The important change is not an AI detector
On 10 August, Anthropic published its implementation plan for the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content. Claude models launched in the EU on or after 2 August 2026 will support machine-readable marking at launch. Anthropic says the marks will apply wherever supported models are offered, worldwide, across Claude, Claude Platform, Claude Code, Claude Cowork, Claude Tag and cloud access through AWS, Google Cloud or Microsoft Foundry. Earlier models are still in transition.
Generated text will receive an imperceptible watermark at model level. Anthropic says it travels with copied text and may survive some editing. Supported files such as SVG, PNG and JPG will receive signed C2PA provenance metadata where the product surface supports it. Anthropic has not yet published the detector or detailed technical method, so buyers cannot independently test every claim today.
The operational consequence is already clear. A press officer can write a release, ask Claude to improve its grammar and receive copy that carries a Claude signal. A localisation team can translate human-authored product copy and return marked text. An agency can combine marked lines with original writing. The detector may see Claude processing, but it cannot reconstruct authorship, editorial control or truth from that signal alone.
A mark is a processing signal, not an authorship verdict
Anthropic states the limitation directly: a detected mark indicates that content may have been processed by Claude, but it is not conclusive proof of full provenance. Claude may have generated the first draft, translated a client draft, converted a file or only proofread it. The text may then have been edited, excerpted or mixed with other material. One binary result collapses several materially different production histories.
Absence is equally weak evidence. Anthropic says a mark may be unavailable because the model predates support, the passage is too short, the text was heavily edited or translated, material from several sources was mixed, file metadata was stripped, or a platform did not support that marking type. A clean detector result cannot certify human authorship. A positive result cannot certify that Claude originated the underlying ideas or claims.
This is why detection should never become an automatic rejection rule for recruitment, journalism, education, supplier evaluation or client approval. It is one machine-readable signal to investigate beside source files, edit history, named responsibility and the substance of the work. Research on watermarking and co-creation warns that turning model-origin signals into simple visible labels can misrepresent hybrid authorship and say nothing about whether content is true.

Do not confuse Anthropic's policy with every legal duty
Article 50 creates different obligations for providers and professional deployers. Provider-side marking under Article 50(2) concerns synthetic audio, image, video and text outputs in a machine-readable format, subject to technical feasibility and exceptions for standard editing assistance or functions that do not substantially alter input data or its semantics. Anthropic has chosen a broad model-level implementation that can also mark proofreading, translation and file conversion. That product behaviour is not proof that every marked sentence required an audience-facing AI label.
Professional deployer disclosure under Article 50(4) is another decision. It applies to deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest. The Commission's guidance provides a route for public-interest text that has undergone substantive human review or editorial control where a person or legal entity holds editorial responsibility. A spellcheck is not that substantive review, and a watermark detector cannot establish the review by itself.
For ordinary commercial copy, the team still needs to classify the final use, jurisdiction, subject and audience. A marked internal headline exploration, translated product description, investor statement, synthetic testimonial and public-interest explainer do not carry the same legal or reputational treatment. Counsel should settle difficult scope questions. Production should preserve enough evidence for counsel, the client and the publisher to make that decision against the actual final text.
Split the copy record into origin, processing and approval
Add three fields to every material copy handoff. Origin records who supplied the ideas, facts, claims and first substantive wording, with links to the client brief, interview, research, transcript or human draft. Processing records what Claude was asked to do, the product surface, model and date, and whether the task was generation, summarisation, translation, rewriting, formatting or review. Approval records who checked facts, claims, tone, rights and final use, plus the version they accepted.
Keep the input and output or a meaningful diff for high-risk copy. A raw chat transcript is often too noisy, while a final document with no trace is too thin. The useful middle ground is the source version, material instruction, model and surface, changed passages, reviewer comments, approved version and final file or CMS revision. Do not store confidential prompts in an uncontrolled project folder; follow the client's retention and access policy.
Give every status a precise meaning: draft, AI-processed, fact-checked, claims-approved, legal-reviewed, client-approved and published. 'Human reviewed' is too vague if one person corrected punctuation while everybody assumed somebody else checked the offer. A named approval state lets the watermark remain what it is, a provider signal, while the production record explains the human responsibility around it.

Change the agency-to-client delivery note
A supplier should stop describing an entire campaign as simply 'AI-generated' or 'not AI-generated'. Deliver a short content-processing note with the approved copy: source owner, Claude's task, model or product where known, material changes, human reviewers, factual and claims checks, final publication owner, disclosure decision and any supported mark or metadata test. Attach the note to the version being delivered, not to a generic agency policy.
Write the statement of work around notification and evidence. The supplier should disclose approved AI systems and material uses, obtain approval before changing a model for sensitive work, preserve source and review records, avoid using detector output as sole proof of authorship, cooperate with marking or disclosure checks, and correct delivery if the promised record is missing. The client should provide accurate source claims, name accountable reviewers and prevent an approved draft from being materially changed after sign-off without reopening review.
Do not strip a watermark or C2PA metadata merely to make a delivery appear human-made. Transformation can legitimately remove signals during CMS entry, transcoding, screenshotting or file conversion, but the production record should say what happened. Concealment creates a worse governance problem than the original mark. If a platform strips metadata, retain the validated master and the pre-publication test beside the live URL.
C2PA makes human oversight a structured production fact
Claude's signed file metadata follows C2PA, an open standard for cryptographically bound provenance claims. C2PA does not decide whether an asset is good, true or legally safe. It lets a verifier assess who signed a claim, whether it remains bound to the asset and whether the included assertions have been tampered with. That is useful evidence, not an automated creative or legal judgement.
Version 2.4 adds a machine-readable AI Disclosure assertion with model information and a human-oversight field. Its example states include fully autonomous, prompt guided and human validated. The vocabulary is still only as trustworthy as the process and signer behind it, but the direction matters: human review can become a named assertion tied to an asset instead of an informal sentence in an email.
For mixed campaigns, use one content ID across copy, images, video, audio and derivatives. Link the source, model processing, human approval and final placement. Validate Content Credentials on the supported master, then test the actual delivery paths. The C2PA specification is designed for whole-workflow applicability, but any CMS, design export, social platform or re-save can still break the chain in practice.

Run a ten-document handoff test
Choose ten real documents that represent the team's range: a human press release sent for proofreading, a translated product page, a generated social caption, a script summary, a claims-heavy advert, an executive post, a public-interest explainer, a supplier treatment, a short headline and a mixed human-AI draft. Use only approved, non-sensitive test material where a provider's forthcoming detector or file validator requires submission.
For each document, record the true origin and ask a reviewer who was not involved in production to reconstruct it from the handoff pack. Can they identify the source owner, Claude's task, material changes, factual evidence, reviewer, disclosure decision and approved version? When Anthropic releases detection access, compare the result with the known history. Count false assumptions, missing evidence, retrieval time and versions that cannot be connected to publication.
Pass the pilot when the team can explain each document without treating the watermark as a confession or its absence as a certificate. The new Claude marking policy is useful because it exposes a gap that already existed. Creative teams have been passing hybrid copy between people, models, documents and platforms without a shared account of who contributed what. The competitive response is not better camouflage. It is a copy workflow whose judgement survives the handoff.
Build
Make the copy handoff defensible
I help brands, agencies and production teams turn AI-assisted content into a controlled workflow with clear sources, review states, disclosure decisions and retrievable evidence.
Launching a business of your own? Founder Launch OS connects the brand, offer, website and visual campaign in one guided Codex or Claude Code workspace.



