Why everything AIs write carries an invisible mark

If you asked an AI assistant to translate a contract, summarize a report or rewrite a letter for you since August 2, the text you received carries a mark. Not a stamp, not a line at the bottom of the page, not a hidden character that could be erased with a good text editor: an invisible mark, woven into the choice of words, and unreadable to you.

This isn't an idea from Anthropic or OpenAI. It's a European obligation that came into force on August 2, 2026, and it targets every AI provider that sells in Europe, even without the slightest office in Europe.

I'm going to tell you exactly what the law requires, how this mark is made, and above all what it proves and what it doesn't prove, because that's where everyone gets it wrong, including very serious people.

The law requires four things, and two concern you

Article 50 of the AI Act, the European regulation on artificial intelligence, sets out four obligations. An assistant that chats with you must tell you that you're talking to a machine, unless it's obvious. A system that recognizes emotions or classifies people must warn those it examines. Doctored content, those videos where someone is made to say anything even though they said nothing, must be identified as doctored. And a system that produces text, sound, images or video must insert a mark into it that can be read by a machine.

The last two apply to you, because they no longer target only the manufacturer but also the person who publishes. With an exception that saves the day, and it's important: if a human really rereads the content and takes responsibility for publishing it, the label is no longer mandatory. In other words, the law doesn't require you to say that an AI took part, it requires you to say when nobody checked.

For systems that were already online before August 2, there's a deadline: they have until December 2, 2026 to comply, and nothing is retroactive. Text generated before that date doesn't have to be labeled.

Timeline of the three dates in Article 50 of the AI Act, from August 2 to December 2, 2026

Three dates, and the one that directly concerns you is in the middle: on August 14, ten days after it came into force, Anthropic published its mechanism instead of keeping it to itself

The fines, to finish, go up to 15 million euros or 3% of worldwide revenue, and whichever is higher applies. That's why an American lab started marking its output on the very same day, and worldwide rather than only in Europe. When the bill is calculated as a percentage of revenue, you don't argue about the geographical scope, you use the version that works everywhere.

How you put an invisible mark in a sentence

Everyone imagines a watermark like an invisible character slipped between two words, or a line hidden in the file properties. That's not it at all, and it's crucial for what follows, because it completely changes what you can do with it.

The method used by Anthropic comes from work published by Google in 2024 in the journal Nature, and it has a name: SynthID-Text. The principle rests on a simple idea. When a model writes, it is constantly hesitating between several words that would do the job: important, crucial, capital, essential. With the mark, it's a secret key that decides between these candidates, word after word, without ever forcing it to use a word it wouldn't have considered on its own.

The vocabulary isn't split in two, the text remains the same text, but the sequence of small choices carries a signature that only the key makes it possible to recognize. A single word proves nothing, you need between 500 and 1,000 words for a detector that has the key to see the pattern take shape. And Anthropic explained everything on August 14, two weeks after it started marking things without saying so.

What the mark proves, and what it doesn't prove

Here, most articles get it wrong, so I'll say it slowly. The mark says that the text went through Claude. It doesn't say who wrote it.

You can write your cover letter yourself by hand over three evenings and ask Claude to correct the mistakes: it will come out marked. The law specifically exempts grammatical correction and standard editing functions, but Anthropic explains that it cannot distinguish an entire text passing through the machine from a comma, so it marks it in every case. It is the safest choice for it and the least useful one for you.

And there is no detector. Anthropic announced a free detection API, but it still isn't here: as of September 23, nobody outside Anthropic can read this mark. A teacher who had the key could say that a passage had passed through the machine. You, with your browser, can't verify anything at all. It is exactly this imbalance that makes people grit their teeth, and it is difficult to blame them.

A pile of handwritten papers on a teacher's desk, with a red pen and glasses

A teacher, a red pen and a pile of papers. Without the key, he reads nothing at all; with the key, he will read only that a passage has seen a machine, never who thought it up

Why some people call them spies

A post published on September 21 on the Brand.io website, and since picked up throughout the tech press, suggests another word besides watermark: spymark, the spy. The argument fits in one sentence. A watermark is visible, declared and inert, a mark that you see and ignore. A spy is invisible, survives re-encoding, and can be read only by people you did not choose.

The technical point behind the vocabulary is more interesting than the vocabulary itself. In an image, the photo version of SynthID stores a 64-bit identifier, which is enough to point to an entry in a database. The image does not only say that it was generated by a machine, it can say by which prompt, at what time and from which account. For text, Anthropic describes the same mechanism in another form: the key is with them, and with those they give it to. All that remains is to name the list, regulators, police, newsrooms, verification companies.

And the most troubling case does not even come from there. Microsoft encodes an identifier in the images produced by its Paint, including on Copilot+ machines where the computation is supposed to happen locally, and the technical sheet attached to the file, the one that normally describes everything the photo contains as hidden information, does not mention it. It was a researcher who found it by analyzing the program, not Microsoft, which wrote it into its documentation.

What does this concretely change for you

Three situations, and you've gone through at least one this week.

A phone held above a kitchen table to photograph a plate of pasta

A photo of a plate taken with your phone has never passed through an image generator. This detail will matter the day someone wants to sort the photos into two piles

Your kid's homework, first. Today, nothing changes, because nobody can read the mark, neither you nor their teacher. The tools that claim to flush out AI text are still what they were yesterday, guesses. The day a school has the key, it will be the opposite: the mark will say that a passage passed through the machine, and it will not say who thought it up. The student who has their mistakes corrected will end up in the same bag as the one who had their entire assignment written.

Your work next. If you write letters, reports or articles, you will increasingly often go through an assistant, even if only for proofreading, and these texts will come out marked. It changes nothing about their quality and nobody will hold it against you today. But the day a client, a publisher or a recruitment department decides to sort people based on this criterion, it will do so with a tool whose key you will not have.

And the deadline, to finish, you have to say it honestly: today, it changes nothing for you, and I can’t tell you when that will change. The detector will arrive in a few months, or not at all. That’s the whole limit of this story, we’ve imposed an obligation, and the tool that makes it verifiable doesn’t exist yet.

What erases the mark, and what keeps it

Anthropic has published the list of what damages its own mark, which is pretty honest of them. A short text doesn’t carry enough choices to hold. A very factual text, a shopping list or code, leaves too little freedom for the model for the signature to stick. Heavy paraphrasing, passing through another model or a complete rewrite makes it disappear. A screenshot of a marked text washes it away too, since it’s no longer text.

And there’s a detail that concerns every blog in the world, mine included: the metadata of an image, that information stored in the file and not in the image, evaporates at the first format change or the first re-encoding by a social network. That’s what makes text marking much more solid than everything we cobbled together before. There’s nothing to erase, there’s nothing to hide, there are only words chosen differently.

What remains is the figure nobody has published and that matters more than everything else: the frequency of errors. How many human texts will be wrongly marked, how many machine texts will slip through? Without that figure, we’re talking about a proof tool that has never been measured on this precise point. The day a school wants to condemn a student with it, that will be the first document they ask for.

My question, and I don’t have the answer, is what we do with proof that nobody can challenge because nobody can read it. And for this blog, everything is in order: a human rereads and signs every line, it’s written in black and white in the law. I just can’t prove it to you.

Join the conversation

You need an account to comment on this article. Creating one is free and takes under a minute.

  • The XMLTV file, free to download every day
  • Comment on articles and reply to other readers
  • Get an e-mail when an article you follow is updated

No comments yet.

Une erreur s'est produite. Cette application peut ne plus répondre jusqu'à ce qu'elle soit rechargée.Veuillez contacter l'auteur. Reload 🗙