A consultant finishes a client report at eleven at night. They have built the argument. They have run the numbers. They have written every line. Then they paste it into an AI assistant to correct tense errors and rewrite one messy section. Three weeks later, the client runs the file through an AI checking tool, which flags part of it as AI generated.
Nobody lied. Somebody still has to explain it in a meeting.
That meeting is going to happen more often. Several major AI providers are adding machine readable marks to supported outputs, and text watermarks can travel with copied wording. Most teams I speak to don’t know this has happened. They have no rule for it and no answer ready for the day a client asks.
One distinction matters. A provider watermark detector reads a keyed signal in the output. A conventional AI detector makes a probabilistic guess from writing patterns. A Content Credentials verification tool reads signed provenance metadata. These are three different kinds of evidence.
Marking Became The Default And Almost Nobody Noticed
According to Anthropic’s marking guidance, Claude models launched in the EU on or after 2 August 2026 support marking at launch. Supported text carries an embedded watermark, while supported file types may receive signed C2PA provenance metadata. Anthropic says marking applies worldwide wherever supported models are offered, although some platforms and features may not support every marking type.
The EU accelerated the change. Article 50’s transparency obligations became applicable on 2 August 2026, while the AI Act itself entered into force on 1 August 2024. European Commission guidance says providers must add machine readable marks to synthetic text, images, audio and video, subject to technical limits and exceptions including standard editing that does not substantially alter the input or its meaning. About 190 companies and organisations had signed the voluntary code by the end of July.
Google started earlier. SynthID creates a detectable text watermark by adjusting token probability scores during generation, while the words still read naturally. Google DeepMind uses related watermarking methods for images, audio and video.
So the trace is there. What it proves is a much smaller thing.
A Mark Means Processed, Not Written
This is where I think most firms have it wrong. A mark can show that a model was involved, but not how much it contributed. Translation or substantial rewriting may carry a detectable watermark because the model chooses most of the words. Light proofreading may leave too little signal to register. The mark indicates involvement, not authorship.
A missing mark proves even less. Heavy edits can weaken a text watermark, short passages may carry too little signal, and screenshots or format conversion can strip file metadata. Outputs from older or unsupported models may carry no detectable mark. For now, Anthropic says it is working to add marking support to older models as well.
So this is a management problem, not a tech one. Any rule that treats a checking tool’s score as proof will fall apart the first time somebody argues back.
The part I’d think about tonight is the work created after marking was introduced. It may be checked later when provider tools become available. Older work can still be run through conventional AI detectors, but those scores are not watermark evidence and should not be treated as proof. You do not pick when the question lands.
What Organisations Are Actually Doing
The first move is separating watermark verification from conventional AI detection. Universities got there years ahead of business. Vanderbilt disabled Turnitin’s detector after noting its supplier’s claimed 1% false positive rate. Based on the 75,000 papers submitted in 2022, the university estimated that about 750 could have been incorrectly labelled if the tool had been used. Where detection survives, it should start a conversation rather than end one.
The second move is writing AI use into the paperwork so nobody has to guess. A revised June 2026 proposal from the US General Services Administration would require covered contractors to disclose the LLMs and supply chain entities used when processing Government Data, and to extend role specific safeguards to relevant subcontractors and service providers. The proposal includes exceptions for common commercial products and incidental use. I’m seeing the same approach arrive in engagement letters, because a named human reviewer is easier to defend than a detector score.
The third move is building provenance into the file when it is made, instead of arguing about it later. The Content Authenticity Initiative reported more than 6,000 members in January 2026. Devices such as the Google Pixel 10 and Sony PXW-Z300 can create Content Credentials at capture, while compatible workflows can preserve or update them through editing. That is stronger evidence of origin and change history than a generic detector, although it does not prove that the underlying content is true.
None of this removes the awkward part. Across 13 experiments, Oliver Schilke and Martin Reimann found that people who disclosed AI use were trusted less than those who did not. The penalty persisted when AI was described as a proofreading aid and when participants were told disclosure was mandatory. Third party exposure produced a larger trust penalty than self disclosure. That’s why the firms handling this well are choosing the smaller loss on purpose.
Stop asking only how the work was written. Ask who remained accountable, what the system contributed and how the output was checked. A mark cannot answer those questions.
