Richmond News Now

Claude’s AI Text Watermarks Raise Concerns for Students and Authors

 Breaking News
  • No posts were found

Claude’s AI Text Watermarks Raise Concerns for Students and Authors

September 08
05:51 2026
Claude’s AI Text Watermarks Raise Concerns for Students and Authors

ATLANTA, United States – September 08, 2026 – Anthropic has begun embedding statistical marks inside text produced by its newest Claude artificial intelligence models, joining a group of AI developers rolling out watermarking to satisfy new European transparency rules.

The marks are invisible to readers, add no characters to a passage, and travel with it when it is copied and pasted elsewhere. Anthropic said in an August 14 explanation that the watermark can survive light editing.

What a detected mark proves is narrower than the word “watermark” suggests. It indicates that Claude was involved in producing a passage at some point. It does not establish that Claude wrote it, and Anthropic said its system cannot separate the two cases. “It cannot distinguish ‘Claude wrote this’ from ‘Claude heavily edited this,'” the company said.

This gap sits beneath the situations in which people are most likely to reach for a detector: a student who ran an essay through a chatbot for grammar, a scholar who had one translate a source, a novelist who dictated a draft and asked for a clean copy.

Anthropic and about 190 other signatories (among them are several major AI model providers) agreed in July to the European Union’s Code of Practice on Transparency of AI-Generated Content, which requires providers to mark machine-generated text. The obligation took effect on August 2.

Anthropic said it is applying watermarking worldwide rather than only in Europe because it has no durable way yet to limit the feature by region.

How the mark is made

Large language models write one word at a time, choosing from a ranked list of plausible candidates. Where two options are equally good, the choice is settled by a random number. Anthropic’s watermark changes the source of that randomness. Instead of an ordinary random number generator, the model draws on a secret key and the preceding few words. Anyone holding the key can later test whether a passage’s word choices match the pattern the key would produce.

The method is a version of SynthID-Text, published by Google DeepMind in the journal Nature in 2024, and descends from a 2022 proposal by the computer scientist Scott Aaronson. Anthropic said internal testing showed no effect on the quality, creativity, or readability of Claude’s output, and cited DeepMind’s finding that users rating watermarked and unwatermarked Gemini responses showed no statistically significant preference.

The technique has structural limits the company acknowledges. Watermarking needs choices to work with, so it thins out on factual sentences where only one word is correct, on very short passages, and on code, which usually has to be exact. It thins out most of all on proofreading. When a person hands over their own writing and asks only for punctuation fixes, nearly every word in the returned text is the person’s, and there may be nothing for the mark to attach to.

Anthropic released a detection interface in private preview in August and updated its guidance on Sept. 1. Access is limited to organizations that EU law requires to check, including regulators, law enforcement, news organizations, fact-checkers, researchers, educational institutions, and EU civil society groups, along with enterprises carrying out their own compliance duties. The company said it plans to widen access over time.

For enterprises, watermarking also raises questions about how AI-generated material moves through automated business processes. As AI automation connects models with applications, databases and internal workflows, organizations may need clearer controls for tracking when generated content enters downstream systems.

Only two models, Fable 5.1 and Mythos 5.1, carry the mark so far. The EU law grants a transition period for models released before Aug. 2, and Anthropic said it is adding marking to those over the coming months.

Independent researchers have questioned how much of a watermark survives contact with the real world. A preprint by Xia Han, Qi Li, Jianbing Ni and Mohammad Zulkernine of Queen’s University in Ontario reported that SynthID-Text detection degrades under paraphrasing, copy-paste editing and back-translation, all of which preserve meaning. The paper has not been peer-reviewed, and its authors propose a competing scheme of their own.

Computer scientists at ETH Zurich, including Thibaud Gloaguen and Nikola Jovanovic, published work in 2024 and 2025 showing that the presence of a watermark can be detected from outside a system using ordinary queries, and that, in some configurations, SynthID-Text marks could be stripped from text more than 90% of the time. A website advertising Claude watermark removal appeared within days of Anthropic’s announcement, working by paraphrasing text through another model.

Schools have been here before

Vanderbilt University switched off Turnitin’s AI detector in 2023, and other universities followed, citing unreliable results. Stanford researchers reported that year that several detectors flagged essays by non-native English writers far more often than essays by native speakers. NBC News reported in January that a growing number of students say their work has been wrongly flagged, and that several have sued their universities over the penalties that followed.

Watermark detection works differently. It does not judge writing style, so the specific failure that penalized non-native speakers does not apply in the same form. But Anthropic has not published a false-positive rate for its detector, and its own guidance describes a positive result as a signal rather than proof. The absence of a mark, the company added, does not mean AI was uninvolved.

Universities and school districts outside the approved list cannot test student work for a Claude mark at all right now.

Publishers draw a line the mark cannot see

Book and journal publishers have spent two years trying to separate acceptable assistance from ghostwriting. Elsevier tells authors they need not disclose using AI to check grammar, spelling, and punctuation, but must disclose substantive generative use. That policy turns on what the software did. A watermark reports only that the software was there.

Writing in MediaPost, Steve Rosenbaum argued that the asymmetry favors the publisher, because a detected mark carries the weight of forensic evidence while an author’s account of how a tool was used sounds like an explanation. Anthropic’s guidance supports the author’s side of that exchange, stating that a mark does not confirm provenance and that Claude may not be the original author.

Translation is the sharper case. Anthropic said a translation produced by Claude carries a full watermark, because every word in it is Claude’s, even when the ideas and the structure belong to the original writer.

Platforms are moving regardless. Substack began rolling out scanning in July through the detection company Pangram, letting readers request an estimate of how much of a post was machine-written. Co-founder Chris Best called the problem “Claudefishing,” his term for readers investing attention in writing no person thought through. The novelist Vera Kurian has built an app, AuthorProof, for writers who want to document that a manuscript is their own.

Developers have pushed back hardest on code. A link to Anthropic’s support page collected 451 points and 425 comments on Hacker News within days, much of it from programmers. The software developer Simon Willison wrote that a requested refactor carrying an embedded pattern would not be acceptable to him. Anthropic’s later explanation said the watermark is not applied where an exact output is required, which covers most code, though comments inside code can carry it.

John Gruber, who writes the technology blog Daring Fireball, described the approach as a perversion of writing and criticized Anthropic for a page titled “How Claude marks AI-generated content” that did not describe the mechanism. The technical explanation followed three days later.

Each provider’s watermark uses its own key. A Claude detector cannot tell whether a passage came from a rival model or from a person.

This fragmentation can also matter during data migration, when large volumes of stored text and associated metadata move between systems. Provider-specific signals may need to remain interpretable after content is transferred into new databases, cloud platforms, or applications.

About Data Prism

Data Prism is a data engineering and AI consultancy specializing in data pipelines, artificial intelligence, automation, web scraping, API integration, and cloud data solutions. The company helps businesses transform raw data into actionable insights and build reliable, scalable data infrastructure

Media Contact
Company Name: Data Prism
Contact Person: Media Relations
Email: Send Email
Country: United States
Website: https://www.thedataprism.com/

Categories