Anthropic plans to add text watermarks to newly supported models. It explains the measure by invoking the transparency requirements of the EU AI Act. That sounds compliant. The practice itself is nasty, because the watermark may enter more than a piece of text generated independently by a machine. It can also enter a work that a person has already written.

An author writes an essay. The ideas are theirs, the material is theirs, and they arranged the structure. A few sentences feel awkward, so they ask Claude to polish them. Claude outputs the text again, and its watermark enters the essay. When someone later runs a detector, the machine can read Claude’s statistical signature. It cannot read the time the author spent on the work, or know which sentences Claude touched.

From that moment, the essay is contaminated.

I mean something specific by contamination. The author may still own the copyright in law, but the work now carries a suspicion of machine origin. The watermark cannot say what the person did and what Claude did. It cannot measure Claude’s degree of involvement. It offers only one conspicuous result: Claude detected.

For most readers, that result is enough to shape a judgement. Few will investigate whether Claude corrected a handful of faulty sentences or wrote the entire essay. A school, publisher, employer or content platform that sees the watermark is also likely to suspect the author first. The burden of explanation then falls on the author. They must find drafts, notes and version histories to prove that the thinking already existed and that Claude merely helped with the language.

A copyright claim that was once clear has now been pushed into an opaque relationship between human and machine.

Anthropic has not taken the copyright directly. It does not need to. By leaving its own signal inside the work, it can make other people doubt who wrote it. A copyright certificate or terms of service may still say that the user owns the output, while the author’s reputation suffers in the real world. The right remains. Its credibility has been dirtied.

That is the difference between copyright contamination and copyright seizure. Seizure changes who owns the right. Contamination makes the right ambiguous and gives the author an extra burden of proof. The first is easy to recognise and oppose. The second hides inside a supposedly neutral technical signal, yet follows the work wherever it circulates.

More absurdly, Anthropic itself admits that detecting a Claude marker does not prove the full origin of a text. Claude may have done nothing more than proofreading, translation, summarisation or file conversion. The original ideas and words may have come entirely from the user.Anthropic’s watermark explanation

That disclaimer gives the game away. Even the maker of the watermark knows that it cannot establish authorship. Yet Anthropic still inserts a signal that people can easily mistake for proof of authorship. When the outside world misreads it, Anthropic tells the author that this is not technically how the signal should be understood.

The author bears the consequences in the real world. Anthropic is responsible only for the technical definition. Convenient.

Nor does the EU AI Act require such a crude approach. Article 50 leaves an exception for standard editing and for operations that do not substantially alter the input or its original meaning.Related explanation from the European Commission If Anthropic still puts the same kind of watermark on proofreading and light editing, it is choosing to expand the scope of the marker. The EU requires AI-generated content to be identifiable. It did not authorise Anthropic to mix an ambiguous machine signal into a human author’s work and leave the author to clean up the consequences.

If Anthropic genuinely wants to meet a transparency obligation, it should limit watermarks to content substantially generated by the model. Ordinary proofreading must not cast suspicion of machine authorship over the whole text. A detection result must also say what Claude did, rather than return only a bare conclusion that a watermark exists.

Otherwise, compliance is merely using an author’s copyright as litmus paper. Anthropic drips its machine signal onto the work, waits for the colour to change, and then asks the author to explain to the world who actually wrote it.

The practice is unethical.

Compliance cannot be achieved by contaminating someone else’s copyright.