You must have seen it. Everyone is asking about the supposed ‘Claude watermark’ and what it means for them. My social media has been flooded with medical students speculating about how it will affect the quality of their academic writing, alongside tech-savvy creators trying to circumvent it through specific Claude ‘Skills’. So what is this all about?

A little background

Since 2 August, every new Claude model has embedded an invisible watermark in the text it generates. This seems to be tied to Anthropic’s signing of the EU’s Code of Practice under Article 50 of the AI Act, which requires providers to make AI output detectably machine-generated. Other major labs have made similar commitments.

What the watermark actually does

Large language models generate text one word at a time, choosing between several statistically plausible options at each step. Take “the weather today was cold and”: the model is very unlikely to pick “sugary,” but “overcast” and “grey” are both reasonable, and it barely matters to a reader which one it picks. Watermarking works by biasing that low-stakes choice: instead of picking randomly, the model uses a hidden key to nudge its selection in a way that’s undetectable to a human reader but statistically recoverable by anyone holding the key. Do that enough times across a long enough piece of text, and a detectable pattern emerges.

The mark travels with the words themselves, not with a file or a session. Copy the sentence into a different document, and the pattern remains. It’s also, by design, fairly persistent: Anthropic hasn’t said exactly how much editing it takes to strip the mark out, though the underlying technique is widely expected to weaken under heavy rewriting rather than survive it indefinitely.

How Claude's text watermark works

The nuance that actually matters

There is one important caveat we must establish early. The watermark only applies to words Claude itself selects. When Claude lightly edits or proofreads something a person has written, the model isn’t generating fresh sentences; it’s making small, targeted changes to existing ones. Since nearly all the words in the final version remain the person’s own, there is, in Anthropic’s own words, “very little (if anything)” to watermark. A single grammar pass on an otherwise human-written article may leave next to no detectable trace.

In other words, we don’t have to worry about Claude marking all your personal writing as AI-made. This said, some issues still remain.

Where the real question sits

So we know that very light use of Claude does not produce a watermark, and that more intense use of the tool may result in a stronger mark. That said, my concerns lie with what this means for the middle ground. What about users who have their own ideas for a piece of writing but use the tool to rephrase or summarise? Ultimately, most of the words in that output would be generated by Claude, which would leave a watermark. But the watermark only ever measures whose words survive into the final text, not whose thinking produced it, and those two things can pull in different directions.

Let me illustrate this with an example. Maybe it’s my recent internship at The Guardian’s legal team still dominating my subconscious, but say I’m a journalist working on the next big story. I’ve spent the last few weeks labouring over the piece, but the result is too long for the brief I was given. So I ask Claude to rewrite the passage to shorten it. The result? Potentially a watermark, sitting in a piece where the idea, the reporting, and most of the execution are still mine. Claude isn’t wrong about what’s being detected however it is simply a snapshot of the picture rather than an indication of authorship. Things get murky where one is mistaken for the other.

Now let’s flip it. Say instead I brainstorm the entire structure and argument of the piece with Claude, lean on it heavily to work out what I actually think, and then sit down and rewrite every word myself. None of the model’s words survive into the final draft, so there’s no watermark at all. On paper, this piece looks entirely human-authored. But the thinking, arguably the harder and more valuable part of writing, came substantially from the tool. If the journalist’s lightly-polished piece gets flagged while this one sails through clean, the watermark ends up rewarding whoever hides their AI use over whoever discloses a light edit.

What interests me specifically is how this intersects with some of the foundations of copyright law, namely the relationship between labour and copyright. In jurisdictions like the UK, we often apply a labour, skill, and judgement test, assessing copyright holders on the effort they put into their creation. Painer is an EU case that grappled with this in practice: the CJEU held that a photographer could make copyright-protected “free and creative choices” across the process of producing an image, choices the Court and Advocate General located roughly across preparation, execution, and the final selection of the image. As long as the creator can show meaningful involvement in that process, they’re in the clear.

Going back to my journalist example: if I prepared and executed the news article, and only used Claude to finalise it, on paper that may already be a small challenge to defend cleanly. Add a watermark sitting in the finished text, and you’ve got a piece of evidence pointing one way (these words came from the model) while the actual creative labour points another (the ideas, structure, and reporting came from me). The brainstorming example sits on the opposite side of the same problem: no watermark, but arguably a much thinner claim to the “preparation” phase Painer cares about, since the ideas themselves originated with the model.

UK law, under the Copyright, Designs and Patents Act 1988, does technically allow for “computer-generated works” with no human author, giving copyright to “the person by whom the arrangements necessary for the creation of the work are undertaken” rather than to any human creator in the ordinary sense. Worth noting, though, that the UK government has recently signalled it wants to remove this provision altogether, while preserving protection for AI-assisted work. If that goes ahead, the “no human author” category disappears, and cases like the ones above stop being an edge case sitting outside ordinary copyright law. They become the central test.

So could Claude make a case for owning its own output?

A model could point to the fact that it selects words based on a genuine evaluation of context, tone, and meaning, not a lookup table. It produces output that is, in a narrow technical sense, original: not copied from any single source, assembled through a process that responds meaningfully to the specific prompt in front of it. If human authors get credit for creative choices made under constraint (a sonnet’s rhyme scheme, a brief from a client), why should a model’s choices be categorically different?

The argument collapses, however, on the first real test that copyright law applies almost everywhere: authorship requires a human mind exercising creative judgment, not merely a process that produces varied and contextually appropriate output. The US Copyright Office has repeatedly declined to register works generated without meaningful human creative control, on the basis that copyright protects the fruits of human intellectual labour, not the operation of a machine executing statistical patterns, however sophisticated. No jurisdiction currently on the table treats the model as a candidate author in its own right. The watermark doesn’t change that; if anything, it’s a technical acknowledgement that these are, categorically, machine outputs: the opposite of an authorship claim.

So what does the watermark actually settle?

Not much, legally. It doesn’t determine authorship but it does make a certain kind of question askable in the first place: given a finished piece of writing, how much of it, in the words that survive, actually came from the model versus the person? Before watermarking, that question was almost entirely unanswerable after the fact. Now, in principle, it isn’t, even if the current tools to answer it are still limited to Anthropic and whoever it shares detection access with.

This is a bigger shift than it sounds. Copyright disputes over AI-assisted work have so far mostly hinged on self-reporting and circumstantial evidence: platform metadata, version histories, an author’s own account of their process. A persistent, word-level signal that survives copy-paste is a different kind of evidence entirely, closer to the sort of forensic trail courts are used to weighing in other contexts, and a long way from where AI-authorship disputes have generally sat until now. But it’s a trail that only catches one shape of AI involvement, and the two examples above suggest it may be the wrong one to be catching.

For journalists, students, and anyone else quietly leaning on Claude somewhere between “grammar check” and “co-author,” those are the real stakes. I am not contesting that the watermark itself is unfair or that we should remove it. Instead, we must be aware of the catch which is namely that it hands future editors, publishers, and courts a piece of evidence calibrated to measure the wrong thing, and no obvious way to tell, from the mark alone, whether they’re looking at a light polish or a ghostwritten piece, let alone the reverse.

Thumbnail photo by Brett Wharton on Unsplash