Watermarking AI Content: Good Start But More Parameters Needed

Experts welcome Anthropic’s move to watermark AI generated content but caution that it should not be the only benchmark.

By Entrepreneur Staff | Aug 19, 2026
file
AI chip artificial intelligence, future technology innovation

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Anthropic last week took everyone by surprise as it announced that it would be a watermarking context generated by its Claude model. 

While Anthropic’s move is aimed at complying with the EU AI Act’s Transparency Code, it signals the beginning of a new trend in the AI space – especially when it’s becoming extremely difficult to distinguish between AI-generated and human content. 

Since the announcement, there is a wide discussion on limitations of watermarking and places it can actually work. 

How will the watermarking work?

Anthropic in a detailed blog post explains that watermarking uses low-stakes choices like these—which occur many times over a piece of generated text—to leave a pattern in Claude’s responses. 

“That pattern is undetectable to the reader, but is detectable to anyone who has a key that encodes it. When watermarking is used, choices are still made at random, but the source of the randomness is different. Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick…” it said. 

It also summarised some of the key things that one should know about watermarking: 

We use a method of watermarking that does not have any practical impact on the quality or content of Claude’s outputs;

The difference between watermarked and un-watermarked text will not be distinguishable to readers;

Nothing is added to the text and there are no hidden characters;

Watermarking doesn’t require extra tokens, and will not be more expensive;

Watermarking carries no identifying information and can’t be traced to a specific person, organization, or chat;

Efficiency concerns 

Anthropic has highlighted some of the limitations with the new tool. For instance a complete rewrite of the text is unlikely to be detected by machines as AI generated. 

And then, it also cautions that “Claude may not be the original author. People often use Claude to proofread, translate, summarize, or convert files. The output can carry a Claude mark even if the underlying ideas, text, or data originated from another source…” 

Even as experts believe it’s a good start, they warn that it should not be the end and that it should not be the only benchmark to deduce whether a content is AI generated. 

In a statement, Bart Willemsen, VP Analyst at Gartner, says: “This first work on watermarking machine-generated content is a start, but should not be the end. Nefarious intent will find a way to undo or bypass the watermarks and so it works much like encryption: something is strong, until it no longer is and preparations need to already be in play to move to something more robust.”

“Image marking is initially arguably more persistent than markers for text – the latter doesn’t persist for example when someone just manually types again what was originally generated. For example, already with heavy editing, translation, or running the output through another model before subsequent usage,” he adds.

From a technical point of view, model-level watermarking requires central keys or verification APIs to prove origin. This poses a challenge to typical enterprises who are seeking to create a balance with secrecy and data privacy when they’re submitting documents to machines (third-party engines) to verify the watermarks or so. 

Vipul Prakash, Founder and CEO of FireAI tells Entrepreneur India: “This is a real tension, and I won’t pretend it isn’t. What’s reassuring, at least on paper, is that the watermark itself carries zero identifying information: no user, no organization, no chat history is recoverable from it, and there’s nothing embedded in the text beyond the statistical pattern. So the watermark’s existence isn’t a privacy risk. The privacy risk shows up the moment you have to send a full document to a third-party API to get it checked, because now you’ve handed over the content itself, key or no key.”

“…enterprises should treat a watermark-verification API exactly like they’d treat any other third-party data processor, under an NDA, ideally on infrastructure with contractual guarantees about retention and non-training use, the same diligence you’d apply before piping a document through any external service. I’d also expect, and would push the frontier labs to build, narrower verification primitives over time: a hash-based or on-prem check that confirms provenance without requiring the full document to leave your perimeter. Until that exists, the pragmatic move for anyone in BFSI, healthcare, or government, sectors we work closely with, is to only run watermark checks on content that’s already meant for external eyes anyway, not on anything still sitting inside your four walls,” he continues. 

Willemsen of Gartner also stresses that organizations should not rely on the absence of markers as assurance of manual creation. For reasonably controlled activities, maintaining the original markers simply adds a level of trust to the first communication. Nor should one appear certain that content is 100% AI-generated if a marker is present – they might also be added when AI is used to proofread or refine human generated texts. 

“The value of the markers then is context-dependent. It won’t likely combat malinformation (deliberately spreading wrong and harmful content) but in reduction of mis- and disinformation, the watermarkers are a good starting point,” he added.

From security point of view, Vignesh Sankaran, CTO – SAAFE Tech adds that sandboxed on-premise containers without external service involvement, Zero Data retention (ZDR) enforcements and complete data sanitization approaches have to be technically put in place to ensure the balance of corporate secrecy and data privacy.

He also cautions that statistical text watermarking modifies the underlying probability pseudo-random number generator (PRNG) seed to bias token selection without changing meaning. It acts as a soft heuristic, not an absolute cryptographic proof. Watermarking proves the origin of unchanged text but cannot prevent deliberate evasion.

That said, as mentioned above Anthropic’s new move is set to start a new trend of watermarking AI generated content across formats. However, it’s unlikely that watermark alone can solve the complex problems, especially around transparency. For now, we can expect other AI companies to follow the suit, at least to comply with the EU regulations.

Anthropic last week took everyone by surprise as it announced that it would be a watermarking context generated by its Claude model. 

While Anthropic’s move is aimed at complying with the EU AI Act’s Transparency Code, it signals the beginning of a new trend in the AI space – especially when it’s becoming extremely difficult to distinguish between AI-generated and human content. 

Since the announcement, there is a wide discussion on limitations of watermarking and places it can actually work. 

Entrepreneur Staff Editor

Entrepreneur Staff
For more than 30 years, Entrepreneur has set the course for success for millions of... Read more

Related Content