On August 11, Anthropic confirmed that Claude now marks everything it produces. Text carries an invisible watermark embedded in the words themselves, one that survives copy and paste. Image files carry signed metadata. It applies worldwide, across every Claude product, with no way to turn it off.
The natural reaction is relief. If AI-generated work identifies itself, the hardest question your organization has been avoiding just answered itself. That reading is wrong, and organizations that act on it are going to get hurt.
The mark is a hint, not proof
Anthropic says plainly what the watermark cannot do. It cannot prove Claude wrote something, because people use Claude to proofread, translate, and tighten their own writing, and the mark does not distinguish a full draft from a fixed comma splice. Heavy editing can strip it. So can converting the file or taking a screenshot. Short passages are less reliable than long ones. And there is no detector yet. Anthropic has promised documentation and outside tooling, but today the mark exists and your ability to read it does not.
Then there is the part that matters most. Only Claude is marked. ChatGPT, Gemini, Copilot, and any open model someone runs on a laptop are not covered. So a positive result means AI was probably involved somewhere, at some depth. A negative result means nothing at all.
Weak signals become strong accusations
That shape is exactly the problem. Schools ran this experiment already with the first generation of AI detectors. Students got accused on the strength of a percentage score. Some of those accusations were wrong, and students who write in plain, simple sentences got flagged more often than everyone else. Teachers who had never been asked to weigh probabilistic evidence were handed probabilistic evidence and told to make a disciplinary call with it. The tools were not the failure. The absence of any process around the tools was the failure.
A watermark is better technology than those detectors were. It creates the same problem, because the problem was never the technology. Picture the version that lands on a principal’s desk in October. A teacher suspects a paper. A check comes back positive. Who ran it? Does the student get told what was found? Does “I used it for grammar” count as a defense, and who decides? If you cannot answer those questions today, the watermark did not help you. It gave a live dispute a number to argue about.
What to write down instead
The organizations that handle this well will not be the ones with the best detection setup. They will be the ones where disclosure is already normal, so detection never has to carry the weight.
A policy built on catching AI use puts you in an adversarial posture with your own people, depends on tools that keep changing, and fails the moment someone uses a model that is not marked. A policy built on disclosure asks when and how people tell you AI was involved. It works no matter which tools exist, and it turns a watermark into confirmation of something already on the table instead of a surprise.
That policy has to be specific to be worth anything. Name what gets disclosed, what does not, what is off limits, and what data never goes into these tools at all. Then add one sentence stating that a watermark is not proof. It protects the accused, and it protects whoever has to make the call.
The watermark is a fact about the tools. What your organization does when one turns up is a fact about your organization, and only one of those is yours to decide.
If your AI policy assumes you will be able to catch misuse, this announcement made that assumption weaker rather than stronger, and the section is worth rewriting before it gets tested. Let’s talk about what that looks like.