Earlier this month,
Anthropic announced that text produced by Claude would begin carrying an
invisible watermark, a machine-detectable pattern embedded in the choices the
model makes as it generates language. The company is adopting a system based on
Google DeepMind’s SynthID technology, part of a broader effort by the
technology industry to make synthetic content identifiable. Anthropic’s move
comes as new transparency provisions of the European Union’s AI Act take
effect, requiring providers to make certain AI-generated content detectable in
machine-readable form.

The idea is not
particularly radical. Google already uses SynthID to mark AI-generated text,
images, audio, and video. OpenAI uses C2PA Content Credentials and SynthID for
supported generated images, and recently expanded SynthID watermarking to
supported audio. Microsoft adds metadata to certain media generated or altered
with AI and offers visible or audible watermarks in some of its consumer
products. 

There are good
reasons for doing this. Generative AI has made it cheap and increasingly easy
to manufacture convincing photographs, voices, videos, and documents. And it is
important for society to understand when something is real and when it is
fabricated. A political candidate can appear to say something she never said. A
photograph can depict an event that never occurred. A familiar voice can be
synthesized from a relatively small sample of recorded speech. As the
distinction between synthetic and recorded media becomes harder for humans to
discern, some mechanism for establishing provenance begins to look not merely
sensible but necessary.

The European
regulations reflect this concern. Their stated purpose is to reduce deception
and manipulation and protect the integrity of the information ecosystem. But
there is a difference between a label and a watermark, and that difference
deserves more attention than it has received.

A label is
primarily intended to tell a person something. We put ingredients on food,
warnings on medicine, and disclosures on financial products because we believe
people should have information that affects how they interpret or use those
products. One could imagine a similar convention for AI: a photograph labeled
as synthetic, an article disclosing that AI assisted in its production, a video
telling viewers that portions were generated rather than recorded.

An invisible
watermark does something subtly different. It creates information about the
artifact that can persist independently of what the creator chooses to
disclose. Google’s text watermarking technology, for example, modifies the
probabilities used to select tokens during generation, producing a statistical
pattern that can later be detected. Other provenance systems can attach
cryptographically verifiable information about how an asset was created and
modified.

If AI-generated
content was diligently labeled, we may not need deeply technical
AI-watermarking. But we live in a world of deepfakes and clickbait and all
manner of profit and political-based deception. This is core to why we’ve
needed to develop watermarking technology and to begin to regulate it.

Watermarking is
more than labeling. It is evidence. But evidence developed for one purpose has
a way of acquiring new purposes as institutions, markets, and laws evolve
around it. And that’s what I’d like to dig into today.

The typewriter that kept no records

For most of the
history of creative work, the tools used to make something had remarkably
little to say about who made it.

Imagine an author
finishing a novel on a typewriter in 1975. When she delivered the manuscript to
a publisher, she claimed to have written it. In the ordinary course of events,
that claim was accepted. If someone else appeared and claimed authorship, the
dispute would have to be resolved through evidence: drafts, notes,
correspondence, witnesses, perhaps even the distinctive characteristics of the
typewriter.

Some cases would be
easy to settle. Others would not.

There was an
unavoidable element of trust in the system because the tool itself had no
memory of the creative process. The typewriter could leave forensic evidence,
but it did not maintain a ledger of the author’s relationship with it, nor in
fact know who was striking its keys. It did not record which sentences it had
helped compose because, of course, the typewriter did not compose them.

For decades,
increasingly sophisticated digital tools preserved much of that basic
arrangement. A novelist could write in Microsoft Word without Microsoft
becoming a participant in the novel. A photographer could alter an image in
Photoshop without Adobe acquiring a creative relationship to the photograph.
The software was instrumental to the work, but the conceptual boundary between
tool and creator remained relatively clear.

Generative AI
complicates that boundary because the tool no longer merely executes
instructions. It can propose. It can write a sentence, redesign an image,
generate computer code, suggest a melody, reorganize an argument, or offer
twenty alternatives to an idea. Increasingly, it can do these things inside the
ordinary software people already use to work.

This creates a
category that will probably become far more common than either purely human or
purely AI-generated work: AI-augmented work.

The article you are
reading belongs in that category.

I began with the
argument. I developed it in conversation with an AI assistant. I supplied
examples and analogies, including the typewriter comparison. The AI helped me
test the argument, suggested ways to organize it, and produced draft language.
I made decisions about what belonged, what did not, and what the argument
ultimately meant. I edited and updated drafts and then loaded them back into AI
for feedback, additional research and verification. The iterative process took
multiple iterations and significant time. I wrote and rewrote much of this
article offline. But I won’t claim to have typed every sentence. I augmented my
original ideas with modern tooling to drive towards a higher-quality outcome
than if I had not used AI-assistance. The final work emerged from that human to
AI back-and-forth.

So who created it?

Our instinct is to
answer that question by looking for a percentage. Perhaps a work that is 90
percent human and 10 percent AI is human, while one that reverses those
proportions is artificial. But creative contribution has never been
particularly amenable to arithmetic. Ten words can contain the central insight
of an essay. A single editorial suggestion can transform a book. An art
director may profoundly influence an image without touching the camera.

A watermark cannot
resolve this problem. It can establish something narrower. And understanding
just how much narrower requires separating four ideas that are likely to become
increasingly entangled: provenance, participation, authorship, and ownership.

From provenance to ownership

Provenance is the
simplest of these concepts. It concerns history: Where did an artifact come
from? What happened to it along the way? Which tools interacted with it?

This is precisely
the problem that systems such as C2PA’s Content Credentials are designed to
address. C2PA defines provenance as information about the history of a digital
asset and its interactions with actors and other assets. Its credentials can
contain cryptographically verifiable information about an artifact’s origin and
subsequent modifications.

From provenance, we
can sometimes establish participation.

If a detectable
watermark associated with a particular model survives in a document, that may
provide evidence that the model participated in generating some of its text.
OpenAI makes an important version of this distinction in explaining its
image-verification technology: detecting its provenance signals can indicate
that an image was generated with OpenAI tools, but does not establish that the
image is accurate, unedited, legally owned, or being presented in the proper
context.

Participation, in
other words, is not authorship.

This distinction
becomes especially important as AI moves from being a destination, a website or
user interface one visits to ask for something, to being a feature embedded
throughout ordinary software. Consider a photographer who uses AI to remove a
distracting object from an otherwise original photograph. Or a programmer who
writes a large software application but accepts several functions suggested by
a coding assistant. Or an attorney who writes a brief and asks an AI system to
make two paragraphs clearer. Or an author who submits a chapter for editing,
accepts five suggested changes, rejects twenty, and rewrites another three
herself.

In each case, AI
participated.

That fact tells us
remarkably little about authorship.

Authorship asks a
different and much more difficult question: Who supplied the expressive choices
that make the work what it is? Who conceived the argument, selected the
composition, determined the structure, chose among alternatives, and exercised
the judgment that produced the final artifact?

American copyright
policy already recognizes some of this complexity. In its 2025 report on AI and
copyrightability, the U.S. Copyright Office concluded that generative-AI
outputs can receive copyright protection when a human determines sufficient
expressive elements, and that using AI as an assistive tool does not itself
prevent copyright protection. Prompting alone, by contrast, is generally
insufficient.

Even authorship,
however, is not ownership.

Human beings
routinely create things they do not ultimately own. Employees produce works
whose copyrights may belong to employers. Authors transfer rights to
publishers. Multiple contributors can possess different interests in the same
work. Ownership is a legal and economic arrangement layered on top of creation.

These four concepts
therefore form something like a ladder. Provenance tells us where something has
been. Participation tells us who or what contributed to the process. Authorship
asks who actually created the protected expression. Ownership determines who
possesses the rights.

A watermark begins
near the bottom of that ladder. The question is whether, over time, we will
allow it to climb.

When evidence answers the wrong question

There is no reason
to believe that watermarking itself gives an AI company copyright in the things
its models produce. Under current American law, it does not. Nor is there
evidence that the companies developing these systems are conspiring to use
transparency regulation as a back door to ownership. The more interesting
concern is structural rather than conspiratorial.

Suppose that 15
years from now, a creator becomes involved in a dispute over a valuable work
produced with substantial AI assistance. The creator says that the idea was
hers, that she developed its essential form, and that AI was simply one of
several tools involved.

The technology
provider, meanwhile, may possess something the creator does not: an extensive,
machine-verifiable record.

There could be
timestamps. Model identifiers. Generation records. Cryptographic credentials.
Statistical watermarks embedded in surviving portions of the artifact. Perhaps
there will be a history showing dozens or hundreds of interactions between the
creator and the system.

None of this would
necessarily establish authorship. It certainly would not, on its own, establish
ownership.

But it might look
remarkably authoritative.

And this is where
the distinction among the four concepts becomes important. Evidence can be
excellent at answering one question and still be poor evidence for another. A
watermark might provide strong evidence that an AI system participated in
producing a work while providing almost no evidence about the relative creative
importance of that participation.

My worry is that
institutions have a natural tendency to privilege what can be measured. The
creator’s evidence might consist of memory, intention, judgment, notebooks,
conversations, and testimony about how an idea developed. The corporation’s
evidence might consist of cryptographically authenticated records generated
automatically at industrial scale.

One account is
human and interpretive. The other looks objective.

The danger is not
necessarily that the machine record is false. The danger is that better
evidence about one question may acquire undue authority over a different
question.

Proof of
participation can begin to feel like proof of authorship. Proof of authorship
can begin to influence assumptions about ownership. The steps are individually
small. The distance between the first and the last is not.

The infrastructure comes before the law

Technology often
creates capabilities before society has decided how those capabilities should
be governed. This is especially true of data. Systems built for convenience
become systems of surveillance. Records collected for security become valuable
for advertising. Data retained for operational purposes becomes discoverable in
litigation. None of these secondary uses needs to have been part of the
original plan.

AI provenance may
follow a similar path.

Today, its
rationale is compelling: help people identify synthetic media, combat
deception, and provide greater transparency about what they encounter online.
But once the infrastructure exists, it will exist for other purposes as well.

Imagine a world in
which AI systems participate, however modestly, in a substantial share of human
intellectual production. They help write books and business plans, edit
photographs and films, produce computer code, design products, draft contracts,
analyze scientific results, write emails and refine inventions. At the same
time, those systems leave behind increasingly durable evidence of their participation.

The companies
operating them will then possess something previous toolmakers generally did
not: a technically sophisticated record connecting their products to the
creative process itself.

Perhaps nothing
consequential will come of that. Current copyright principles may prove
perfectly capable of maintaining the distinction between tool and author.
Courts may insist that provenance establishes only provenance and refuse to
infer creative rights from technical participation.

But it is also
possible that the law will evolve. New forms of licensing may emerge. New
theories of machine contribution may be proposed. Contractual terms may change.
Courts may confront disputes we have not yet imagined. Economic pressure may
encourage companies to seek rights that seem implausible today.

If any of that
happens, the evidentiary infrastructure will already have been built. And that
is what makes the present moment worth examining. The important question is not
whether Anthropic, Google, OpenAI, Microsoft, or anyone else intends to claim
ownership of AI-assisted work. There is no basis for making that accusation,
and intention may ultimately be beside the point. The question is what becomes
possible once society has created a persistent technical record of machine
participation in human creativity.

For most of
history, we lived with an imperfect arrangement. People claimed authorship,
other people sometimes challenged them, and institutions tried to determine
what happened from whatever evidence survived. There were ambiguities and
injustices in that system, as there are in any system built around human
testimony and incomplete records.

We now have the
ability to replace some of that ambiguity with data. That is usually described
as progress. And often it is. But data does not merely resolve uncertainty. It
redistributes power toward whoever collects it, controls it, interprets it, and
persuades institutions of what it means.

The great promise
of AI watermarking is that, years from now, we may be able to ask whether an
artificial intelligence participated in creating something and receive a much
better answer than we can today.

We should build
that capability with care. Because over time we may discover that society has
begun asking the watermark a different question. “Did AI participate in the
creation of this” is today’s intended question. But when that question shifts
to “Who deserves credit” and “Who owns it”, will AI-platforms have an argument
to begin laying claim?  The evidence may
already carry more authority than we intended to give it.