AI watermarks cannot tell writing from editing
TechnologyAugust 23, 2026

AI watermarks cannot tell writing from editing

Anthropic has started watermarking the text Claude writes. An AI generated document watermark is not a stamp on the page. It is hidden in the words themselves, and it travels into whatever you paste it into, including the proposals and scopes of work that leave your business.

That much is real. Most of what is being said about it is not.

What was announced, and what was not

Anthropic published the details on 14 August 2026. The mechanism is not a tag on the file and not a note in the metadata. It works by making low-stakes word choices that form a pattern, invisible to a reader, readable by anyone holding the key that encodes it.

Two claims have attached themselves to the coverage that followed, and the announcement supports neither.

The first is that Claude stamps a watermark inside the Word and PowerPoint files it generates. Anthropic's announcement does not mention Office documents anywhere. What it describes is a content credential attached to generated files of supported types, and the examples given are .png, .jpg and .svg. Content credentials are C2PA metadata, a different mechanism with different properties, and metadata can be stripped by anything that re-saves the file.

The second is that this is live everywhere today. The wording is that future Claude models will generate watermarked text. Models launched before 2 August 2026 sit inside an EU transition period, and Anthropic says watermarking for those will roll out over the coming months.

Nobody can check a document yet

There is no detector. Anthropic says it will "soon be offering a watermark detection API" and is "in the process of working out the details of its implementation."

So the position today is a marker that exists, in text you have already sent, that nobody outside Anthropic can read. That is worth sitting with before anyone panics.

The limit nobody has quoted

Anthropic published what the watermark cannot do. One of the three should change how a South African business reads this story.

"Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text."

Set that against the documents you actually worry about. A scope of work is factual. So is a quote, a method statement, a tender response, a board pack. These are documents where the words are constrained by the facts, which is exactly where Anthropic says the signal thins out. The watermark is weakest where your commercial writing lives.

A second limit points the same way. Detection "doesn't work well on small samples, where there are fewer word choices and thus less information to go on." A covering letter is a small sample.

The exposure is not the one you expect

The third limit runs the opposite way, and it is the one that should concern an operator.

"A watermark can only determine that Claude was likely involved with the content at some point. It cannot distinguish 'Claude wrote this' from 'Claude heavily edited this.'"

Anthropic adds that light editing probably will not remove the marker, and that only a complete rewrite replacing every word will.

Put those together. A proposal your team wrote, that someone ran through Claude to tighten the language, carries the same signal as one Claude drafted from nothing. The marker does not separate them and does not claim to.

The risk to a business here is not being caught passing machine writing off as its own. It is being flagged for something it was entitled to do, by a tool that cannot tell the difference, in front of a client who assumes it can.

What South African law asks of you

Nothing.

The watermark exists because of the European Union's AI Act, whose transparency code took effect on 2 August 2026. That law binds providers of AI systems. It does not reach into a South African business's tender submission.

No National Treasury instruction note and no published provision of the public procurement framework requires a bidder to disclose AI assistance. There is no rule here to breach.

That makes the exposure contractual and reputational rather than legal, which is harder to manage rather than easier. A client who feels misled does not need a regulation to end a relationship.

The Monday version

The useful response is a records question, not a policy one.

If a client asked which of the documents you sent them last quarter were machine drafted, could you answer? Most businesses cannot. They keep no note of which proposals were assembled with AI help, by whom, or how much of the first draft survived into the version that went out.

Fixing that is cheap while the question is hypothetical. Keep a plain record against outbound documents that matter, covering who wrote the first draft, what tool touched it, who edited it and who signed it off. That belongs in the systems you already run rather than in a new one, and it is the same discipline that makes a document defensible for any other reason. Zorah has yet to meet a mid-market business that keeps it.

A policy telling staff how to use AI is the easy half, and most businesses now have one. The half that answers a client's question is the record.

The companion to this piece is the inbound version of the same problem. Your prompts and your drafts are records too, and they are discoverable.

ShareLinkedInEmail

Comments (0)

Leave a comment