RSS Amplifier

Dangerously Educated by Tayla Burrell · Aug 22, 2026

Claude's watermark, clearly explained

0
Sign in to vote or save

Tayla Burrell · Dangerously Educated by Tayla Burrell

Welcome to every of you who have joined us since the last edition. This one is longer than usual because the topic earned it. There’s a copy-paste prompt near the end, and one date in here I’d write down somewhere you’ll see it again.

Two weeks ago I had a plan for this newsletter.

I was going to bring you the 40 giveaways that make it obvious you used AI to write something, and a skill that removes them from your drafts. I’d been collecting them for months. Every “it’s not x, it’s y”, em-dash, and “the honest part? you’re already behind”.

Then six days ago I woke up in a hotel room in Melbourne on a work trip, opened my laptop, and found out that Anthropic had made most of that list completely useless.

You have to laugh or you’ll cry.

On 11 August, Anthropic confirmed that every Claude model released after 2 August 2026 weaves an invisible watermark into the text it writes, and attaches signed provenance data to the files it creates. You can’t opt out. You can’t see it. And unless you spend 2 hours rewriting, you probably can’t get it out.

The internet took it about as well as you’d expect.

On r/ClaudeAI, in a thread that’s now sitting at 3,683 upvotes and 988 comments, the top comment was about code:

“Code too? There’s no way this doesn’t impact quality, you can’t optimise for both.”

By Monday, Business Insider was reporting on people cancelling their Claude subscriptions over it. And within a week, a GitHub repo appeared that claims to take the marks out. It has 13,299 stars as I write this. The ironic part is that nobody can prove it works.

But I think all the reactions are missing the point.

The anger isn’t unfounded. I feel it myself. If I spend 8 hours writing a newsletter and then use AI to do the tidying, how is it fair that the whole thing gets flagged as AI? That’s absurd.

I just think the mark itself is going to matter far less than everyone expects, and the changes that come from it are going to matter far more. There are real opportunities in this, if you know how to take them.

So here’s what we’re covering today:

  • Why this is happening at all, and the exact date everything changes

  • How the watermark actually works, and why you can’t just delete it

  • The four problems nobody has solved yet

  • The three big changes coming for us (and what I think this does to the value of your work)

  • The four things I’m personally doing about it this week

The EU has always been the strictest region when it comes to AI regulation. Great for safety, terrible for innovation. But it never really affected the rest of us, until 20 days ago.

On 2 August, the transparency obligations in the EU AI Act became enforceable (article 50, if you want to look it up). People must be told when they are using an AI system, and when content is AI-generated.

For Anthropic, OpenAI, Google and the rest, that means everything their models produce has to be tagged in a way machines can read.

The thing that’s annoying a lot of people is that the rules only apply in the EU. But the labs cannot hand out unmarked models by location without collecting far more identity and location data than any of us want to provide. So they applied it to everyone.

Which means we all suffer the consequences.

Anthropic’s watermark must be live on every model launched on or after 2 August 2nd. Which at the moment is… none. All the current models sit inside the EU’s grace period, and has until December 2nd to introduce the watermark.

But it’s been almost 2 months since a new model was released. We’re about to see the first watermarking model, and we need to be ready for it.

Before you start hating on Anthropic and cancel your Claude subscription, know that Anthropic did not start this. Google has been watermarking Gemini’s text with SynthID since 2024. OpenAI updated its own support page to cover text watermarking in the same week. Anthropic, OpenAI, Google, Meta, Microsoft and Mistral have all signed the EU code that requires it (no surprise the xAI has been silent on this one, though they will have to comply eventually).

Anthropic were simply louder, and got the whole internet’s reaction for it.

Which brings me to the thing almost everyone has wrong: what this mark actually is.

There are two completely separate watermarking techniques that will now apply to all content generated with AI.

The first is inserting an imperceptible watermark in the text itself, and it can’t reliably be removed.

When Claude writes something, it won’t just put a special character on the end or add something into the metadata. That would be too easy to remove.

Instead it will change the randomness it uses when picking each word, so its word choices form a pattern a detector can spot across enough text. You can’t see it, and neither can I.

The pattern lives in the words themselves, no amount of copy and pasting into Google Docs, Substack or emails will remove it.

But the watermark can only be identified with enough volume, so an Instagram caption will be more difficult to identify than a 2,000-word article. Code is similarly less identifiable, because there are only so many valid ways to write the same function.

The best explanation of the technique is an interactive essay by James Padolsey, How AI Text Watermarking Works. It’s an incredible interactive read, and if you have any interest in this at all, definitely check it out.

The second technique is in the files, and this can be removed.

When Claude creates a PNG, a JPEG or an SVG, it will now attach a signed C2PA manifest. That’s an open industry standard, and unlike the text mark, this one lives in the file’s metadata, which means that if you screenshot, copy and paste it to a new doc or re-export it, it comes off straight away.

As of the time I’m writing this, this currently only applies to the three image formats, not your PDFs and Word documents.

You can’t escape these changes. They apply everywhere. It’s added at the model level, so it covers Claude Chat, Cowork, Claude Code, and the Claude API. And if you try to edit them away? It might work, but nothing is guaranteed. Anthropic’s own wording is that the watermark “may persist through some editing”, which is not exactly reassuring.

As you could imagine, these techniques have created some big unintended consequences that nobody has solved yet.

Every rule like this has second-order consequences that people can rarely predict. This rule was written to stop deepfakes and undisclosed AI slop. What it has actually produced is four problems that land on people like you and me.

The thing I find so interesting here is how many philosophical questions this has created, and it really feels like the ethics and morals are coming to the forefront.

There’s been a lot of talk online so I’ve grouped it into a few key themes that I’ll share with you first so that you can kind of form your own perspective on it before I give you mine.

Most of the panic I have read is built on a mental model that goes: Claude has installed an AI detector, and one day soon a client or a follower or a coworker will run your work through it and find out you cheated.

In reality, that’s not what this is. A detected mark means the text passed through Claude. It does not mean Claude wrote it. Ask Claude to fix the typos in something you wrote at midnight, and that paragraph carries the mark. Ask it to translate your own copy into Spanish and the Spanish carries the mark. Ask it to tighten your intro and the tightened intro carries the mark.

The watermark says nothing about authorship. The problem is that algorithms, AI detectors and other people do not know that.

The harsh truth is that if you do not educate your audience, your clients and your team on what the mark actually means, they will assume you did not do the work. It’s extremely unfair. But we cannot change it. All we can do is work with the reality, which is why the last section of this is what I’m personally doing about it.

If it’s useful, send this newsletter to them directly. Then you know they are getting the accurate version instead of all the misconceptions going around on LinkedIn and Instagram.

The most-watched YouTube video on this whole story isn’t about writers or creators or business owners, or even the update itself. It’s a video from Caleb Ulku titled Claude’s Watermarks Just Broke SEO, and it has 135,537 views in 7 days, because nobody knows what will happen when Google can finally sort its entire index into human and AI.

Nobody knows whether Google will act on these marks. Anthropic hasn’t said. Google hasn’t said. But if you’ve been publishing AI-assisted articles to a blog for two years, you now have a lot of pages carrying a machine-readable signal you never knew you were adding, and no way to check which ones.

I think that this has received so much traction because it’s the question with the most amount of money attached to it. If this changes SEO, entire industries will be turned on their heads, and the fallout will be immense.

Imagine creating a system that instantly reveals whether someone gained muscle from the gym or from steroids, but giving nobody the ability to use it. That’s roughly where we are.

There is no public detector. Anthropic can read the mark. You can’t. Every tool currently advertising “Claude watermark detection” is guessing, and Forbes ran a piece on 16 August on how many of the removal apps that appeared are outright scams, some carrying malware.

An engineer on the Claude Code team confirmed on 12 August that a detection API is coming and that third parties will be able to use it. But even then, his words were: “it is not perfect, you can edit it, but it’s a first step.”

Which creates a fundamental problem. The tool that lets your client verify your work is the same tool that lets you remove the AI trace. You paraphrase, you check, you paraphrase again, you check again, until it comes back clean. At current API rates that’s about four cents per pass over a thousand words. A no-brainer.

The most immediate concern when Anthropic first announced this change was the impact it will have on the quality of AI’s work.

John Gruber (the inventor of markdown) released a 4,500 word blog post on 16 August titled Anthropic’s ‘Watermark’ Text Adulteration in Claude Is a Perversion of Writing, and it was extremely popular on Hacker News. His argument is worth understanding even if you disagree with it. He wants the model to pick the best, most precise word at every decision point, for him. The moment those choices are also serving somebody else’s objective, they aren’t the best words any more. Anthropic’s defence is that swapping “grey” for “overcast” changes nothing for the reader. Gruber says that’s exactly the problem.

No two synonyms carry the exact same meaning. “He leaped at the chance” and “He jumped at the opportunity” are very similar sentences expressing the same general sentiment, but they are not the same. The exact words we choose when writing matter.

Then there’s code, which is where I think the bigger damage sits. So much of what’s actually useful about AI right now is only possible because it can write code. Your vibe-coded dashboard, your slide generations, your automated daily brief. All of it is code.

And code has almost no room for a watermark to hide in.

If I learnt anything from the two programming classes I took at university, it’s that one wrong character out of 10,000 can completely change the output (and not for the better).

Until we see the results from the first watermarking model, everyone arguing about this, including me, is just guessing. But it will be interesting to see the fallout if it does come to fruition.

After reading and watching hours of content about this, I’ve thought very deeply about what I think this means for those of us with businesses, personal brands or any kind of IP you’re monetising.

This is my best attempt to distill it down to just 3 points about where the future is going. The principles that will outlast the current news cycle and stay relevant 12 months from now when AI has changed yet again.

Human-made is about to command a premium, the same way handmade already does.

Think about how you feel when you find out something was AI-generated. Nothing about the work changed. But something feels different. You were reading a newsletter, watching a video, looking at an image as a message from a person, and it turns out it was not.

Your perception of value just dropped.

We already price this in everywhere else. A ceramic mug made by someone at your Sunday market costs five times the one from Kmart. You’re not paying for a better mug, but for the fact that a specific person made it, with their hands, and not a factory or a supply chain you would rather not think about.

If we carry this through to the knowledge economy, I’m already seeing services split into three models.

1. The “good enough” model. AI-run businesses producing work faster and cheaper than we’ve ever seen. $100 vibe-coded websites, same-day brand kits, accounting at a tenth of what an accountant charges. These do not have to be perfect and nobody expects them to be, because you get what you pay for. They are still far better than what most people could make alone, and I think an enormous market of micro-businesses will open up here.

2. The “human-made” model. These businesses will charge a premium for the single reason that no AI touched it, a claim that gets rarer by the day. Hand-illustrated brand identity. Editorial writing with no AI input. Original photography instead of generated stock. The trap is that you can only survive here if you are exceptional, because you are competing with people who have far more intelligence and labour on demand than you do, and you have to beat them by enough to justify the price.

3. The “AI-first” business model. You take the thing only you have - your IP - the frameworks, skills, methods and insights that you’ve built through actually doing the work, and you combine it with AI to deliver better results in less time, with less effort for them. Imagine you coach people on how to overcome objections to close a sale. As an AI-first founder, you give them a custom AI tool, trained on your IP, where they can practice the close, get feedback and improve without you in the room. AI that only works because of your unique knowledge.

This is the direction I’m endeavouring to take. My work got substantially better once I started using AI strategically rather than avoiding it, and I would encourage almost everyone reading this to be there too, with honest disclosure about where it sits in your process.

There’s no right answer. But choosing which lane you want to sit in and owning it fully has just become one of the most important things any person or business can do.

Models are trained on the internet. The internet is now full of AI writing. So each generation of models learns more from it’s own previous output (called synthetic data) and less from humans. Over time they slide further from how people write and closer to how machines do.

Researchers call this an autophagous loop (or AI Inbreeding if you like).

If that kept compounding, it would get very hard for these models to keep improving. Being able to identify AI text means the labs can filter it out of training data and train on human writing instead. The EU has effectively handed every AI lab a get out of jail free card on the biggest problem in their industry.

Whether it saves us from em-dashes, “it’s not x, it’s y”, and “not because x, but because y” is probably too much to hope for.

As I am writing my first draft of this newsletter, it is 6:51am on a Tuesday. I am in Melbourne for my actual job, I have had this newsletter half-formed in my head for a week, and I am voice-noting into my phone before the day starts.

What you are reading is the result of me:

  • Giving those voice notes to AI

  • Using my newsletter skill to consolidate them into a starting point

  • Editing it properly on Saturday morning so I can get this out to you, even though it’s been a crazy busy week

Without that, you wouldn’t be reading this. I didn’t have the hours.

That’s where the line sits for me. Being able to decide “I want AI to help me write this piece”, not feel bad about it, and tell you that AI did help me write this piece. And I can say that with zero shame because the thinking is mine and the alternative was you getting nothing.

But the edition before last, I wrote entirely myself. And most of them, honestly, because the goal of my work is not just to inform you or give you tips and advice. It’s to give you a new perspective and a good enough incentive to actually go and do something differently enough to get results.

That comes down to how well I can get what is in my head into yours, and AI could never do that justice.

So I am clear for myself on where AI fits. And I’m confident about what it this stance will do for my brand, how I am perceived, and the value you get from reading this each week.

That’s my line. I encourage you to create your own version of it, written down.

Where AI sits in your process, where it does not, and why. Once you have that, this whole story about AI identified text stops being a threat and becomes something you can actually back yourself to talk about without shame.

Paste this into Claude (or whatever you use) and answer the questions honestly:

I want to work out exactly where AI belongs in my work and where it doesn't, so I can be honest about it publicly instead of vague.
My context:
- What I do: [e.g. I write a weekly newsletter and take on 2-3 brand strategy clients a quarter]
- What people are actually paying me for: [e.g. my judgement on positioning, not the words themselves]
- Where I use AI now: [e.g. research, structuring my voice notes, first drafts of admin emails, never the ideas]
- Anything I've signed that mentions AI: [e.g. one client contract says "original work" and I'm not sure what that covers]
Interview me one question at a time. Don't ask me things you can already work out from what I've told you. Start by pushing back on where my current line is inconsistent, then help me write two things: a plain-English disclosure I could put on my site or in a proposal in my voice, and a short list of the specific tasks where I've decided AI doesn't belong, with the reason for each.
Keep it simple and non-technical. Assume I'm smart but not a developer, and only move to the next step once I've answered the one before.

Reading my contracts. The Claude watermark story is not a small one, and many business have probably taken the opportunity to think about their own AI usage policies. Start keeping an eye on your client agreements, brand partnerships and platform contracts. Search for terms like “AI”, “original work” and “human-authored”. If something’s in there, far better that you find it than face the consequences down the track.

Doubling down on my AI model. There’s three models I gave you for how your content and business can fit in this new AI landscape. I’m going for the AI-first model. Whatever you choose, own it, and be upfront about it. Play to your strengths.

Not buying a watermark remover or a detector. Neither can be verified right now, the real detector does not exist publicly yet, and a solid chunk of those apps are scams with malware in them. The easiest money you will save all month.

Not switching to a new model over this. Every major lab except xAI has signed the same AI code. One will start, then the others always follow. I wouldn’t stress about trying to find the workaround. If you are stressing, it’s probably a sign to re-assess how you’re using AI.

Your co-workers, clients, friends, family and audience all need to know about these changes. For their careers and themselves. Sharing this with them is the most useful thing you can do to help them prepare.

Share

I write this newsletter on my mornings and weekends to keep you informed and ahead of AI, without the hype. If you’re finding Dangerously Educated helpful, you can support the newsletter by becoming a paid subscriber.

No posts

Read the original on taylaburrell.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.