A Process, Not a Creator
AI output becomes an asset when it carries quality, origin, and ownership. A watermark delivers none of the three.
A billion dollars of silicon, the best model in the world loaded and running, and no prompt, produces exactly one thing: heat. The prompt is the act. Everything downstream is process.
On August 2, 2026, Anthropic began weaving an invisible statistical watermark into everything Claude writes — worldwide, on every surface, with no opt-out and no published mechanism. It is a mark applied by the toolmaker, to the customer's workpiece, asserting the toolmaker's participation.
The objection is not that marking is wrong. The objection is that the mark records the only party in the transaction that had no intent, and records nothing about the party that did. Anthropic is a process. It is not the creator.
What follows is what the mark should have said instead. It is not a proposal. The architecture has been filed, allowed, and running — the patent covering it was filed September 27, 2024 and allowed June 3, 2026, two months before the watermark shipped.
What shipped
Claude models launched on or after August 2, 2026 embed a statistical watermark in generated text. The construction described in reporting is the standard one: bias token selection among near-equivalent candidates against a secret key, so that a long enough passage carries a detectable signature.
It applies across the API, claude.ai, Claude Code, Cowork, and Tag, and through AWS, Google Cloud, and Microsoft Foundry. Anthropic's documentation describes no opt-out at any tier. The mechanism is unpublished — no bias strength, no key policy, no quality evaluation. Detection tooling is "forthcoming," and the key stays with the vendor. The driver is Article 50(2) of the EU AI Act.
Anthropic's own stated claim is that a hit means content "may have been processed by Claude." It fires on proofreading. It fires on translation. Absence proves nothing.
Supported image files get something categorically better: a signed C2PA manifest — detached, cryptographic, publicly verifiable. That choice is the tell. Where there was a container to put a signature in, Anthropic used a signature. Watermarking is what happened where they had nowhere to put one.
The disclosure obligation is legitimate. The implementation inverts who is accountable.
Data has no origin. Assets have origin and ownership.
This is the distinction the entire debate is missing, and it is not a semantic one. You cannot give data provenance by labelling it, because data is not the kind of thing that has a maker, a lot, or a holder. An asset is. Origin and ownership are precisely what convert a stream of bytes into an asset that carries title.
So the question is not "how do we tag AI text." It is: what has to be true for AI output to be a manufactured asset rather than an anonymous artifact? Three things, and they are three different jobs done three different ways.
- Quality is measured to a depth. Not a boolean — a stated level, honestly given, that says how far the measurement actually reached. This is the "Measured" in Measured AI.
- Origin is measured. How was this made? Which plant, which code, which raw materials. This is the supply side.
- Ownership is signed. Whose is it? The customer signs their intent, and the output is bound back to it. This is the demand side, and it is where property rights live.
Origin plus ownership is title. Quality is the grade on the title. Now score the watermark against all three — next to a thirty-cent bolt.
| Attribute | Grade 8 bolt | Watermarked AI output |
|---|---|---|
| Quality — depth | 150 ksi tensile, verifiable by test | no property claimed, no level |
| Origin — maker | Registered insignia, public register | "may have been processed by" |
| Origin — materials | Heat number, lot, mill test report | no weights, no config, no plant |
| Ownership | Chain of title from purchase order | no prompt, no customer, no terms |
| Who can read it | Anyone, with eyes | the vendor, on request |
| Method published | SAE J429, ISO 898-1, ASTM F3125 | undisclosed |
| Liability for a false mark | Federal offense, 15 U.S.C. ch. 80 | disclaimed by the applier |
We know more about a thirty-cent bolt than we know about a watermarked AI output.
That is not a flourish. It is true line by line, and the fastener world settled every one of those rows decades ago. When counterfeit Grade 8 stock was flowing into defense and aerospace in the 1980s — marks being faked at industrial scale, the exact shape of today's problem — a covert mark in the steel was available and was not what got built. What got built was the Fastener Quality Act of 1990, amended in 1999 specifically "to strengthen the protection against the sale of mismarked, misrepresented, and counterfeit fasteners": registered maker identity recorded publicly, mandatory lot traceability, accredited independent testing, a certificate that travels with the lot, and criminal liability for lying.
Note what the maker's insignia is, institutionally. The manufacturer chooses its own mark and records it in a public register. Nobody issues it. That is a declared identity, not a granted one — the same structure we use for a corporate identity key, and the reason a model owner should never have to subordinate itself to a super-CA to be identifiable.
Quality: depth, never a boolean
The trusted-computing industry made a branding error twenty-five years ago that the AI industry is now repeating. The TPM never trusted anything. It measured, and it signed. Trust was always a policy decision made on top of the evidence by whoever was relying on it.
Measured compute, not trusted computing. We measure what is measurable at the moment of inference and sign that measurement. We do not ask anyone to trust; we hand over evidence and a signature, and the relying party decides. And because it is a measurement, its strength is a depth, stated as a level:
A Grade 2 bolt is not a fake bolt. It is honestly weak, marked as such, and correct for a job that does not need more. A weak claim is not a fake claim — and an understated claim is a false claim. The watermark cannot say any of this. It is a boolean with no ladder underneath it, which is the one shape a quality system must never take.
Origin: the five-part manufacturing record
NVIDIA calls the modern data center an AI factory that manufactures intelligence. Take the metaphor seriously and the provenance of an inference is a manufacturing certificate. The whitespace is not any single part — it is having all five bound in one signed object.
- Known plant — the iron is genuine. Authentic CPU, GPU, and fabric in confidential mode, against issued hardware roots of trust.
- Known plant — the code is known. The inference stack is measured and maps to an auditable build.
- Raw materials — the model is known. The exact weights, bound to a declared corporate identity and anchored.
- Work order — the intent is signed. The prompt, the context, and the asserted terms, signed by the customer's own key.
- Title — the output is bound. One signed receipt ties plant, materials, work order, and output together: non-repudiable authenticity and transferable ownership.
Parts one through three are the supply side. Every serious competitor holds fragments of them. Part four is the one nobody signs — which is why nobody can issue part five.
Ownership: the demand side is the whole argument
The entire field signs the supply side and ignores the demand side. Everyone is racing to prove that a genuine provider ran the right model honestly — the foundry attesting its own authenticity. Nobody signs the prompt.
TSMC proving it is a genuine fab running a certified process tells you precisely nothing about who owns the wafers. Title comes from the customer who supplied the design, commissioned the run, and therefore owns the chips — even though TSMC owns the fab. Provenance of the machine is not title to the goods.
Complete provenance is bilateral. The supply side says what manufactured it. The demand side — a customer intent manifest signed by the customer's own key, carrying the prompt hash, the context hashes, the asserted terms, and a timestamp — says who ordered it, from what design, under what terms. Fuse both inside the same signed output receipt and you have title to manufactured knowledge: this party submitted this exact signed intent to this measured model and got this exact output.
Seen against that, the watermark is not a weak attestation. It is a brand tag on a fragment of the supply side, and it is silent on the entire half where ownership lives.
Precedent — already mandated in payments
Under PSD2's regulatory technical standards, an authentication code must be specific to the exact amount and payee the payer agreed to, and any change to either invalidates the code. That is not "prove who the user is." It is bind the user's authenticated intent to this specific transaction — and Europe made it compulsory at billions-of-devices scale.
Substitute prompt for amount and output for payee and it is the demand side exactly. The regulator that just mandated a watermark for AI already mandated the right mechanism for money. The pattern is proven; only the domain is new.
Verifiability is not truth
A standard is worth nothing if its authors will not apply it to themselves, so here is ours applied to us.
On August 13, 2026 we found that 74.1% of the entries in one of our own signed change histories recorded our processing rather than events in the world. Every signature was valid. Every hash matched. The anchor held. And the referent was wrong — a true statement about two stored values and a false statement about the world. Both defects had been introduced by improving the pipeline, and nothing warned us, because every guard we build assumes errors look like errors.
Signing makes a claim non-repudiable. It does not make it about anything. That is the hardest lesson in this field and the one most likely to be skipped by everyone now rushing to attach provenance metadata to things.
A confident wrong answer is strictly worse than a gap, because a gap is visible.
Which is the real indictment of covert marking. It is engineered to be invisible, unfalsifiable from outside, and unaccompanied by any evaluation the public can check. It manufactures confidence without manufacturing a way to catch itself being wrong — and it will be treated as evidence in proceedings that have no discovery, where the accused cannot verify or rebut it because the key belongs to the accuser's supplier.
The chain runs through the model, not around it
Steel already works this way end to end. Nobody trusts a central authority; each party warrants the one thing it actually knew, and the certificates chain: heat number → mill cert → lot → distributor → assembly → maintenance record.
The data version is the same shape. A farm creates its own identity and signs the animal record. The processor signs the lot. The carrier signs the bill of lading against that lot. The storefront signs the listing against that bill. Then an agent answers a question about that beef, and its answer carries a record that references the records it consumed — and becomes an input to the next agent, which references it in turn.
A statistical mark on a blob cannot do this. It has no field for its inputs. That single difference separates a warning label from a supply chain. And the economics run the same direction: a watermark can be stripped for pennies, because anything a public detector will score is something an optimizer will defeat. Nobody can strip accumulated signed history, because nobody can back-fill it.
Why now: the button nobody clicked
None of this is new technology. Public-key signatures are thirty years old and they have always worked. They failed to take hold for one reason, and it was never cryptographic. As I wrote on the Fourth of July: "A signature is only worth something if someone verifies it, and people do not."
Print used to carry provenance for free — "when you held a document you held something with a provenance you could reason about: who made it, where it came from." Digitisation severed that, because copying became free and identical: "a real vote count and an invented one look identical on a screen." Signing was the obvious repair, and it sat unused for three decades.
Notice that steel never had this problem. A bolt kept its chain of custody because you cannot costlessly copy a bolt; the mark, the lot, and the certificate stayed attached to a physical thing. Text lost its provenance the moment duplication became free. The fastener industry never had to solve what we are solving, because physics solved it for them.
What changed is the reader. "An AI will do the one thing humans never would. It will verify at machine speed." For the first time there is a consumer of information that will actually check every signature, on every document, without getting bored. The demand side of verification finally exists — and it is not human.
Anthropic shipped a mark designed for the button nobody clicked. The reader that clicks every button is already here.
That is the design error stated precisely. An invisible mark, adjudicated by the vendor on request, is built for a world where verification is a favour you ask for. A detached public-key record is built for a world where verification is automatic, free, offline, and performed by a machine that never tires of it. One of those worlds arrived in the last three years.
It also explains why the watermark cannot touch the failure everyone actually cares about. "AI hallucinates because it was raised on an ocean of origin-less text in which a true statement and a fluent, confident, entirely fabricated one are indistinguishable." Hallucination is an input pathology. A watermark marks the output and says nothing whatsoever about what went into it. It cannot reduce hallucination by any amount. It can only annotate it.
This empowers AI. It does not leash it.
Every autonomous system today collapses back into an advisory system, because it cannot verify its inputs and liability has nowhere to land. So it hedges, recommends, and asks a human to confirm. The ceiling on agentic AI is not intelligence. It is that acting on unverifiable input is indefensible, so nobody lets the agent act. Signed inputs move liability to the party that actually knew.
Verification is what converts an assistant into an actor.
The second benefit accrues to the model makers themselves, and they should want it more than we do. A watermark can never clear a model of anything — a compromised, proxied, or poisoned model stamps output identically to a pristine one. The mark cannot distinguish operating as intended from operating as attacked. An attestation can. It is the only mechanism that can say a model ran as designed, on known weights, on a known machine.
There is also a structural reason no single lab can solve this. A lab can attest its own output. Only a third party can attest across labs — and every enterprise runs several.
Stop detecting AI. Start crediting it.
Detection is a contamination posture. It treats AI output as a pollutant to be found in clean water, and it spends the entire engineering budget losing an arms race against a verifier the defender published.
The opposite posture wins on every axis. AI output that arrives with a complete manufacturing record — a stated quality level, a measured origin, and a signed owner — is more trustworthy than the anonymous artifact beside it, not less. Make AI output the highest-provenance content on the internet: the only content that can state what it was made from, how deeply that was measured, and who stands behind it.
None of that requires touching the output. The record sits beside the artifact, publicly verifiable, offline, forever. The bytes stay exactly as the model produced them.
The future is not built on the brand of the tools. It is built by people, using tools good enough to state their own condition. Mark the plant. Grade the run. Sign the work order. Bind the output.
Anthropic is a process. It is not the creator.
Measured against itself
A paper arguing for measurement should be measured. This one was assembled with Claude, and it will carry Claude's watermark. Here is what that mark covers and what it leaves out.
| The process | The creator | |
|---|---|---|
| Elapsed | 38 minutes | 257 of 348 days with commits |
| Turns / messages | 93 assistant turns | 411,637 archived messages |
| Sessions | 1 | 457 |
| Output produced | 184,772 tokens | 1,567 commits across 42 repositories |
| Durable record | one transcript | 2,544 archives · 35 anchored on-chain |
| Priority | August 15, 2026 | patent filed September 27, 2024 |
Both columns are floors, not totals. The left one is exact — it comes straight out of the session transcript. The right one is what the archive interface reports across two machines; the underlying corpus is larger, and the commit figures cover only the repositories cloned locally. Where a number is uncertain we have taken the smaller one, which is the correct direction to err when the number is your own.
Every load-bearing claim above was written down before the session that assembled this page opened. The manufacturing record and the demand-side argument: June 25, 2026. The measurement principles: July 7, 2026. The patent covering the architecture: filed September 27, 2024, twenty-two months before the watermark shipped.
The session itself is a worked example of the thing being proposed. Seven signed instructions, timestamped, three of them corrections that changed the argument — that bolts are stamped and the stamp is the model; that quality belongs beside origin and ownership; that the corpus outranks the conversation. That is a work order, and it is on the record.
The mark covers the 38 minutes. It is silent on the 257 days.
Grading our own claim
Consistency requires applying the ladder to this evidence too. The authorship record is not uniformly deep. Of 2,544 local archives, 35 are anchored on-chain — about 1.4%. The rest are durable local records with hashes, not backdate-proof anchors. Extraction and topic labels are machine-generated and imperfect.
So the honest claim is: a large, dated, independently inspectable body of work, anchored in part. Not "proven." That is an L1-to-L2 claim about authorship, stated as a level. It is far more than a watermark establishes, and saying exactly how much more is the entire point. An understated claim is a false claim; so is an overstated one.
Which is the difference that matters. Both marks are imperfect. Only one of them tells you how imperfect, in what dimension, and how to check.
— Steven Sprague, CEO, Rootz Corp.
Sign a prompt, own the answer, and flip one bit to watch tamper detection fire at proof.rootz.global. Measurement depth is stated on the page rather than implied.
From the Printing Press to the Prove-It Button → · The AI Factory Needs a Quality System → · Talk to us →