RSS Amplifier

Gal Ratner · Aug 19, 2026

Your Cover Letter Gets a Watermark. Their Layoff Doesn't.

0
Sign in to vote or save

Gal Ratner · Gal Ratner

On August 2, a European rule took effect that changed how every major AI company marks the text its models produce. Twelve days later Anthropic published the engineering explanation for how Claude does it, and the mechanism is more elegant than the outrage around it suggests. The mark rides inside the words themselves. No hidden characters, no metadata, nothing you could strip with find-and-replace. When the model reaches a point where two words are equally good, where “overcast” and “grey” would both finish the sentence, the choice now comes from a cryptographic key instead of an ordinary random number. Do that a few hundred times across a document and you have left a statistical fingerprint that anybody holding the key can read back.

It applies to every word Claude writes for you, everywhere on earth, with no opt-out, because Anthropic says it does not yet have a durable way to scope the behavior by region.

Now hold that next to something nobody put in a press release. In the same month that European law made your use of an AI system provable from the text you produced, there is still no rule anywhere requiring your employer to disclose that an AI system is why your job no longer exists. Not in the EU. Not federally in the United States. One American state added a checkbox to a form, and what happened to that checkbox is most of what follows.

On the same day Anthropic published the watermark explainer, Google announced that Gemini users could finally turn off the visible watermark on generated images, video and music. The sparkle logo stamped in the corner had been real friction for anyone doing professional work, the digital equivalent of delivering a comp with the stock-photo watermark still on it. Coverage read it as a win for creators. People who had been asking for it got a settings toggle and a small sense of having been listened to.

Google was entirely upfront about the rest. The same announcement said the invisible SynthID watermark and the C2PA provenance metadata stay embedded regardless of the setting. The Gemini account posted it publicly. Every outlet that covered the toggle reported it in the second paragraph. Nobody hid anything, and almost nobody registered it, because a visible toggle absorbs the entire conversation and a permanent invisible layer generates no conversation at all.

Look at what was actually transferred. Users received control over whether a logo appears in a corner, a layer that governs how their work looks. Users received no control whatsoever over the layer that survives cropping, compression and format conversion, the one that governs what can be proven about their work later. There is no setting for that. There is no plan tier that unlocks it. Google’s VP for Gemini described the change as a balance between creative control and safety, and the balance is precise to the decimal. The user got the cosmetic layer. Google kept the evidentiary one.

The shape of the generosity is worth noticing too. The toggle is not offered in countries where visible AI labels are required by law, so the concession appears exactly and only where nothing compelled it. And in India, South Korea and Vietnam the option is reportedly restricted to Google AI Ultra subscribers, meaning content generated on cheaper plans in those markets keeps the visible badge automatically. Even the decorative freedom is a paid upgrade, and the people who cannot afford it are the ones who go on wearing the mark in public.

Hold that pattern, because it recurs. You are handed a lever over the layer that does not matter. The layer that determines what can be established about you is not on the menu, and was never going to be.

Article 50 of the EU AI Act is the transparency arm, and its second paragraph is the one that produced the watermark. Providers of systems generating synthetic audio, image, video or text must mark those outputs in a machine-readable format, detectable as artificially generated or manipulated. Around 190 organizations signed the accompanying Code of Practice at the end of July. Failure runs to fifteen million euros or three percent of worldwide turnover, whichever is larger.

Read the rest of the article and the shape of the thing comes into focus. Paragraph one covers telling people they are talking to a chatbot. Paragraph three covers emotion recognition and biometric categorization. Paragraph four covers deepfakes, plus text published to inform the public on matters of public interest. Paragraph five governs how visibly all of that has to be disclosed. The Commission finalized three separate icons. It issued guidance on whether a digitally de-aged actor counts as plausibly real.

Every clause of it regulates synthetic content. Not one clause regulates synthetic labor. There is no provision anywhere in Article 50 requiring a company that eliminated a function because a model now performs it to mark that fact in any format at all, machine-readable or human-readable or otherwise, and no fine attaches to staying quiet about it. The European Commission built a provenance regime for paragraphs and left the provenance of an unemployment claim entirely to the discretion of whoever caused it. Content provenance protects a reader from being deceived. Labor provenance would protect a worker from something, and nobody drafted it.

New York went first. In January 2025 Governor Hochul directed the state Department of Labor to add a question to the WARN Act notice, the filing a company must submit before a mass layoff. The question asks whether technological innovation or automation contributed to the cuts. Check the box and you name the technology. It went live that March, the first requirement of its kind in the country.

More than 160 companies filed WARN notices in New York over the following year. Not one of them attributed a single layoff to AI or automation.

Set that against what those same companies were telling a different room. Challenger, Gray & Christmas tracks the reasons employers give publicly for cutting jobs. In 2025 employers cited AI in 54,836 announced cuts. Through June of 2026 the figure had reached 101,743, roughly twenty-three percent of all announced cuts that year, and AI held the top spot as stated reason for five consecutive months through July. Since Challenger began tracking the category in 2023 it has been named in more than 173,000 job cut announcements.

Tens of thousands of layoffs publicly blamed on AI by the very companies doing the laying off, and zero of them surfacing on a state form that asks the identical question in a venue where the answer carries legal weight. Either New York is an extraordinary statistical outlier in the American labor market, or the answer a company gives depends entirely on who is asking.

To investors, AI is a growth story. It reads as discipline, as modernization, as a leaner cost structure run by people who understand where the world is going, and it moves the stock. To a state labor department, AI is an admission that triggers retraining obligations and creates a paper trail somebody’s lawyer will read back to them later. Same company, same quarter, two audiences, two answers, and no mechanism anywhere that forces the two to reconcile.

The penalty structure finishes the explanation. New York’s WARN Act carries a civil penalty of five hundred dollars a day for failing to file the notice. Nothing whatsoever attaches to the checkbox. It is voluntary self-attribution with no audit behind it, and it has performed exactly the way an unenforced disclosure always performs. Fifteen million euros if you fail to watermark a paragraph. Not one dollar if you decline to say why four thousand people are out of work.

And those four thousand people will never be told. There is no form that requires it, no filing they can request, no agency that collects it. A man who spent eleven years at a company gets a calendar invite, a severance packet and a stated reason that will never mention the system that replaced him, and if he suspects it anyway he has no document to point at, because the only document that asks the question does not have to be answered honestly and carries no penalty for silence. He will go home, open his laptop, and start rewriting his resume in the same tool.

The watermark itself is neutral. Where it lands is not, and the mechanism explains why.

Anthropic’s own documentation is unusually candid about the limits. The mark indicates that Claude was likely involved at some point. It cannot distinguish Claude having written something from Claude having heavily edited it. Detection degrades on short passages. It thins out on factual writing, where the correct word is the only word available, and on code, where an exact token is required or the thing breaks.

Those caveats matter more than they look, because they mean the strength of the signal scales with how much of the writing the model actually did. Which is to say it scales inversely with how much you already knew how to do yourself. A confident writer who runs a paragraph past Claude for a grammar check leaves almost nothing behind. Someone who needed more help leaves more.

So consider who needs more help, and what tends to happen to them when a mark turns up.

Picture the actual population here. A man disputing a charge on his power bill who wants the letter to sound like it came from someone the utility should take seriously. A woman whose English is her third language rewriting a resume for the eleventh time. A contractor drafting a scope of work at eleven at night. None of these people are committing fraud. None of them know a mark exists, because nobody told them in any form they would ever encounter. They are paying a monthly subscription for the privilege, competing in a labor market contracting underneath them partly because of the same tool, and the tool now writes their reliance on it into the output in a form they cannot see, cannot verify and cannot contest.

To be exact about what the mark does and does not do, because the distinction matters and the sloppy version of this argument gets destroyed: the watermark does not identify you. Anthropic is clear that it carries no identifying information and cannot be traced to a person, an organization or a chat. It says an AI was involved. Nothing more. But your resume already has your name on it. Your letter to the power company already has your account number. Your client deliverable already has your invoice attached. The mark never needs to identify anyone, because by the time it is read, the document is already sitting in a folder with your name on the tab. Provenance attaches to the individual by circumstance, every time, automatically, and attaches to the corporation never.

We have already run this experiment with worse instruments and we know the result. A Stanford team tested seven commercial AI detectors against essays written by non-native English speakers. The tools flagged that human writing as machine-generated sixty-one percent of the time, and on roughly a fifth of the papers all seven agreed with each other. Against native speakers the same tools were nearly error-free. Turnitin, deployed across more than sixteen thousand institutions, once labeled over ninety percent of a single international student’s paper as AI-written. Subsequent work has found the same skew against neurodivergent students, and a Common Sense Media report found Black students more likely to be accused. The complaint faculty keep repeating is that there is nothing to inspect. A score appears, and the student has to disprove a number.

Anthropic draws the distinction itself, noting in the FAQ that commercial detectors work by spotting AI’s verbal tics rather than reading a key, and then volunteering two of the tics: models are fond of the construction “this isn’t X, it’s Y,” and they reach for the word “quietly” far more often than people do. I have now cut both out of this piece twice.

The obvious response to all of this is that those detectors are statistical guesswork while a watermark is cryptography, so the watermark will simply be more accurate. Accuracy was never the binding constraint. The damage comes from an enforcement culture that treats a number as an accusation, is already deployed at institutional scale, already skews in a documented direction, and is now getting an upgrade that works.

Meanwhile the appeals machinery does not exist. Anthropic has said a detection API is coming and has published no accuracy threshold, no false positive rate, and no dispute procedure. The EU Code requires providers to offer detection free of charge and specifies unrestricted free access for regulators, law enforcement, media, fact-checkers, researchers and civil society. Read that list again and notice who is missing from it. Every party guaranteed access is a party running the check. The person whose contract just got cancelled over the result is not named anywhere in it.

I have spent close to thirty years shipping production software, and for the last two most of what I ship is agentic. I built and deployed a wedding planning agent that handles live customers and PCI-scoped payments. I have written the MCP servers, the tool loops, the retrieval pipelines, the observability layer underneath all of it. I am not a spectator here. I am one of the people whose work makes the headcount arithmetic come out the way it does.

That is exactly why the asymmetry is so visible to me. I have been in the meetings. Nobody puts “we replaced them with Claude” on a slide. The slide says organizational efficiency, or modernization initiative, or right-sizing to the operating model. Then the same executive gets on the earnings call two weeks later and talks expansively about AI leverage, because that language is worth something to the share price. Both statements are true to their audience and nothing in the system forces them into the same room. And I have watched it from the other side of the table too, sending architecture work into a market where entry-level technical hiring has fallen through the floor, knowing that the roles I would have hired into fifteen years ago are precisely the roles the systems I build now absorb.

The hardest part of this to argue with is a matter of public record.

In May 2025 Dario Amodei told Axios that AI could eliminate half of all entry-level white-collar jobs within five years and drive unemployment to somewhere between ten and twenty percent. He said the people building the technology have an obligation to be honest about what is coming, and that most people simply did not believe him. He was blunter than any other executive in the industry and, on the trend line since, closer to right than the people who called it fearmongering.

On August 15 of this year, one day after his company published the watermark explainer and in the middle of a visible wave of subscription cancellations over it, Amodei posted that the backlash against AI is fundamentally a crisis of trust. Ordinary people, he wrote, do not trust companies or governments or the tech industry, and always suspect somebody is cooking up a new way to screw them over. He located the cause in a condition decades in the making rather than in a decision his own company had shipped twelve days earlier.

He has said harder things about his own industry than most of his peers, including that the most accurate criticism of AI companies is that they have not delivered on their promises. That is on the record and it counts for something. It does not survive contact with what happened next.

The forecast was correct and the forecaster spent the following year accelerating toward it. Anthropic did not slow down after May 2025. It shipped faster models, better coding agents, longer autonomous runs, and sold them to the exact companies restructuring around the labor they replace. Foreknowledge is not a defense. In every other industry it is the aggravating factor, the thing that turns an accident into negligence. A company that publishes a forecast of the harm its product will cause and then optimizes the product does not get absolved by the forecast. The warning established knowledge. It never established care.

So the sequence reads plainly. The executive who called the displacement a year before anyone else now runs the company that shipped the mechanism making a displaced person’s use of AI provable, while leaving the displacing company’s use of AI entirely unrecorded. Brussels wrote a content rule instead of a labor rule, a deadline arrived, one hundred and ninety organizations shipped in unison. Nobody needs to have intended the result for the result to be what it is.

Put the two projects side by side, because the comparison does all the work.

Text watermarking was forecast, regulated, fined, and shipped worldwide across every major provider in roughly three weeks. It required embedding a cryptographic key into token sampling across global inference infrastructure, coordinating a technique out of a Nature paper, and doing it without measurably degrading output. Hard engineering, delivered under deadline, at scale, by competitors simultaneously.

Labor displacement was forecast by one of those same providers a year earlier, in public, in numbers. It has been regulated nowhere, fined nowhere, and the corresponding disclosure mechanism does not exist. What it would require is a mandatory field on a form that companies already file.

One of those is a genuinely difficult distributed systems problem. The other is a checkbox. The difficult one took three weeks because fifteen million euros was attached to failing. The checkbox has produced zero disclosures in eighteen months because nothing at all is attached to skipping it. Nobody in this story is incapable. Everybody in it is responsive to consequences, and consequences were only ever installed in one direction.

I do not think the product is being crippled. The watermark adds no tokens, costs nothing extra, and does not slow generation. DeepMind served a watermarked model to a slice of live Gemini traffic and found no statistically significant difference in user ratings, and a controlled study of side-by-side answers found no perceptible quality gap. If you cancelled your subscription over degraded output, the evidence is not on your side, and Anthropic will have no difficulty saying so.

I am not alleging a conspiracy, and the piece does not need one. Amodei has called for policy responses including taxing AI companies so the gains do not pool at the top. One hundred and eighty-nine other organizations signed the same code. Google and OpenAI are building versions of the same thing. Every one of those facts is true and none of them changes where the mark lands.

And the Challenger figures deserve a hard look, because they are employer self-attribution rather than audited causation. Daniel Zhao at Glassdoor has warned that a company saying AI drove a layoff does not make it so, and Fabian Stephany at the Oxford Internet Institute has raised the same concern about firms scapegoating AI to dress up ordinary cost cutting. Some real share of that 101,743 is a story executives told rather than an event that occurred.

Follow that caveat all the way down and it lands somewhere worse than where it started. The only public numbers we have for AI-driven job loss were volunteered by companies, for their own reasons, to an audience they were actively trying to impress, while those same companies volunteered nothing at all to the one form with legal consequences attached. We have no reliable measure of how many jobs AI has actually eliminated, because nobody is obligated to produce one, and the only parties who know have every reason to keep both versions in circulation.

Which brings it back to what Amodei actually said in August. Ordinary people, he wrote, always suspect that companies and governments are cooking up some new way to screw them over. He offered that as a diagnosis of an irrational public mood decades in the making. Take it instead as a testable claim, and test it against his own company’s record across the same eighteen months. The technology got faster. The forecast came true. The disclosure regime that shipped covers the resume and leaves the layoff alone. The suspicion does not require anybody to be plotting. It requires only that the harm land on people who did not choose it while the accountability lands on people who cannot contest it, and both of those have stopped being suspicions.

None of this requires abandoning watermarking. Provenance is useful and I want more of it, not less.

It requires three unglamorous things. Publish the false positive rate and a dispute procedure before the detector ships, and guarantee access to the accused individual by name rather than only to regulators and journalists. Make AI attribution on layoff filings mandatory, auditable and penalized when wrong, so that a 160-to-zero result becomes impossible instead of merely costless. And carry the logic of content provenance one step further, so that a company deploying AI to eliminate a function has to say so with the same specificity Europe now demands of a paragraph.

Connecticut is already partway there. From October 1 of this year, employers filing WARN notices in the state must disclose whether the layoffs relate to their use of artificial intelligence, and an affirmative answer carries obligations rather than sitting inert on a form. One state, and it lands two months after the watermark did.

Every one of those fixes is easier than what already shipped. Embedding a cryptographic key inside token selection across a global inference fleet, in coordination, across every major provider, in about three weeks, is a harder problem than requiring a company to say why it cut four thousand jobs. The industry proved this month that it can move at extraordinary speed on transparency when a fine is pointed at it.

There is a version of AI transparency that protects readers from being deceived, and there is a version that protects workers from being replaced without anyone having to say so. We built the first one this month, at remarkable speed, worldwide, across competing companies, under threat of nine-figure fines. The second one has been sitting on a New York form since March of 2025, unchecked one hundred and sixty times, waiting for somebody to attach a consequence to it.

Google gave its users a toggle for the logo in the corner and kept the layer that proves things. Brussels gave the public a provenance regime for paragraphs and left the provenance of a lost job to the discretion of whoever caused it. Anthropic’s CEO told us this was coming, built it faster, and then explained that our distrust is a decades-old condition rather than a response to anything in particular. Every one of those was defensible on its own terms. Put them end to end and you get the same result each time, which is that the people with the least ability to contest an accusation are the only ones who reliably end up marked, and the entities that could have been made to answer for any of it never once were.

Gal Ratner is the founder and CTO of Inverted Software and WhiteStar Labs, and Chief Architect at Prana Entertainment in Las Vegas. He has spent close to thirty years shipping production software on the Microsoft and .NET stack for clients including Microsoft, Sony, Rockstar Games, 2K Games, Best Buy and Allegiant Air, and was employee number six at Break.com. His current work is production agentic AI: MCP servers, the Microsoft Agent Framework, RAG pipelines, SQL Server 2025 vector search, and the PLogger observability framework. He is the author of the novel The Archive of Lost Suns, rides motorcycles, co-hosts Edge Grip Podcast, and trains Brazilian jiu-jitsu in Las Vegas. He writes about what actually ships at galratner.substack.com.

Disclosure: the reporting and argument in this piece were developed in conversation with Claude, made by Anthropic, whose watermark is one of its subjects.

No posts

Read the original on galratner.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.