Starting soon, all text that’s either generated or “processed” by Claude will bear invisible AI watermarks that can be detected with the right tools, a move made in response to new European Union regulations regarding the disclosure of AI-generated content.
Anthropic’s wide-ranging pledge to watermark Claude-generated text (including code generated by Claude Code) goes above and beyond the mandates in the EU AI Act, which took effect earlier this month. And while there’s been some pushback from Claude users who have called the new policy “unethical” and even “disgusting,” the overall consensus seems to be that watermarking AI content, including generated or even just edited text, is a good thing.
Personally, I’m cautiously optimistic. When used responsibly, AI can be a valuable tool, and part of using AI responsibly is being candid about it. If I use Claude to polish a cover letter to an employer, I should disclose it — and I’m more likely to disclose it (or skip using Claude) if I know that employer can easily look for Claude watermarks. It works both ways, too. If our employers send us company memos penned by Claude, they should say so, and soon we’ll be able to check for ourselves.
That’s the bird’s-eye view of how the EU AI Act could work, as implemented by Anthropic. (Google and Meta have signaled their intentions to sign the act, while OpenAI says it’s taking a “layered” approach to “content provenance.”) Look closer, though, and there are loopholes, carveouts, and caveats aplenty.
For example, while Claude will soon watermark all the text it generates, including code, the EU rules actually exempt computer code from their watermarking provisions. There’s also an exemption for “standard editing,” as well as a provision that AI providers need only implement watermarks “as far as this is technically feasible,” which seems to leave a fair amount of wiggle room.
Aside from the loopholes, there are also practical gotchas. While Claude watermarks are designed to survive a simple cut-and-paste or even light editing, there’s nothing stopping an AI slop purveyor from washing Claude text through an open-weight model that doesn’t mark its output. In other words, you can’t prove text was actually written by a human just because it lacks an AI watermark (a catch that Anthropic openly admits).
Overall, I think the EU AI Act is making an important gesture towards transparency and accountability when it comes to AI usage. We should be honest about when we use AI. But will the EU AI Act — or AI watermarking in general — stop AI slop? Let’s not kid ourselves.
Understanding AI Watermarks
AI watermarks are embedded signals, often invisible to the naked eye, that identify content as machine-generated. In text, they can take the form of subtle statistical patterns in word choice, syntax, or character sequences that a detector can recognize. For images, they might be pixel-level alterations invisible to humans. The idea is to create a reliable trail of provenance, letting platforms, employers, and readers know when they’re looking at AI output.
The technology has been in development for years. OpenAI, Google, and Meta have all experimented with watermarking schemes. But until now, adoption has been voluntary and inconsistent. The EU AI Act changes that by making watermarking a legal requirement for high-risk AI systems and general-purpose models. Anthropic’s move is one of the first major compliance efforts to make headlines.
Nevertheless, the technical challenges are formidable. Watermarks must be robust enough to survive common transformations like copy-paste, paraphrase, or resizing. But if they’re too robust, they can degrade the quality of the content. Conversely, if they’re too subtle, they can be stripped by a bad actor running the text through another language model. This is the central tension that makes watermarking an imperfect solution.
The EU AI Act and Its Loopholes
The EU AI Act, which began applying this month, is a landmark regulatory framework. It requires providers of AI systems to ensure that synthetic content is “marked in a machine-readable format” and detectable as artificially generated. However, the act contains explicit exemptions that weaken its reach.
One notable exemption is for computer code. The act states that the watermarking obligation does not apply to “computer code,” which is odd considering that many AI assistants now generate substantial amounts of software. Anthropic’s decision to watermark code goes beyond the legal requirement, but if other providers follow the letter of the law, code generated by their tools may remain unmarked. That’s a significant gap, given how much AI-generated code is being deployed in production systems.
Another exemption is for “standard editing.” What qualifies as standard editing is left vague. Does a chat assistant that rephrases a sentence count? Does a grammar checker? Anthropic has said that Claude will watermark text that is “processed,” not just generated, but the EU’s definition might be narrower. This ambiguity allows companies to interpret the rule favorably to their bottom line.
The phrase “as far as this is technically feasible” is another escape hatch. If a company claims that watermarking certain outputs would degrade quality or is too costly to implement, they can sidestep the obligation. This clause essentially means that compliance is on the honor system, absent strong enforcement.
Why Watermarks Won’t Stop AI Slop
The broader problem is that watermarks only work if everyone plays by the same rules. Open-weight models like Llama, Mistral, or Qwen can be downloaded and run locally without any watermarking. An AI slop operation could generate a thousand articles with Claude, run them through a local model to paraphrase, and publish them as original. No watermark survives that process, and there’s no way to trace the output back to Claude.
Even simpler, a user could manually paraphrase key sentences or ask the AI itself to rewrite in a different voice. Research has shown that watermark detection accuracy drops sharply when text is lightly paraphrased. Anthropic claims its watermarks are resilient to “limited” editing, but adding a synonym swap or reorganizing paragraphs can break the signal.
Moreover, the absence of a watermark proves nothing. An AI model that doesn’t watermark produces clean text. A human who writes in a robotic tone might be falsely accused of using AI. This creates the classic false-positive dilemma. Platforms that deploy detectors risk flagging original human writing as slop, while sophisticated slop producers simply strip the watermarks.
Another factor is scale. AI slop isn’t a single source; it’s a torrent. Even if a watermark is present, a social media site would need to scan every piece of text in real time, comparing it against watermark databases. That’s a computational burden that many smaller platforms can’t afford. Larger platforms may do it for content posted publicly, but private messages, emails, or internal documents are beyond their reach.
The Value of Transparency
Despite these limitations, watermarking has considerable value as a transparency measure. It normalizes the idea that AI-generated content should be labeled. It gives individuals the means to check whether a piece of text they received was machine-generated. For example, a hiring manager can run a cover letter through a detector to see if it bears Claude’s mark. A journalist can verify whether a press release was written by an AI. That’s a tangible shift from the current state, where AI use is often hidden.
Transparency also benefits AI users. When companies know that watermarking is possible, they may think twice before using AI to create deceptive content. It creates a social contract: AI is a tool, but its use should be disclosed. That cultural change is more important than the technical watermark itself.
Anthropic’s decision to watermark code, even though it’s not required, is notable. It signals a commitment to responsible AI deployment. The company has also published guidelines for third-party detectors, hoping to build an ecosystem of verification tools. Whether those tools become widely adopted depends on developers and regulators.
What Needs to Happen Next
If watermarking is to evolve beyond a paper tiger, several things must happen. First, standards need to be universal. A watermark from Anthropic should be detectable by a tool built by Google, and vice versa. The EU AI Act mandates interoperability, but the technical specifications are still being drafted.
Second, the exemptions should be narrowed. If code is exempt, why did Anthropic watermark it? Because it’s feasible. The EU should update its guidance to remove the “technically feasible” clause, forcing companies to implement robust watermarking by default. Standard editing exemptions should be clarified, perhaps with a threshold for how much transformation removes the obligation.
Third, platforms need to step up. Social media platforms, search engines, and content management systems should integrate watermark detection into their pipelines. Instead of waiting for regulators to enforce, they could label suspected AI content automatically. This is a business opportunity, not a burden. Trust is a currency, and platforms that can flag AI slop will gain user confidence.
Finally, the public needs better media literacy. Watermarks are not a magic bullet, and even a perfect watermark won’t stop a person from believing a false claim. Education about AI’s capabilities and limits is essential. People should learn to ask where content came from, rather than relying purely on technical markers.
None of this will happen overnight. The EU AI Act is just the beginning. Other countries, including the United States, are considering similar legislation. In the meantime, AI models continue to produce text, images, and code at unprecedented speed. The flood of AI slop will likely get worse before it gets better.
As a society, we need to decide what kind of information ecosystem we want. Watermarks are a step in the right direction, but they are not a destination. They are a tool among many. Their success depends on the broader framework of laws, platform policies, and social norms. Without those, watermarks are just a drop in the ocean of slop.
The rise of generative AI has brought many benefits, from auto-completing emails to aiding creative work. But it has also introduced a new category of noise into the digital environment. Watermarking won’t silence that noise. It may, however, help us learn who is making it.
Source: PCWorld News