Analysis
What's new: Pulse covered Anthropic's rollout of invisible, machine-readable watermarks across new Claude output starting August 2, in response to EU AI Act transparency requirements. Ars Technica's follow-up reporting adds a sharper detail: the watermark's invisibility isn't incidental, it's the design goal, and that same property is what makes independent verification of its robustness difficult right now.
The 'For Now' Framing
Ars Technica's reporting frames the current invisibility as a temporary state rather than a permanent guarantee -- Anthropic has kept detection tooling limited, meaning outside researchers can't easily test how well the watermark survives adversarial attempts to strip it, such as running Claude output through a second AI system specifically designed to remove statistical watermark signals. That's a different concern than the one Pulse's original coverage raised, which focused on ordinary editing diluting the mark; this is about whether a motivated bad actor could defeat it deliberately once the underlying mechanism becomes better understood.
Why the Distinction Matters
A watermark that survives casual editing but not targeted adversarial removal is still useful for its stated compliance purpose -- flagging AI-generated content in good-faith contexts like academic submissions or content-moderation triage -- but it does very little against someone specifically trying to launder AI-generated text as human-written. Anthropic hasn't published adversarial-robustness benchmarks publicly, which means the watermark's real-world reliability against determined removal remains an open, untested question rather than a documented limitation.
The Counterweight
Keeping detection tooling restricted is also a reasonable security posture -- publishing exactly how to detect the watermark would make it easier for researchers to build effective removal tools, a tradeoff between transparency and robustness that most anti-fraud and anti-abuse systems face. Whether Anthropic eventually publishes controlled robustness data to outside researchers, the way some cybersecurity vendors run responsible-disclosure programs, will determine whether "invisible for now" resolves into a documented, tested system or stays an open question indefinitely.