Attention Deficit · research story
Authorship · provenance · regulation

The Hidden Mark in Your Draft

Claude models launched on or after August 2 can leave a machine-readable signal in generated or processed text. The signal records model processing. Revision history provides separate evidence about authorship.

Sources: Anthropic's marking guidance, Emma Wilson's provenance argument, Axios reporting, the European Commission's Article 50 guidance, Google DeepMind's SynthID documentation, and the C2PA specification.

Zoom out

A model signal passes through a detector and platform policy.

Implementation path

Article 50 requires machine-readable marks for covered outputs.

01 · RULEEU Article 50Certain generated or manipulated outputs require machine-readable marking.
02 · MODELToken choices shiftThe generator adds a statistical pattern.
03 · PLATFORMA detector reads itPlatforms decide when and how to display a label.
04 · PERSONA judgment followsThe reader may infer much more than the signal contains.
A watermark provides technical input to a separate platform labeling decision.
Sources: European Commission Code of Practice; Axios, August 12, 2026.

Article 50 creates a detection requirement. Platforms choose the reader experience.

The European Union's transparency rules began applying on August 2, 2026. Providers must support machine-readable marking for covered generated or manipulated content. Standard editing is exempt from the marking obligation. Anthropic's implementation can still mark text processed during proofreading, translation, or summarization.

Mechanism

Statistical text watermarks and signed file credentials use different mechanisms.

Provenance mechanisms

Text watermarks and signed manifests produce different evidence.

cleardirectspecificplainmeasuredbounded
specific
+
precise
+
general
Content Credential

A signed manifest can record tool and edit history. Validation covers record integrity. Truthfulness remains outside the validation result.

A detector reports evidence of a statistical model signal. A Content Credential validates a signed provenance record.
Sources: Google DeepMind SynthID; C2PA Specification 2.3.

The text mark changes token probabilities during generation.

Text models choose one token at a time from a probability distribution. Watermarking methods make small, keyed adjustments to token choices, producing a pattern a detector can test later. For supported files, C2PA Content Credentials use a cryptographically signed manifest associated with the asset and its edit history.

The authorship gap

Model processing can follow a human draft or a generated draft.

HUMAN DRAFTOriginal argument
human contribution100%
model signalnone
PROOFREADTwo commas fixed
human contributionmost
model signalpresent
TRANSLATELanguage changes
human contributionideas
model signalpresent
REWRITEStructure changes
human contributionmixed
model signalweaker
Authorship assessment combines detector output with revision history.
Concept based on Axios reporting and Emma Wilson's Substack. Bars illustrate separate concepts and carry no detector score.

Positive detection can follow a human draft after proofreading.

Axios reports proofreading, translation, and formatting can leave Claude's signal. Extensive rewriting, short text, or mixed sources can weaken detection. A binary label can overstate model authorship or miss substantial model involvement.

Stress test

Detection confidence depends on text length and later editing.

Long, varied generation

More token choices give the detector more signal.

Short factual answer

Fewer valid word choices reduce the available signal.

Light editing

Some watermarking methods remain detectable after small changes.

Thorough rewrite

Paraphrasing or translation can sharply reduce confidence.

Short text, mixed sources, and rewriting can reduce detector confidence.
Sources: Google DeepMind SynthID limitations; ICLR 2024, “On the Reliability of Watermarks for Large Language Models.”

Statistical detection confidence changes with text length and editing.

Google reports SynthID works best on longer, varied text. Confidence falls for short factual answers and after thorough rewriting or translation. Research has found stronger schemes can survive substantial paraphrasing, but detection may require hundreds of tokens and a specified false-positive threshold.

Perspectives

Stakeholders use detector output for different decisions.

Stakeholder uses

Creators, platforms, regulators, and adversaries use detector output differently.

CREATORWill my work be misread?

Editing assistance and full generation can both receive one visible label.

PLATFORMCan I label at scale?

A machine-readable signal is cheaper than reviewing every item.

REGULATORCan synthetic content be identified?

Interoperable marking supports enforcement and disclosure.

ADVERSARYCan I remove the signal?

Rewriting creates an arms race between robustness and evasion.

Detector evidence has different limits for authorship, disclosure, moderation, and intent.
Perspectives synthesized from Emma Wilson, Joel Comm, Google DeepMind, C2PA, and watermark robustness research.

Each stakeholder applies a different decision threshold.

Creators evaluate credit and false inference. Platforms need a signal they can process at scale. Regulators need implementation across products and borders. Adversaries test removal. Each use produces different thresholds for false positives, false negatives, quality effects, and privacy.

Convergence

Origin, creator identity, likeness, and consent require separate evidence.

Beyond the AI label

A provenance signal cannot establish permission to use a face or voice.

ORIGINWhich generator or camera handled the asset?

Watermarks and signed manifests can identify supported tools and devices.

CREATORWho claims responsibility?

C2PA extensions can attach a verified person or organization to an assertion.

LIKENESSWhose face or voice appears?

Matching systems compare media with an enrolled person's face or voice template.

CONSENTWas the use authorized?

A license, platform process, or applicable law supplies the permission record.

An asset can carry valid AI provenance while using a person's likeness without permission.
Sources: C2PA 2.4 identity guidance; YouTube likeness detection; Tennessee ELVIS Act; multimodal watermark implementations.

Multimodal marking and likeness protection are beginning to meet at publication time.

C2PA 2.4 represents machine identity and can incorporate human or organizational identity assertions. Google verifies SynthID signals in image, video, and audio. OpenAI combines C2PA metadata with an embedded signal for supported images and embeds a signal in supported audio. YouTube scans uploads for enrolled creators' faces and says voice matching is planned for 2026. Tennessee's ELVIS Act adds a property right in an individual's voice. Each mechanism answers a different question about origin, attribution, identity, or permission.

Revision history

Record the claim, source, edits, and approval.

CLAIMWhat did we publish?Name the statement a reader may rely on.
SOURCEWhat supports it?Link the release note, dataset, interview, or calculation.
EDITWhat changed?Preserve substantive revisions and the tool used.
OWNERWho approved it?Record the person responsible for the final version.
A work record adds source, edit, and approval history to model-processing evidence.
Operational framing adapted from Emma Wilson, “The AI watermark turns every draft into a receipt.”

Teams need provenance for the claim and the generated file.

Emma Wilson proposes a lightweight record of the brief, source material, substantive edits, and approval. The record identifies who owned the claim, what evidence supported the claim, and who accepted responsibility for publication.