Anthropic started watermarking Claude's text this month, and a good part of my feed reacted like it had been caught. The reaction is more revealing than the announcement.
A correction first, because most of the posts I've read get this wrong. Anthropic did not decide on its own to mark your writing. Article 50 of the EU AI Act became applicable on 2 August 2026 and requires providers to mark AI-generated content in a machine-readable way. Anthropic signed the EU Code of Practice on Transparency of AI-Generated Content in July, along with roughly 190 other signatories. Google and OpenAI signed the same document.
Anthropic published the mechanics on 14 August. Models launched on or after 2 August carry the watermark, older models get it over the coming months, and it applies everywhere because there is no durable way to scope it by region. A rule written in Brussels now runs through every Claude session in Toronto.
What the watermark actually does
The method is a version of SynthID-Text, published by Google DeepMind in Nature in 2024. When the model picks the next word and two candidates are equally good, that choice is normally settled by a random number. Watermarking changes the source of the randomness to something derived from a key, so the pattern of choices can be checked against it later.
Nothing is added. No hidden characters, no extra tokens, no change in quality. What comes out the other end is a probability that Claude was involved.
Here is the part nobody quoted during the outrage cycle. Anthropic states that when Claude proofreads or lightly edits human text, nearly all the words are still the person's, so there is very little for the watermark to attach to. The more the model writes, the more choices it makes, and the more room the watermark has to live in.
Call it a proportionality meter. It measures how much of the final text the machine chose, and nothing else.
Your ideas were never watermarkable. Your argument, your framing, your experience, the reason the piece exists at all. None of that is a token-level decision. The watermark can only see the words.
My father was an editor
He was a writer and a poet too, but the work that paid was editing. For most of his career I watched him take other people's manuscripts and make them better without making them his.
That is the craft. You tighten, you cut, you fix the rhythm, you catch the thing the writer was too close to see. You leave the story alone and you leave the voice alone.
Editors have worked this way for as long as there have been editors, and nobody has ever asked for a disclosure line about it.
I use AI the same way. I bring the ideas, I direct the research, I decide what the piece is arguing. Then I hand it to an editor who never sleeps and is never too busy for me.
The distance between that and what Chris Best calls Claudefishing is not a fine one. It is the entire question.
The law already wrote in the editor
Read Article 50 past the headline and it gets interesting.
The obligation on deployers is to disclose when text published to inform the public on matters of public interest has been artificially generated. But it does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication.
The same regulation that produced the watermark also wrote in the editor exemption. The test in European law is not how many words came from a model. It is whether an identifiable person stands behind the result.
Editorial responsibility. That is the standard, and it is a much older idea than any of this.
There are real teeth behind Article 50, up to 15 million euros or 3% of worldwide turnover. Which tells you the drafters thought hard about where to put the line. They put it exactly where publishing has always put it.
The rarest workflow on LinkedIn
Pangram analysed just over a million social posts in July. LinkedIn was the most AI-saturated platform in the study, with more than 40% of longform posts flagged as fully AI-generated. LinkedIn made up about a third of the content scanned and nearly two thirds of everything flagged.
Then there is the number that should stop you. Only 4.3% of LinkedIn longform was classified as AI-assisted or mixed, the smallest share of any platform measured.
Everything else was either fully human or fully machine. LinkedIn does not use AI as a polish layer. It writes the whole thing or none of it.
So the workflow I have been describing, human ideas with machine editing, is not the common practice I assumed I was defending. It is close to the rarest thing on this platform.
That changes what this piece is. I thought I was defending something ordinary. I am arguing for something almost nobody does.
The platforms have already picked this line
Look at what shipped in the last six weeks and the pattern is consistent.
Substack partnered with Pangram on 21 July and added an optional statement where writers describe how they make their work. Best was explicit that the problem is not AI use. It is the gap between what a reader expects and what is actually there.
LinkedIn followed on 30 July. It added a button letting members flag a post as slop, and it removed its own "enhance your post" feature. The replacement is a proofreader, described as one that "does not change your voice."
LinkedIn's stated position is that AI and slop are two different things. The company that built the slop button also killed its own generator and shipped an editor in its place. Same line, drawn in a product instead of a statute.
Where the line actually sits
Richard Tofel, formerly of ProPublica, published a proposed set of ground rules four days ago. Composition should be disclosed. Copy editing need not be. Substantive editing should be.
He is stricter than I am, and I would rather say so than claim him as support. Research and readability edits sit comfortably inside his rules. Structural rewriting and style work sit closer to his substantive line than I am fully comfortable with.
His sharpest point is the double standard. A machine's help cannot be concealed but a human ghostwriter's can, and the reader is the one with the actual claim to know. He would give bylines to editors who write whole passages. He is right about that.
So here is my line. If I could hand the same task to a human editor without thinking twice about the byline, no disclosure is owed. Where I would owe a human co-author credit, I owe the reader a note.
Detection tools are not verdicts
The tooling is real but it is not a courtroom. Pangram claims a 0.01% false positive rate, and independent work out of Chicago Booth found it substantially outperforms open-source detectors under strict conditions.
It also has a body count. The Caribbean regional winner of the 2026 Commonwealth Short Story Prize was flagged as fully machine-written and denies using AI. Pangram's newspaper study named specific op-ed writers, and the Wall Street Journal editorial page pushed back hard after running the same pieces and getting different scores.
Polished prose reads as machine prose to a classifier. If you write cleanly, you carry a risk that sloppy writers do not.
Treat a detection score as a reason to ask a question. Never as the answer to one.
And if you are in Canada, notice what you are not getting. There is no federal AI statute here. AIDA died on the order paper in January 2025 and has not been reintroduced. Canadian writers get the watermark, because it could not be scoped regionally, without the Article 50 carve-out protecting an editor in Dublin.
The norm arrives before the law does. It usually does.
How I make this
Since I am arguing that process should be visible, here is mine.
The ideas are mine. Every edition starts from something I am actually arguing about, usually from work. I decide what the piece says before any model sees it.
I direct the research. Claude runs the searches. I read the sources, check numbers against primary documents, and cut anything that will not survive scrutiny. Vendor statistics get labelled as vendor statistics. When the evidence cuts against my thesis, it goes in anyway.
Drafting is collaborative. I supply the argument, the structure and the voice constraints. Claude produces prose. I edit it line by line, and some editions end up closer to my own draft tightened while others end up closer to a Claude draft rewritten. The ratio moves. I do not think the ratio is the interesting part.
The last step never changes. Nothing publishes that I would not defend in a room. If a sentence here is wrong, it is my error and not the model's. I hold editorial responsibility for every word.
If someone scanned this edition with Pangram, I expect it would flag it. That is fine. Now you know what the flag means.
The panic is the data
The watermark measures one narrow thing: how much of the published text the model chose. It says nothing about whether anyone thought.
Which is why the reaction has been so instructive. If your process starts with your own ideas and ends with an editing pass, the watermark finds very little to hold onto. If you are frightened of it, the fear is telling you something about your process.
I have written before about harness engineering, the discipline of building the environment and feedback loops that make an agent's work reliable. This is the same problem one layer up. The harness for writing is an editorial process with a name attached to it.
Publish your process. Then let people judge the work.
