The duty sits with the provider, the mark sits on the work
The rules that came into force this month require model providers to label the audio, image, video or text they generate so that a machine can detect it, with fines reaching 3 per cent of annual turnover. Anthropic told WIRED it is marking Claude's output, including output from Claude Code, in order to comply, and plans a detection interface so users can check text themselves. What that describes is a duty defined between a regulator and a company: the fine has an addressee, a percentage and a balance sheet behind it.[1]
The detectable object, though, does not stay inside that relationship. It is embedded in the sentences a person hands to an employer, a client or a journal, and Anthropic itself accepts that the method yields a probability rather than a verdict. Guillaume Meyer, whose removal code has drawn more than 100 contributors on GitHub, names the exposure precisely: a false mark costs the candidate whose application is rejected or the researcher accused of undeclared AI use, while the provider that met its labelling obligation carries nothing. The opposite reading is available and worth stating: the same visibility could protect writers by making undisclosed use demonstrable rather than merely alleged, and Meyer says he is not against content attribution.[1]
What are the removal tools answering?
Meyer's code has a model that does not watermark rewrite the text, swapping synonyms and reorganising content. Erik Hughes spent 15 minutes building a tool that strips invisible and look-alike characters, reorders sentences within a paragraph and substitutes some words. Leon Chlon, a visiting fellow at the University of Oxford, condenses the text, translates it into a language with distant semantics such as Arabic, and translates it back. Anthropic had already accepted that heavily edited, paraphrased or translated content may not carry the mark.[1]
Read as a labour question, that list describes who has to spend the time. Each method is unpaid effort added on top of work someone was already being paid to produce, and it comes cheapest to whoever can run a second model. Freelance content writers and social media creators have been contacting Meyer for help using the code; the group with the least room to argue with a client about a probability score is the group taking on the extra step.[1]
This column asked earlier who controls the data that shows what a worker did during the day. The watermark answers a narrower version of the same question with unusual clarity: the provider Anthropic generates the mark, whoever holds the detector reads it, and the person who wrote with it carries it. Anthropic says a detection interface is coming; until it ships, nobody outside the company can test whether these removal methods work.[1], [2]
What would settle this?
A measurable test exists. Anthropic says it will ship a text-detection interface; when it does, the same question becomes answerable in numbers. If the interface is published by 31 October 2026 and reports a false-mark rate on human-written text together with its confidence bands, the burden Meyer describes can be priced. If it ships without either figure, the probability stays a private number that an employer or an editor can read as a verdict, and the removal tools keep being the cheap answer for the person whose name is on the work.[1]