Anthropic is not “complying with the EU AI Act.” It is building a private detector for institutions and calling it transparency.

On September 9, Anthropic starts embedding a statistical watermark in Claude Opus 5. The company says the mark is an “imperceptible pattern in word choice.” No extra characters. No change to pricing. No user data in the signal. No action required. Then it tells customers this is required by EU law.
That last sentence is the problem.
Article 50(2) of the EU AI Act requires providers to mark synthetic text, audio, image, and video in a machine-readable format and make it detectable as AI-generated. Recital language lists options: watermarks, metadata, cryptographic provenance, fingerprints, logging, or combinations. The law does not require an invisible, keyed, token-level signal. It does not require a detector locked behind an API. It does not require the mark to travel through copy-paste and survive light edits. Those are design choices.
The Commission’s own Code of Practice on Transparency of AI-generated Content is voluntary. The legal duty is marking plus detectability. Metadata plus a public, user-facing detector would satisfy the statute. A C2PA-style provenance tag on files already exists. Anthropic is using that for files. For text, it chose something else: bias the model’s next-token choices with a secret key, then let only approved parties test whether the sequence matches that key.
Read what that architecture actually does.
You cannot see the mark.
You cannot verify it.
You cannot run the test yourself.
Anthropic holds the key. Detection is in private preview for regulators, law enforcement, media, fact-checkers, and “eligible organizations” as defined under EU law. Anthropic says it will expand access over time. Until then, the public is not the audience. Institutions are.
That is not consumer transparency. That is a one-way glass.
True transparency would tell the reader what they are looking at. A visible label. A metadata flag any tool can parse. An open detector anyone can run. Article 50(4) already requires deployers to disclose deepfakes and certain public-interest AI text to people. Article 50(5) says information must be clear, distinguishable, and accessible at first exposure. A secret statistical pattern that only a vendor API can score does the opposite. It makes your copy legible to the state and the platform. It does not make the system legible to you.
Three more facts that should bother anyone who actually uses these tools for work:
1. The mark is applied at the model layer, worldwide. Not just in the EU. API, Claude.ai, Claude Code, Cowork, AWS, Google Cloud, Microsoft Foundry. A Brussels compliance story becomes a global content-control layer.
2. It changes which words the model picks. Anthropic says meaning and quality are unaffected. The published evidence for “harmless” statistical watermarks is mostly third-party work on other models, scored by preference ratings. That is not a privacy impact assessment. It is a marketing claim. If the sampling process is now keyed, the output is no longer a clean sample of the model. It is a sample of the model plus a secret. Users have no way to inspect the difference.
3. The detector is not yours. Even if the watermark contains “no information about the user, their organization, or their conversations,” the capability sits with the vendor and approved institutions. Today it answers “was this likely Claude?” Tomorrow the same pattern: secret key, restricted API, statistical score — is how you audit students, contractors, journalists, political speech, and commercial copy. Once the pipe exists, the use cases expand. That is how surveillance infrastructure is built: first as compliance, then as policy, then as default.
Article 50 even carves out assistive editing that does not substantially change meaning. Grammar, light polish, translation-as-assist. Anthropic’s own help text describes a broad, model-level mark that travels with pasted text and may survive some edits. Over-marking is not required by the Act. It is convenient for the company that owns the detector.
Consumers do not owe platforms a forensic trail of every sentence they ship. Workers do not owe governments a probability score on a draft. If the goal is “people should know when they are reading AI,” put the label where people can see it. If the goal is “regulators and vendors should be able to score speech they do not own,” say that out loud.
Call this what it is: transparency for institutions, opacity for users.
Demand public detectors. Demand open keys or third-party verifiable schemes. Demand that “compliance” not become a private surveillance API wrapped in a privacy FAQ. The next decade of AI governance will be decided by whether marks serve readers or serve the people who already have the keys.
I help food and beverage brands build real organic communities through strategy, content, and brand storytelling. If your content feels busy but ineffective, that is the problem I fix. Follow me @gallucciNET on social media.
adage, emmy, telly & webby award-winning digital marketing consultant for purpose-driven food & beverage brands.




