Published · 3d agoProduct3 min read
Anthropic's Watermark, Not The AI Act, Is The Spec You Now Ship Against
Techdirt argues Anthropic complied with the EU AI Act more broadly than the law required. For anyone shipping model-written text, the vendor's implementation is the constraint that actually binds.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Anthropic has released more details about how its text watermarking works, and the debate over it has intensified as a result; many people are upset about it.
- According to Techdirt, it appears that Google has already been doing something similar with the output from Gemini.
- Generative AI is always trying to generate the next token, and it does so probabilistically rather than deterministically, so each run produces something slightly different.
- Companies can deliberately bias a model's token selection so the tool is slightly more likely to choose certain words than it would without that bias.
- With a long enough text and a key describing the bias, one can inspect the text and see that enough of the very slight changes match the watermark bias to suggest the text was likely generated by a model carrying that watermark.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Anthropic has published more detail on how its text watermarking works, and the argument about it has escalated accordingly [1]. Techdirt reports that Google already appears to be doing something similar with Gemini output, which means the practice is spreading across the model layer rather than sitting with one vendor [2].
The mechanism matters because it determines who carries the cost. Generative models pick the next token probabilistically rather than deterministically, so the same prompt yields slightly different text each run [3]. Vendors can deliberately bias that choice so the model is marginally more likely to select certain words [4]. Given a long enough passage and the key to the bias, a checker can see that enough of those small nudges line up to suggest the text came from a model carrying that watermark [5]. Techdirt describes the result as far from foolproof but capable of flagging text likely generated with that specific bias [6].
The part operators should read twice: editing the output afterwards may or may not remove the mark, depending on whether the edits change enough of the biased words [7]. That makes the marker state of any human-in-the-loop pipeline indeterminate by design [8]. You cannot tell a client, an examiner, or a compliance reviewer whether your final draft is still carrying provenance signal, because the answer depends on how much of the vocabulary your editors happened to replace.
Techdirt's central point is that Anthropic chose to comply with the law in a way that looks broader than what the law requires, for reasons the piece treats as more understandable than critics allow [9]. Practically, that shifts the governing spec. If the vendor's implementation is wider than the statute, then the thing constraining a downstream product is the implementation, not the legal text a compliance team read [10]. Reading the AI Act tells you your obligations. It does not tell you what your model provider has already stamped into your output.
The second cost is expressive range. Techdirt notes the REAL Rating site uses a one-to-five scale to distinguish degrees of AI involvement, and argues a watermark collapses all of that into a single binary question: did this use AI at all [11]. Any product that wants to disclose honestly and precisely, say, model-assisted editing versus model-authored prose, now discloses into a detection regime that cannot represent the difference. Techdirt's related worry is that this will be used to attack and denigrate people using the technology reasonably, who will be falsely accused of cheating [12].
The threat model that produced this is, by Techdirt's account, the deepfake panic. The EU rushed out its AI Act because it did not want to be slow to regulate, in the way it believes it was slow on social media [13]. Techdirt argues the deepfake fear has been largely overhyped, that it has not really materialised to date, and that most AI-modified content has been correctly identified as such [14]. The publication's conclusion is that the costs land hardest on people using the tools properly [15].
Watch whether other providers document watermarking breadth, and whether any of them expose the marker state to the customer instead of leaving it to be discovered downstream.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Anthropic has released more details about how its text watermarking works, and the debate over it has intensified as a result; many people are upset about it.
ReportedView cited source - [2]
According to Techdirt, it appears that Google has already been doing something similar with the output from Gemini.
- [3]
Generative AI is always trying to generate the next token, and it does so probabilistically rather than deterministically, so each run produces something slightly different.
ReportedView cited source - [4]
Companies can deliberately bias a model's token selection so the tool is slightly more likely to choose certain words than it would without that bias.
ReportedView cited source - [5]
With a long enough text and a key describing the bias, one can inspect the text and see that enough of the very slight changes match the watermark bias to suggest the text was likely generated by a model carrying that watermark.
ReportedView cited source - [6]
Techdirt says such a watermarking system is hardly foolproof but can call out text likely generated with that specific bias.
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- techdirt.comMike Masnick3d agoThe EU Wanted A Deepfake Detector. It Got An AI Scarlet Letter.
- techcrunch.com2d agoAnthropic says it will watermark text generated by its AI models
Additional citations
- Techdirt



