Anthropic announced last week that new Claude models will embed machine-readable watermarks into generated text and signed provenance metadata into generated files, starting with models launched on or after August 2, 2026. The stated reason is compliance with Article 50 of the EU AI Act. The coverage since has focused almost entirely on the wrong question.

Most of the commentary asks: can the watermark be detected, and can it be removed? That’s an engineering question, and an interesting one, but it’s not the question that matters if you’re a solo operator, a consultant, or a small agency publishing text that an AI helped you think through. The question that matters is procedural: what happens when someone else’s detector flags your content, and what do you have to show for yourself when they do.

I went through this reasoning out loud, in the same kind of conversation this article is drawn from. Writing it down felt worth doing, because the conclusion isn’t what I expected going in.

What actually got announced

Anthropic’s help center is fairly precise about scope. Claude models launched on or after August 2, 2026 carry an imperceptible watermark woven directly into generated text, and supported file types (like .svg, .png, .jpg) get signed provenance metadata conforming to the C2PA standard. The marking applies globally, not just to EU users, and covers every product surface: the consumer app, the API, Claude Code, Claude Cowork, Claude Tag.

Two things worth noting about the mechanism itself. First, Anthropic states the watermark doesn’t change the meaning of the output, it works by nudging word choice between statistically equivalent options at points where several words would fit equally well. Second, and more relevant to what follows: Anthropic itself cautions that a detected mark isn’t conclusive proof AI produced something, and the absence of a mark doesn’t prove AI wasn’t involved. Detection tooling for third parties hasn’t shipped yet either, so right now nobody outside Anthropic can actually verify any of this independently.

That gap, between “a mark exists” and “provable authorship,” is where the real exposure sits.

The law has an exemption built for this. It’s just narrow.

Article 50(4) of the AI Act requires disclosure when AI-generated text is published with the purpose of informing the public on matters of public interest. But it also carries an explicit carve-out: the obligation doesn’t apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication.

That exemption is written almost exactly for the process most people I know already use: draft with AI assistance, read it, decide whether to publish it, take responsibility for what goes out. The problem isn’t that this process fails the legal test. It’s that the exemption requires demonstrating the review happened, and draft guidance interprets that requirement narrowly. A quick skim doesn’t count. What counts as sufficient review, and what counts as “public interest” for a given website, are both still being worked out in practice, not settled by case law.

Where this gets uncomfortable in Germany specifically

Article 50 itself doesn’t create a right for private parties to sue you. But German competition lawyers are actively arguing that a missing disclosure counts as a breach of a “Marktverhaltensregel,” a market conduct rule, under § 3a of the UWG (the unfair competition law). If that classification holds, and it hasn’t been confirmed by the highest courts yet, a competitor or a qualified association could send an Abmahnung, a cease-and-desist demand, over a missing AI label, independent of any regulatory fine from the AI Act itself.

For a freelancer or small agency, this is the actually relevant risk. The €15 million / 3% of turnover figure attached to the AI Act itself is not what lands on your desk. A UWG-based Abmahnung, with legal costs and a demand for a signed cease-and-desist declaration backed by a contractual penalty, is what lands on your desk. And unlike the regulatory fine, private enforcement doesn’t require a government investigation to get started. It requires a competitor, a detector, and a lawyer willing to send a letter.

If that sounds familiar, it should. It’s structurally identical to the Google Fonts Abmahnwelle of 2022, where automated crawlers scanned websites for dynamically loaded Google Fonts, generated screenshots as “proof” of a GDPR violation, and law firms sent thousands of near-identical demand letters. The underlying violation was often real. The claimant’s standing to complain about it frequently wasn’t, because many of them had never actually visited the sites in question; a bot had.

What eventually stopped the fonts wave, and why it matters now

German courts eventually pushed back hard on the fonts pattern, and the legal tools they used aren’t specific to fonts. Courts found that automated, systematic demand letters pursued mainly to generate reimbursement of legal costs or a contractual penalty, rather than out of a genuine interest in stopping the conduct, count as an abuse of right under § 8c UWG. In one widely cited ruling, the Landgericht München went further: someone who deliberately puts themselves in a position to manufacture a claim, by running a crawler rather than visiting a site as a real visitor would, isn’t deserving of legal protection for that claim.

Those doctrines exist now, ready to be pointed to, in a way they didn’t exist when the fonts wave started. It took roughly a year of the fonts pattern running before courts began ruling against serial abmahners for abuse. If an equivalent wave shows up for AI-content detection, the playbook to fight it already exists. That’s a real, structural difference from 2022, even if the underlying legal question (whether Article 50 counts as a Marktverhaltensregel at all) is still open.

None of that makes an unfounded claim pleasant to receive. It just means the ground to stand on, if you do receive one, is firmer than it looks at first read.

The actual fix is boring, and that’s the point

The instinct, when you hear “watermark detector,” is to think the fight is about proving your text isn’t AI-written. It isn’t. The exemption doesn’t ask you to disprove AI involvement. It asks you to show a person reviewed the content and holds responsibility for publishing it. Those are different claims, and the second one is much easier to document without changing how you actually work.

If your process already involves genuine back-and-forth, forming a position, pushing back on a draft, deciding what’s worth publishing, reading it before it goes live, you already meet the substance of the exemption. What’s usually missing isn’t the review. It’s the record of the review surviving past the moment you hit publish.

Two low-friction habits close most of that gap:

Keep the conversation, not just the result. If a piece comes out of an extended back-and-forth with an AI tool, save or export that conversation alongside the draft. It’s a timestamped record of exactly the kind of iterative reasoning the exemption is meant to protect, and it costs nothing extra to produce, since it already exists the moment the conversation happens.

Let your CMS keep its own history. WordPress, and most modern CMS platforms, timestamp every revision automatically if you draft inside the system rather than pasting in a finished block of text. That’s a structural, low-effort record showing a human touched the content over time, sitting in the same place as the published post.

Neither of these fixes anything already published without a trail behind it. For content that went out without documentation, there usually isn’t a clean way to retroactively manufacture proof, and pretending otherwise doesn’t hold up any better than having nothing. The honest position is: close the gap going forward, check what CMS history you already have for anything published recently, and accept that a handful of older, undocumented posts against a documented process started shortly after the obligation took effect is a defensible position, not a smoking gun.

The broader point

Watermarking text is a reasonable transparency measure in the abstract. But a technical marking scheme without published detection specifications, layered onto a legal exemption that’s still being defined by draft guidance, layered onto an unsettled question of private enforcement under German competition law, doesn’t produce clarity. It produces exactly the kind of ambiguity that automated, high-volume enforcement has exploited before.

The response to that isn’t to stop using AI as a thinking partner, or to over-engineer a compliance process nobody asked for. It’s to treat documentation as infrastructure, not paperwork: build it into how the work already happens, so that if anyone ever asks, the answer is already sitting there.

Further reading:

This article does not constitute legal advice. Several of the questions it raises, particularly around private enforcement of Article 50 under German competition law, are unresolved and untested in court. If this is relevant to your published work, a short consultation with a Wettbewerbsrecht lawyer is worth more than any generic guidance, including this article.