole fight lives in that gap.

Quick version first, because I want this to land whether or not you work in AI. As of August 2, 2026, Anthropic started weaving an invisible mark into the text Claude generates. You cannot see it. It does not change how the writing reads. It rides along in the word choices, and it stays in the text when you copy and paste it somewhere else. Files like images get a signed tag using an open standard called C2PA. It is global, there is no opt out, and it applies across the whole lineup, the API, Claude Code, the apps. Anthropic is doing it to meet the EU AI Act, which now asks AI companies to mark their output. You can read their own explainer here.

I have been chewing on this for three days. Here is where I landed. I am for it. I also think it is dangerous. Both of those are true at the same time, and anybody selling you just one half is not being straight with you.

Why I am for it

I spend my days in clinical work and my nights building governed AI systems. When you work in places where being wrong has a real cost, you learn to love provenance. You want to know where a thing came from. You want a paper trail. A world where you cannot tell what a machine touched is a worse world to build in, not a better one.

We are also drowning. Fake reviews, cloned voices, impersonation, whole feeds of generated text pretending to be a person. A mark that says "a machine was involved here" is a small honest thing in a sea of dishonest ones. And Anthropic did not hide this. They wrote it down, they explained the limits, they shipped it in the open (TechCrunch has the rollout). Compared to a lot of what happens quietly inside these companies, disclosure is the part I want more of, not less.

Takeaway: provenance is the right instinct. Knowing what an AI touched is a feature, and I am not going to pretend otherwise just because I can see how it gets misused.

Why it is dangerous anyway

Here is the sentence that matters, straight from Anthropic's own page. The mark means content "may have been processed by Claude." It does not mean Claude wrote it. They say so plainly. If you used Claude to fix your grammar, translate a paragraph, or tighten a clumsy sentence, the mark can land on work that is yours (Forbes put it well: it proves it was used, not who wrote it).

Read that again, because the whole danger is right there. The watermark proves processing. It does not prove authorship. And I promise you it is not going to be used that way.

It is going to be used as proof. A teacher runs a paper through a checker, sees the mark, and calls it cheating. A hiring manager screens a cover letter and tosses it. A platform flags a post. None of them will stop to ask whether the person wrote the thing and used Claude to clean it up, or never wrote a word of it. The mark cannot tell those two people apart. The person on the other end is going to get treated like it can.

And think about who that hits hardest. Not the people with money for editors and ghostwriters and polish. Their work looks clean because a human did the cleanup for them. It hits the student who used a free tool to fix the grammar nobody ever taught him. It hits the person with a disability who uses AI to get real ideas onto the page. It hits the self taught builder with a good idea and no fancy words, the exact person I was a few years ago, working nights, unsponsored, learning out loud. We are about to hand every gatekeeper a stamp that reads "this person used the help," and we are going to let them read it as "this person cheated."

There is a quieter piece too. The mark travels with the text after you copy it. That is the point of it, and it is also a tracking feature. The stretch where you could quietly use a tool to help you write is ending, whether you signed up for that or not (Inc calls it the end of secret AI use). I am not a privacy absolutist. But "it follows your words around and there is no opt out" is a thing we should say out loud, not bury under the word transparency.

Takeaway: a signal that only proves a tool was used is about to be treated as a verdict on who you are. The people with the least cover pay for that first.

Both things are true

I do not have a clean side to sell you, and I am not going to fake one.

I do not want a web full of secret AI slop. So I am not against the mark.

I also do not want a kid's future decided by a stamp that cannot actually tell whether the kid did the work. So I am not for how this is going to get used.

The problem was never the watermark. The problem is what people do with a signal they do not understand. We have done this before. We treated plagiarism checkers like lie detectors. We treated a credit score like a measure of a person's worth. Every time we take a rough signal and start swinging it like a verdict, the people with the least room to defend themselves get hurt first.

What actually needs to happen

The fix is not to kill the mark. The fix is to refuse to let a "processing" signal get treated as an "authorship" verdict.

If you run a school, a company, or a platform, write this down before you act on a watermark. The mark tells you a tool was involved. It does not tell you the person did not do the work. The burden is on you to find out which, and you do not get to skip that step because a checker made it easy.

If you build these tools, the mark cannot ship without the context. "May have been processed" has to travel as loudly as the flag itself. A detector that shows the scary red result and hides the "this might just be proofreading" caveat is not a transparency tool. It is a liability you are handing to the least powerful person in the room.

And if you are one of the people about to get flagged for using a little help on work that is actually yours, hear this clearly. Using the tool is not the crime. Do your work. Keep your drafts. Keep your receipts. The mark says a machine helped. It does not say you didn't.

I am glad Anthropic is being honest about what they built. Now the rest of us have to be just as honest about what it can and cannot prove, because the people who cannot afford to be misread are the ones who find out first.