Machine-readable marking records that a model touched the words. It cannot record whether judgment shaped what they were used for.
What Anthropic actually shipped
Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and has published how it intends to honor it.
Two mechanisms, deliberately different. Text gets an imperceptible watermark woven into the text itself at the model level, which means it is present regardless of which Claude surface produced it, and it travels with the text through copy and paste. Files get signed provenance metadata under the Coalition for Content Provenance and Authenticity (C2PA) open standard, on supported types including .svg, .png, and .jpg. A signed label signals that a file was processed by Claude and lets you detect whether the file has been tampered with.
Models launched on or after August 2, 2026 are marked at launch. Earlier models are in progress under the law's transition period. Marking applies wherever Claude is offered, worldwide, across Claude Platform (API), Claude, Claude Code, Claude Cowork, and Claude Tag, and follows the model through AWS, Google Cloud, and Microsoft Foundry. Detection for users and third parties is committed, with technical documentation forthcoming.
This is competent compliance work, applied globally rather than fenced to the jurisdiction that required it. It is also, read carefully, an argument against the use most people are going to make of it.
The most useful paragraph is in the limitations
Anthropic's own documentation is candid in a way that downstream coverage will not be.
A detected mark indicates that content may have been processed by Claude. It does not confirm provenance. The documentation names the case directly: people use Claude to proofread, translate, summarize, and convert files, and the output can carry a mark even when the underlying ideas, text, or data originated somewhere else entirely.
The failure runs the other way too. Absence of a mark proves nothing. Content may come from a model released before marking was supported, or have been heavily edited, paraphrased, or translated, or be too short a passage to carry a reliable signal, or be a file whose metadata was stripped by a format conversion, a re-save, or a screenshot.
Presence is weak evidence of authorship. Absence is no evidence of anything. A signal that fails in both directions is not proof. It is an input.
That distinction will not survive contact with the people who need it most. Schools, hiring managers, procurement teams, and platform trust systems will receive a binary from a probabilistic instrument, and the paragraph explaining why it is not a binary will not travel with the mark.
Two records, and only one of them is being built for you
Provenance and authorization are different records answering different questions.
A provenance record is retrospective and artifact-bound. It attaches to the output and reports what passed through what. It is authorship-agnostic by construction, because a model that reformats a document leaves the same trace as a model that wrote it.
An authorization record is prospective and decision-bound. It attaches to the act, not the artifact. It names the principal who permitted a specific action, the boundary the action was permitted inside, the moment the permission was granted, and the party who stays answerable when the action turns out to be wrong.
The practice has been arguing this shape for a while on the commerce side. AP2, Google's agent payments protocol, produces cryptographically signed mandates precisely because a receipt is not an authorization. The grant screen matters for the same reason: it is the surface where a consumer hands scoped authority to an agent, and it is the moment the record gets created rather than reconstructed afterward from whatever traces happen to survive.
Regulation is now producing the first record automatically, at model level, across the industry, at no cost to anyone. It will not produce the second. Nobody ships you the second. It is an internal build, and the arrival of free provenance is going to make a lot of organizations feel like they already have it.
The deployer obligation nobody is reading
One line in Anthropic's article does more commercial work than the watermark does: if you deploy Claude in your own product, you should independently assess what Article 50 requires of your products and services.
Article 50 obligations fall on providers and on deployers, and those are not the same party. A brand running an assistant on its own storefront, generating product copy at catalog scale, or answering service inquiries with a model is a deployer. The model provider's mark does not discharge the deployer's duty. It means the brand's output now carries a signal the brand did not choose, cannot remove, and has not accounted for in its own disclosures.
Marking is also becoming a distribution input rather than a compliance artifact. Platforms already read C2PA manifests, and the standard is the one Adobe and the camera manufacturers converged on. The moment a manifest feeds a ranking, labeling, or filtering decision, provenance stops being a legal question and becomes a Representation Layer question. Brands that cannot state how their own assets were produced will have it stated for them, by a platform, using a default they did not set.
What a COO should ask instead
The operational version of this mistake is asking whether AI can be detected in the work product.
That is the detectable question, not the answerable one. The Operational Agent Readiness Index question is different: for any committing action an agent takes inside the business, can you name the authorization that permitted it, the boundary it operated within, and the human accountable for the outcome? Governance Maturity does not ask what touched the record. It asks who decided, and whether the decision sat inside the fence.
An audit trail records decisions. A watermark records processing. An organization that can produce the first has little need for the second. An organization that can only produce the second has not built governance. It has been handed labeling and mistaken the two for each other.
The question underneath
A watermark can tell you a machine touched the words. It cannot tell you whether a person did the thinking.
The organizations that come through this well will not be the ones that got good at detecting AI in their own supply chain. Detection is being commoditized for them, and it was never going to answer the question anyway. They will be the ones that can point at any output, any decision, any committed action, and name the judgment behind it.
That record does not arrive in a model update. You build it, or you do not have it.