Aller au contenu principal
← Chronicles

Chronicle · Writing with the machines

I understand nothing about Claude's watermark

On August 2, Anthropic began tattooing its machines. Every text produced by a recent Claude model now contains an invisible watermark, and the images it generates carry a cryptographic seal. I have my texts corrected by these machines, I illustrate my chronicles with them, and I teach writing to people who will do the same. So I went and read what this tattoo actually does, who it catches, and who it misses.

August 11, 2026 · Reading ≈ 9 min · Milton Thomas
🔊 Listen to the chronicle · French narration by Phrasti
In one sentence

The watermark does not mark the people we are looking for, it marks the people with nothing to hide: the fraudsters already have their solvents, and it is the honest text, corrected by the machine, that will bear the mark.

I. What changed on August 2

Anthropic's official documentation is surprisingly clear for a subject like this one. Two mechanisms, two different natures.

For text: an imperceptible watermark is woven into the text itself. It is not a label pinned to the file, it is a statistical pattern in the choice of words, and it survives copy and paste. You cannot see it, and you cannot scrape it off by switching software.

For images (SVG, PNG, JPG): signed provenance metadata, to the C2PA standard, the same one the big photo agencies use. There it really is a seal on the file, and it makes tampering with the content detectable.

The scope is total: models released from August 2, 2026 mark their output from day one, older ones are being retrofitted, and it applies across every product, the app, the API, the coding tools, the cloud partners. The documentation mentions no way to switch the marking off. None.

II. Why now: the law

This is no laboratory whim. Article 50 of the European AI Act requires synthetic content to be machine detectable, and Anthropic signed the code of practice that goes with it. Brussels asked for a tattoo; Brussels has been served.

I have already written about that regulation, and I stand by what I said there: it is more reasonable than its reputation. The same article, as it happens, provides an exception for content that has been through human review with editorial responsibility. Your newspaper may use an AI without tattooing every wire story, precisely because a human signs off and answers for it. The legislator had seen the problem.

But the technical watermark does not read law. It sits in the words. And that is where things go wrong.

III. Who gets caught, who does not

Let us take stock of the official targets of the marking, in the order in which they are presented to us.

The mass producer of disinformation? He does not work with an American model under European compliance. Open models, the ones you download and run at home, mark nothing, and they are more than good enough to write propaganda.

The cheat in a hurry? The first site promising to erase Claude's watermark was online before most users knew the watermark existed. And the artisanal method remains: have the output rewritten by a second, unmarked model. Twenty seconds of laundering.

Which leaves the honest user. The one who writes his own text, his ideas, his structure, his sentences, then asks the machine to fix two commas and a past participle. What comes out of that correction is text generated by the model, and therefore woven through with its watermark. The detector will say « produced by an AI ». It will not say « thought by a human, run past a machine ». It cannot tell the difference, because in the words, there is none.

The wolves run bare. We stamp the sheep.

I impute no bad intent to Anthropic: the company is applying a law, cleanly, and documenting it, which is more than some of its competitors do. But the economics of the arrangement are what they are: the cost of compliance falls on those who stay inside the system, and the benefit of fraud remains intact for those who step outside it. An honest text, corrected, will look suspect; a dishonest text, laundered, will come out clean.

IV. The case that concerns me, and will concern you

I teach writing, and I teach writing with these machines, which is the wager this house is built on. So the question is not theoretical: when one of my students has spent three weeks on a text, has had it read over by an AI the way you have it read over by a demanding friend, and a recruiter, a professor or an examining board runs that text through a detector, what will the detector say?

It will say what the watermark tells it. And the watermark does not tell the story of the text, it tells the last tool that touched it.

I will be told that this is the price of transparency. But a transparency that fails to distinguish the assisted author from the automatic generator does not make information any clearer. It manufactures a category of suspects whose only crime was to work properly with the tools of their own age. The witch hunt against AI does not need to be supplied with factory-made witches.

V. What we decided to do, on our side

Illuminated manuscript style engraving: a mechanical techno-priest stamps a burning seal onto a file of docile sheep, while wolves slip away unmarked in the shadow of a cathedral of servers. In the corner, the golden seal of the School of the Quill.
The wolves run bare, we stamp the sheep. Image generated by AI, and signed, deliberately, with the house seal.

This chronicle is illustrated with an image generated by an AI. You know that because it is written here, and you would know it even without the C2PA seal it carries: from today, every image we generate bears our own mark, visible, in the corner, the seal of the School of the Quill.

The difference between the two gestures comes down to one word: Anthropic's tattoo is imposed, ours is chosen. Marking yourself what you stand behind is a signature, and it is the oldest trust technology in the world. Being marked without your knowledge by the tool you are using is something else, and the fact that we have no comfortable word for it is exactly the problem.

Transparency is a virtue. It deserves better than an ink stamp.

What I checked before writingHow the marking works (imperceptible textual watermark surviving copy and paste, C2PA metadata on SVG/PNG/JPG, models released from August 2, 2026, retrofit of older ones, all products and cloud partners, no documented opt-out) comes from Anthropic's official documentation, read on August 11. The legal obligation is Article 50 of the AI Act, whose code of practice was signed by Anthropic; the human review exception appears in the same article. The watermark removal site exists and was online before this text was written. I am not naming it so as not to advertise it, but it was shown to me, not described to me.

Unverified, therefore absent: the real effectiveness of the textual watermark, its robustness to paraphrase, its false positive rate, is not publicly documented, and I was not able to measure it myself. The day somebody measures it seriously, this chronicle will have a sequel.

Signé
Milton Thomas
Fontes
Cinzel / Literata / JetBrains Mono
Relevé
Chronicle · Writing with the machines