As Anthropic begins adding invisible watermarks to Claude-generated text, concerns are growing over copyright and privacy. [Photo: Reve AI]

Anthropic has begun adding hard-to-detect watermarks to text generated by Claude, heightening concerns in the tech industry over copyright and privacy.

On Aug. 13, overseas media outlets including Business Insider reported that Anthropic said it would directly insert hard-to-detect watermarks into outputs from some Claude models this week. The watermark remains even after text is copied and pasted, and it may remain after some edits. Anthropic said the measure is intended to distinguish human-written text from text generated by artificial intelligence. It did not disclose the specific technical method.

Tech investor Bill Gurley (빌 걸리) said if only Anthropic can identify the watermark, the company would effectively become "judge, jury and prosecutor". Anthropic said it plans to provide a free application programming interface so users and third parties can verify it directly.

Some developers said they were concerned the watermark could affect the quality of Claude's responses. They said if the method flags AI generation through combinations of certain words or expressions, sentences could become unnatural. Anthropic said the watermark does not change the meaning, quality or readability of Claude's responses.

Concerns were also raised about the scope of application. Critics said even lightly editing human-written text with Claude, such as grammar correction, could be marked as AI-written. Anthropic said the watermark only means Claude processed the text and does not mean Claude wrote it from the start. It said the mark could remain on text that has undergone proofreading, translation or summarisation.

Anthropic also acknowledged this. "People often use Claude for proofreading, translation, summarisation and file conversion," Anthropic said. "Even if the original idea, text or data came from elsewhere, Claude's indication may remain on the output," it added.

That means Claude could leave a mark even on work that merely polishes an original text, even though the European Union's AI Act explicitly excludes such minor editing tasks from watermark obligations. Critics said if a watermark cannot distinguish between large-scale generation and edits as small as changing a single comma, it could end up marking content that the law does not regulate.

Privacy concerns were also raised. Microsoft executive Steven Sinofsky (스티븐 노프스키) cited data retention and the right to have private thoughts without a digital trail as key issues. Software engineering educator John Crickett (존 크리켓) said if AI-generated code carries a watermark, it could become harder to sufficiently prove human contributions when asserting copyright.

Where does the watermark apply, and to what extent

Anthropic said the move is to comply with the EU AI Act. The law requires providers of AI systems to attach watermarks to audio, image, text and video outputs generated or manipulated by AI, and it applies to models released after Aug. 2. Models released earlier are given a grace period until December 2026.

Anthropic said it will apply the marker from the outset to new models offered worldwide, not only in the EU. It will insert an imperceptible watermark into text outputs, and for other types of generated files it will include provenance metadata containing digital signatures where supported. For non-text content, it said it will apply the C2PA metadata standard. It added that watermarks may not be supported on some platforms or features.

Watermarks have been applied globally to supported models since Aug. 2. Google applies its own technology, SynthID, to generative content, and OpenAI is also known to use SynthID for supported images and audio. X, formerly called Twitter, also attaches a "Made with AI" label to content it judges to have been generated or manipulated by AI. One such label was attached on Aug. 13 to a post announcing the resignation of White House press secretary Karoline Leavitt (캐롤라인 레빗), who is set to step down, but it later disappeared.

Some view watermarks positively. They could help reduce so-called "self-cannibalisation," in which AI systems retrain on content they generated themselves and performance deteriorates.

Questions have also been raised about effectiveness. Text watermarks work by subtly biasing the pattern of words a model chooses across an entire document and can only be confirmed with dedicated tools. In the process, a model may choose somewhat unnatural expressions rather than optimal words to maintain the watermark signal.

Even text with a watermark could lose the mark if it is pasted into another chatbot system and edited. Images and video can also have marks removed with screenshots or recording, or with common metadata editing tools. Critics said if Anthropic discloses its detection method, it would not be difficult to build systems that remove it.

Watermarks convey limited information

Critics also point to the limited information the watermark itself conveys. "A detected mark is only a signal that the content was processed by Claude, and it is not fully conclusive evidence," Anthropic said.

That means the mark indicates only that the content may have been processed by Claude, and it can appear even on content Claude did not generate. "Even if a mark is not detected, it does not mean AI did not generate or process it," Anthropic said.

If general readers cannot distinguish between "processed text" and "fully generated text", there are concerns that human writing that underwent light editing could be treated the same as fully AI-generated material.

Another provision of the EU AI Act, Article 50(4), sets out when those who publish content must explicitly label it to the public. Under the provision, even text written entirely by AI does not require a separate label in most cases. AI-written novels or marketing copy do not need labels.

However, content intended to "inform the public about matters of public interest" must be labelled if a responsible editor has not reviewed it. As a result, watermarks could remain at the model stage on virtually all processed content, but at the public labelling stage even AI-written text may not be labelled simply because an editor reviewed it.

EU officials say the transparency requirement is meant to prevent situations that "undermine trust in the information ecosystem and increase new risks of large-scale disinformation and manipulation, fraud, impersonation and consumer deception". European Commission guidance said, "People must know whether they are interacting with AI or being exposed to AI-generated content," adding that this would allow informed judgments, adjustment of trust and reliance on AI, and avoidance of disinformation or deception.

Critics also said there is a gap between the intent of the system and how it is applied, because even AI-generated articles on matters of public interest may not carry a reader-facing label if an editor reviews them.

Anthropic said it will continue to develop watermarking and detection technology to meet the EU's requirements. If the relevant marking does not function properly, fines of up to 15 million euros or 3 percent of global annual revenue, whichever is greater, could be imposed under the AI Act.

Keyword

#Anthropic #Claude #EU AI Act #SynthID #C2PA
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.