In August 2026, Anthropic announced that all new Claude AI models will place invisible watermarks in their output. The watermark changes how the model chooses its next word while generating text. It’s detectable using a detection key controlled by Anthropic.
Article 50 of the EU AI Act requires providers of generative AI systems to mark covered AI-generated content so it can be identified. If an AI provider wants to operate in the EU, they must comply. Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026.
Anthropic says it has no durable way to scope this watermark by region, so it’s being rolled out worldwide, across all models. All future Claudes, whether they’re on the API, the web interface, the app, Claude Cowork, or Claude Code, will carry this mark.
In their own language: “Embedded watermarks will apply to all generated text.”
Anthropic’s watermark was designed to satisfy a European transparency law. It may have accidentally created a forensic tool for challenging copyright claims on AI-generated code.
THE LAW HASN’T CHANGED
The U.S. Copyright Office has had a consistent stance on the copyrightability of AI-generated content.
In 2023 the graphic novel Zarya of the Dawn became the reference point for how the Copyright Office treats AI-generated works. The author of that book had written the whole thing herself. But she used Midjourney to create the images. The copyright got split. She owned the story, but the images were not eligible.
In January 2025, Register of Copyrights Shira Perlmutter said the whole framework turns on “the centrality of human creativity to copyright” and that creativity expressed through AI systems “continues to enjoy protection.”
But that protection has a hard requirement.
AI-generated output only gets copyright when a human determined “sufficient expressive elements.” The human contribution, the creative expression, has to be visible in the final product. Prompting alone doesn’t count.
In “The Brush and the Wall,” I pointed out the tension already built into this framework. AI is treated as too mindless to qualify as an author, yet autonomous enough that a human who merely directs it may also fail the authorship test. If neither side qualifies, the expression sits in a copyright no-man’s-land.
Imagine you own a video game company. All of your software engineers are using Claude Code to assist in their work. Meanwhile, there’s a statistical signal being embedded in code comments and documentation.
An engineer describes her goal and lets Claude determine the implementation: the source code, variable names, organization, control flow, and comments. All the expressive elements were determined by Claude. The human only prompted and made sure the code functioned. There’s nothing of the engineer visible in the finished work.
Under the Copyright Office’s own framework, that’s a problem.
Now, imagine a few months before the release of your big blockbuster game someone leaks it online. You issue takedown notices, track the person who released it and sue him for copyright infringement. And, since your staff used Claude, you’re faced with a dilemma. Do you own the code if Claude touched it? Does it have “sufficient expressive elements?”
In the past, a defendant’s legal team could’ve run the code through an AI detector. But those are far from definitive proof. The false positive rates for tools like Pangram and GPTZero are higher than their proprietors would like to admit. A plaintiff could have such a scan thrown out as evidence on the grounds that these tools flag human-written content as AI.
This new watermark is a different kind of evidence. Anthropic designed the detection signal. When the detection API goes live, a defendant’s lawyers can run the plaintiff’s source code through Anthropic’s own detector. If the watermark is detected, that evidence is much harder to dismiss as an ordinary detector guess.
And if it comes back with the watermark? Your copyright infringement lawsuit just got complicated.
This is why, if you’re part of a software company, you should be raising the alarm about using Claude. Legal departments should be looking at this right now. If you keep all your code a trade secret, there’s probably much less to worry about. But if you release any software to the public, this should concern you.
There’s been no major court ruling on AI-generated software yet. The argument is untested. But looking at how the existing framework has been applied to other creative works, it points in one direction.
THE WATERMARK IS A RECEIPT
Anthropic’s announcement concedes the watermark can’t be applied in instances where an exact output is required. And that’s what a lot of code is. Exact. But they go on to say, “in areas where there is an arbitrary choice between particular words or terms within the code, the watermark can be used, such as comments within code.”
Comments within code. That’s where the mark will live. And there are others. Variable names, error messages, inline documentation, and commit messages are all likely candidates. Those are all places where natural language is used. Places where there are many ways to say the same thing.
And those places are among the places where copyrightable human expression can live. They’re places where a human can visibly demonstrate authorship. And that happens to be the territory the Copyright Office cares about.
Proprietary software doesn’t typically release with the source code and comments. It’s almost always distributed as compiled binaries. But in our hypothetical copyright lawsuit, discovery gets the source repository with the full history and all comments and documentation. A company could start a practice of stripping comments from all of its repositories, but a codebase with no comments would look like they intentionally scrubbed it. And the defendant’s attorneys can show that policy started right after Anthropic announced this watermarking scheme, casting doubt on the process.
Anthropic’s documentation says a detected mark means the material “may have been processed” by Claude. Could mean Claude wrote it. Could mean Claude proofread something a human wrote. That ambiguity is deliberate.
But ambiguity doesn’t survive court very well. Once the mark is detected, the follow-up questions write themselves. What was the prompt? What did Claude produce? What did the engineer change afterward? Where are the diffs?
If the answer is “the engineer described the feature and Claude Code produced the implementation,” the defendant has a strong argument that Claude’s expressive contribution to that code isn’t protected. And if that’s where the alleged infringement lives, there may be nothing to infringe.
THE INCENTIVE PROBLEM
Now, this is where someone will say “Anthropic had to do this. They had to implement the mark.” But did they?
The European Commission’s final Article 50 guidelines explicitly exempt source code from the marking requirement. That carve-out applies directly to the kind of output Claude Code produces. Yet Anthropic chose to apply the mark to Claude Code anyway. Their support page explicitly names Claude Code as one of the surfaces that will be affected by watermarking.
The explanation for rolling this out worldwide? They claim to have no way to scope the watermark by region. But the announcement suggests that the watermark system is something that can be added or removed from the underlying model. They say, “when watermarking is used, choices are still made at random, but the source of the randomness is different.” That’s describing a conditional process.
Anthropic is selling their model to enterprise customers, specifically pitching it as a coding tool. That’s their product. That’s the value proposition. But now those customers are paying for a tool that marks all of its output with a provenance signal. The practical effect, at least in the United States, is the machine creating forensic evidence that could be used to challenge their copyright in court.
Those customers have alternatives. I wrote previously about the competitive asymmetry between compliant Western models and Chinese labs that will simply ignore the marking requirement. The price on those models is already attractive. To someone who’s on the fence? This noncompliance starts to look like a feature.
The EU wanted provenance. U.S. copyright law says provenance of AI generation may negate authorship. For source code, the EU took itself out of the equation. The Commission said code doesn’t need the mark.
Anthropic put it there anyway.
Enjoyed this piece?
I do all this writing for free. If you found it helpful, thought-provoking, or just want to toss a coin to your internet philosopher, consider clicking the button below and donating $1 to support my work.



Fascinating! So, if the Chinese models want to market their wares in the West, they will have to watermark. But what if the Chinese engine is cloud-based and that cloud is not in the West—can I then sell a cowritten book on Amazon in the US, UK, Euro, Australia? If no-one is seeking a watermark on my work, do I have to tick the Amazon (not the world’s most trustworthy company) AI disclose box in the KDP bookshelf? How are they ever going to tell/prove I did or didn’t use AI in some form?
The literal mark of the beast. Crazy!
If the company doesn't own the code, then who does? Another way to say it: does all the code currently being built using Claude now belong to Anthropic?
It's total bs that they can't region lock this tool, but perhaps VPN was the outright thought.
The end result will be total anarchy, but watching it come alive actively is pretty exciting. Thanks for the great summary!