Technology · Digital regulation
EU watermarking rules force AI giants to label synthetic content
From 2 August, providers of the most advanced generative models must mark output so users know they are dealing with AI. Anthropic and OpenAI have already adjusted their systems.
The European Union has effectively ended the era of unlabelled synthetic content. Since 2 August, the transparency obligations of the Artificial Intelligence Act require providers of the most capable generative models to ensure their output carries a machine-readable watermark and that users are informed they are interacting with AI. The rule applies regardless of where the model is developed; if it serves the European market, it complies.
Brussels sets the global baseline again
The mechanism is familiar. The EU passes a regulation with extraterritorial reach, and the world's largest technology companies adjust their global products rather than maintain separate European versions. The General Data Protection Regulation established the pattern. The Digital Services Act reinforced it. Now the AI Act is compelling Anthropic, OpenAI and others to embed provenance signals into every image, audio clip and text passage their models produce.
"I don't think that people understand the scale of change," said Ashley Casovan, managing director of the AI governance centre at the International Association of Privacy Professionals. She described a shift from a world where users had to make an educated guess about whether something was machine-made to one where such content carries a verified symbol or overlay. The change is not optional. The Act designates these transparency rules as applying to providers of general-purpose AI models with systemic risk, a category that captures the current frontier systems.
Anthropic and OpenAI move first
On 11 August, Anthropic announced that all Claude models released since the compliance date would add embedded watermarks in text. The watermark, the company said, is woven into the token stream itself. "You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response," the company wrote in its blog post. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere." The approach differs from image watermarking, where an invisible pixel pattern survives compression and cropping. In text, the statistical signature must survive paraphrasing, translation and partial quotation.
OpenAI moved earlier. At the end of July the company pledged that "people should have better context about the content they see online, including whether it was created or edited by AI." It relies on SynthID, a watermarking tool developed by Google's DeepMind unit, to give AI-generated images an invisible overlay. That capability was extended to audio in the same announcement. Both companies have also signed up to the Coalition for Content Provenance and Authenticity (C2PA) standard, an industry initiative designed to store and transfer provenance metadata across platforms.
The detection gap
Watermarking is only the first half of the equation. The second, and commercially more consequential, is detection. Walter Pasquarelli, a researcher in synthetic content at the University of Cambridge and adviser to the OECD, explained the practical chain: a user generates text on Claude, pastes it into a social media composer, and the platform's interface detects the watermark before the post is published. The platform then decides how to visualise that signal, whether with a label, a badge or a reduced distribution ranking.
That decision is where the economics shift. "There's plenty of evidence, when it comes to media, that as soon people know that something is AI-generated their engagement drops quite significantly," Pasquarelli said. He added, in current digital parlance, that the EU's move could reduce "AI slop", the flood of low-effort synthetic posts that clog feeds and search results. LinkedIn has already added an option for users to flag a post that "seems like AI slop," a signal that platforms are preparing for a labelled environment.
From deception to disclosure
The policy framing has moved noticeably. The AI Act's recitals speak of preventing AI-generated content from being deceptive. The implementation is broader: all output from designated models must be marked, regardless of intent. "The conversation has shifted from AI-generated content which has a deceptive intent to AI-generated content as a whole," Pasquarelli quipped. That expansion suits platforms struggling with volume moderation. A universal label is easier to enforce than a contextual judgment about deception.
Francesca Pole, a data, privacy and cybersecurity lawyer at DLA Piper, confirmed that transparency obligations are "the main focus at the moment, in terms of what everyone is talking about." The reason is practical. The Act's other requirements, risk management, data governance, human oversight, are operational. Transparency is visible. It changes the user interface. It creates a compliance artefact that regulators can audit.
Technical limits and adversarial pressure
Watermarking text at the token level faces a harder adversarial environment than images. An image watermark survives because pixel statistics are redundant. Text watermarking relies on biasing the model's probability distribution toward a detectable pattern. That pattern can be weakened by paraphrasing tools, translation chains or deliberate attacks that rewrite the output while preserving meaning. Anthropic's claim that the watermark "travels with the text when it's copied and pasted" holds only until the text is transformed.
The C2PA metadata approach offers a complementary layer. By binding a cryptographic manifest to the content at creation, it creates a chain of custody. But metadata is easily stripped. Screenshots, copy-paste into plain text fields, and platform re-encoding all break the chain. The EU's requirement that providers "ensure" users know they are interacting with AI implies an obligation that survives these transformations, a standard no current technology fully meets.
Commercial consequences
The engagement drop Pasquarelli cited is not speculative. Internal research at multiple platforms has shown that explicit AI labels reduce click-through rates, time-on-content and sharing. For companies whose business model depends on attention, that creates a tension. They must comply with the Act, but they also have an incentive to make labels subtle, to place them where eyes do not linger, or to design detection thresholds that miss borderline cases.
The Act anticipates this. Article 50 requires that the marking be "effective, interoperable, robust and reliable." The European Commission will adopt delegated acts specifying technical standards. Until those are published, companies have latitude in implementation. Anthropic's token-level approach and OpenAI's reliance on SynthID represent two different bets on what the eventual standard will demand.
Sources
People mentioned
Ashley Casovan
Francesca Pole
Organisations
European Commission · Anthropic · OpenAI · Google DeepMind · C2PA · LinkedIn