Claude's Watermark Has a Shelf Life
It marks assistance, not authorship. And assistance is about to be on everything.

Anthropic started watermarking what Claude writes. Models launched on or after August 2 weave an invisible mark into the text itself. It travels with the text when it's copied and pasted, and Anthropic says it may persist through some editing. It's applied at the model level, so it comes through no matter which Claude product produced the text.
That date is a compliance boundary, not an engineering one: Article 50 of the EU AI Act became enforceable August 2. Older models are still being retrofitted, and Anthropic applied the marking worldwide rather than run a separate path outside the EU.
It works, and that isn't my objection. My objection is that it will stop mattering, because it succeeds on a base rate that's about to eat the signal.
What the mark actually does
It marks assistance, which is a different thing from authorship. Anthropic says so in their own limitations: a detected mark shows the content was processed by Claude and isn't fully conclusive, because people use Claude to proofread, translate, and summarize, and the output carries a mark even when the ideas came from somewhere else.
So the mark answers one question. Was a model involved. That question separates things today because most text still isn't assisted, and that's the part changing fastest.
Assistance is going to be on everything
Look at what already runs through a model in a normal week. Email, internal docs, the Teams message somebody cleaned up before sending, meeting notes, project summaries, release notes, the performance review nobody wanted to write.
None of that is slop. Most of it is somebody's real work with the friction taken out.
The input side will push the rest of the way. When the assistant on your phone turns four dictated words into a paragraph, assistance shows up in places nobody would have opened a tool for. Talking is faster than typing and always was. The only reason we typed is that nothing on the other end could listen.
A mark on nearly everything distinguishes nearly nothing. Once the answer to "was a model involved" is yes almost every time, the question costs nothing to ask and returns nothing worth having. That's not a broken watermark. That's a working watermark with no remaining discriminating power.
You can prove presence, never absence
Anthropic says a missing mark proves nothing. Text that's been heavily edited, paraphrased, translated, or blended into other writing may carry no detectable signal, and short passages don't hold one at all.
Paraphrase defeats it. Run generated text through a rewriter and the mark is gone. An Anthropic engineer said as much publicly the day after the announcement: it isn't perfect, you can edit it, but it's a first step.
So you can demonstrate that a model touched something. You can never demonstrate that one didn't.
Which matters for the thing that's becoming rare. Writing composed by hand start to finish will be unusual in a few years, and unverifiable forever. Anyone can claim it and nobody can check.
Who gets caught
The mark itself is inert. The stigma comes from what gets built on top: disclosure rules, platform policies, academic integrity tools, HR systems. All of them will key to the mark because it's cheap and checkable, and all of them inherit the same defect.
Consider who gets caught. A person writes something themselves and runs it through Claude to fix the grammar. Marked. Someone generates an article wholesale, runs it through a paraphraser, and publishes. Clean, by the mechanism Anthropic documented themselves.
The careful writer trips the wire while the operation running volume walks through. That's the direction the errors run, and they'll keep running that way because presence is detectable and absence isn't.
Rules aimed at a proxy get gamed at the proxy. Everyone else just gets caught.
And this is about to stop being hypothetical. Anthropic has said a text detection API is coming, one you can run yourself. Right now the mark exists and almost nobody can read it. Once anyone can, the checking starts, and it starts during the window where a mark still looks like it means something.
What's left to check
If assistance is universal and its absence is unprovable, the question a reader wants answered doesn't change. It just stops having a shortcut.
Somebody has to read the thing and decide whether it holds up. That was always the job. The watermark was never going to do it, and in a year it'll be on everything, which is another way of saying it will be on nothing you needed to know.
I wrote this post inside BlackOps, my content operating system for thinking, drafting, and refining ideas — with AI assistance.
If you want the behind-the-scenes updates and weekly insights, subscribe to the newsletter.


