Cover piece
Real risk
Claude watermarks generated text. In Brazil, the score does not prove a filing's authorship
The fact
On 14 Aug 2026 Anthropic published, on its own site, how Claude will leave a statistical signal in the text it generates. It is not a visible stamp. It is not hidden file metadata. It is a pattern in word choices, detectable by whoever holds the key. The company says it is doing this to comply with the EU AI Act and that the mark ships worldwide because a durable regional split does not yet exist. For a Brazilian lawyer the issue is not the privacy row on social media. It is what a judge, the Bar or opposing counsel can do with a score that looks like proof and is not.
How the signal gets into the text
A language model generates one word at a time. In many sentences two or three alternatives work almost the same. Those low-stakes choices are settled by chance. The watermark changes the source of that chance. Instead of an arbitrary generator, it uses a secret key plus a few preceding words. The text still sounds natural. Whoever has the key can later ask: is this sequence consistent with the choices Claude would make with that key?
Anthropic describes the method as a version of SynthID-Text, published by Google DeepMind in Nature in 2024, in a family of ideas that goes back to a 2022 proposal by Scott Aaronson. The company's own analogy: in Monopoly, dice or the digits of pi make no difference to the player. Whoever sees the full sequence and knows pi can estimate whether that game used pi. The reader of a filing sees nothing. The detector sees a pattern.
The company lists what the mark does not do, in its own 14 August FAQ: no practical impact on quality or content; the difference is not distinguishable to a reader; nothing is added to the text and there are no hidden characters; it does not require extra tokens or cost more; it carries no data that would tie the passage to a person, a firm or a chat. The mark, Anthropic says, belongs to Claude and the output, not the user.
What the score proves. And what it does not
The scoring function answers one question only: what is the likelihood Claude was involved in that passage? It does not confirm a human wrote it. It does not say whether another model wrote it, even if that other model also watermarks, because the key is different and the method may be different. A short sample has few choices; confidence rises with length. Anthropic is explicit: detecting the mark does not distinguish 'Claude wrote this' from 'Claude heavily edited this'.
False negatives are in the design. Human text that is summarised, translated, condensed or mixed with a synthetic passage may still carry a signal. Text rewritten word by word tends to lose the mark; at that point, the company says, it is arguable whether the text can still be called AI-generated. Light editing probably will not wipe it all. Copy and paste, in the official description, the mark survives. Format conversion that strips metadata is a different game: it applies to files, not to the pattern in the text.
There is a European legal exception firms need to keep. Article 50(2) of the EU AI Act requires the provider to mark synthetic output in a machine-readable way. The same paragraph drops the duty to the extent the system only assists standard editing and does not substantially alter the input data or its semantics. Anthropic, in the FAQ, says the same thing in product language: if you hand over a text and ask only for grammar and punctuation, the mark only lives in the handful of corrections, and that may not be enough to register.
Code, fact, translation and image are not the same case
Where there is only one right answer, the mark barely has room to live. After '2 + 2 =', the correct next token is 4. Code that breaks if the term changes follows the same logic. Code comments and arbitrary name choices can still carry a signal. Translation is the opposite: every word is chosen by Claude, so the mark goes in. Anyone using the model to turn a filing, a contract or an email into another language is in the highest-density watermark scenario.
Claude does not generate images from scratch in the classic sense, but it edits, processes and can produce a file via code. In those cases Anthropic promises a C2PA credential: a small, cryptographically signed note in the metadata of a PNG, JPG or SVG, saying Claude made or processed the file. C2PA is an open standard, the same one camera makers and photo editors use. Any C2PA-aware tool can read Anthropic's credential; the company says it will ship its own drop-and-check box. Here the image content does not change. Strip the metadata, the credential goes with it. Text watermark and C2PA are not the same mechanism. Mixing them in the same argument in court is a mistake.
Commercial 'AI smell' detectors (Pangram and the like) do not use Anthropic's key. They look at prose tics, the 'this is not X, it is Y' construction, extra 'quietly' in English. Anthropic splits the two methods in the FAQ. Mixing a watermark score with a generic detector is the kind of shortcut that becomes an empty accusation in a hearing.
Why now: Article 50, the code of practice and a global rollout
Article 50 of the EU AI Act (Regulation 2024/1689) became applicable on 2 August 2026 for synthetic-content transparency rules. Paragraph 2 requires a provider of a system that generates audio, image, video or text to mark the output in a machine-readable way, detectable as generated or manipulated. The solutions must be effective, interoperable, robust and reliable as far as technically feasible. Paragraph 4 covers visible labelling of deepfakes and of text published to inform the public on matters of public interest, with an exception where there is human review and editorial responsibility.
In July 2026 Anthropic and about 190 signatories joined the Commission's Code of Practice on transparency of AI-generated content. The code is voluntary; Article 50 is not. Signatories get a recognised path to show compliance. Non-signatories must prove, case by case, that the alternative measure is adequate. Anthropic says other major developers signed the same code and that each will implement its own mark. I did not open the Commission's named list in this session. What is in Anthropic's official text: Claude's mark will not be the only one on the market, and the company ships it globally at launch because it does not yet have a durable way to scope by region.
Models launched after 2 August 2026 already ship with the mark. Earlier models have a transition period under European law; Anthropic says it is working to add watermarking to those as well, over the coming months. Detection API: 'soon', no date. Rights over the output, the company says, do not change: the mark does not alter ownership or the user's responsibility under the terms of use.
Reaction, technical limits and what this piece does not claim
Anthropic's official note does not discuss subscription cancellations or name critics. The public debate, though, is predictable and a firm needs to know it without turning rumour into fact. Some fear a quality drop despite internal tests and the SynthID-Text paper (DeepMind saw no statistically significant like/dislike difference on Gemini traffic). Some fear a reputational false positive: the editor who used Claude only for grammar being treated as if they generated the whole text. There is the argument that running the passage through another model wipes or confuses the mark, and that one company's detector cannot read another's key. There is also a harder thesis: that the mark would later support a claim that a third party distilled or copied the model. None of that is in Anthropic's post. I record it as a narrative risk, not as a fact established in this session.
On the other side, Aaronson himself and part of AI research treat the mark as a tool against academic fraud and against inadvertent training on synthetic text, the so-called model collapse. Origin transparency can help a model builder. It remains a crude tool if someone uses it to punish the lawyer who asked for a paragraph to be proofread.
What changes on a Brazilian firm's desk
Brazil does not, as of this date, have an equivalent in force to the European duty to mark generated text in a machine-readable way. Bill 2338/2023 remains the track for an AI legal framework in Congress; I do not treat the bill as law here. What licensed lawyers already have is a different pack. CFOAB Recommendation 1/2024 states that legal strategy stays human. OpenDetector, the first PNIAA delivery with Forlex, looks for a nonexistent statute, a crooked precedent and a citation without an official base. In court, CNJ Resolution 615 bars autonomous AI decisions. None of those instruments asks for an Anthropic watermark score.
Three uses, three densities. Translating a defence in Claude: a dense mark, because every word is chosen by the model. Asking only for agreement and punctuation: a weak or null mark, and European Article 50(2) even drops the provider's duty in that slice. Drafting facts from scratch in the model and pasting them into the e-court: a likely mark, and the real problem remains ground, citation and human review, not the score. If opposing counsel files a detector screenshot and says the petition 'is AI', the technical answer is: probability of involvement, one vendor's key, false negatives by design, and the Consumer Defence Code does not turn a model statistic into proof of intellectual authorship.
The implementation playbook is the same as always, now with one extra line. Record what the model did (translated, summarised, drafted, only proofread). Do not file a passage you have not read in the full source. Run OpenDetector on citations. Do not treat a watermark API, when it exists, as evidence of a colleague's bad faith or as your own discharge. Anthropic promises the mark does not identify the user. That does not stop a poorly briefed judge from asking the wrong question. Whoever implements AI in a firm needs to arrive at the hearing with the distinction ready: one vendor's statistical signal is not authorship, is not a duty to disclose the prompt, and does not replace the licensed lawyer's responsibility.
Mentoring thesis
Regulate harmful use, not the paragraph. A universal watermark is a provider tool for European Article 50, not proof that a filing was born in the model, and it does not replace ground, human review and OpenDetector. Anyone who turns a score into a disciplinary charge or a hearing shortcut is using a crude instrument in the wrong place. While Congress debates Bill 2338/2023, the model lawyers already use shipped with a European rule applied worldwide. A firm that implements AI needs to document the model's role in the filing. Without that trail, the statistical signal becomes the only story. Then the loss is not Anthropic's. It is the licensed lawyer's.
Sources
- Anthropic, 14 Aug 2026: How Claude’s text watermark works
- Nature, 2024: SynthID-Text (Google DeepMind)
- EU AI Act, Article 50 (Commission Service Desk)
- EU Code of Practice on transparency of AI-generated content
- C2PA: content credential standard
- CFOAB Recommendation 1/2024 (OAB e-gazette)
- OAB: OpenDetector and the national solutions programme