For the past couple of weeks, AI watermarking has been the internet’s argument of choice. Anthropic announced that Claude would start watermarking the text it generates. Much of the reaction in response came from people worried they’d be “caught”: students, freelancers, anyone who’d rather their editor didn’t know a chatbot wrote the first draft, or ran a quick grammar check. If you run or advise a law firm, it’s likely that this isn’t your story. The useful questions are simpler, and they sit somewhere more practical: your work, and your tools.
Claude models launched from 2 August 2026 now weave an invisible watermark into the text they generate, a version of SynthID-Text, published by Google DeepMind in Nature. This is to meet the EU AI Act’s transparency rules, applied to Claude’s output worldwide rather than only inside the EU.
It works by nudging the model’s word choices so that, across a passage, a statistical pattern forms: invisible to a reader, detectable to anyone holding the key, and carrying nothing that identifies a user, a firm or a chat (files get a C2PA credential in their metadata instead).
What it reveals is deliberately limited.
A watermark signals only that Claude was “likely involved” at some point, not whether it wrote the text or merely tightened a lawyer’s draft. It strips out easily under editing, paraphrase or translation, and a missing watermark proves nothing, since plenty of AI text won’t carry one. Detection still catches the careless. In one experiment, a watermark hidden in academic papers flagged 506 reviewers who’d broken a no-AI rule, because, as computer scientist Nihar Shah put it, many people “may simply copy-paste AI outputs.” It was never built to catch the careful.
Whose problem this is, and where it bites
Here’s the part a lot of the coverage gets wrong. The duty to mark AI content falls on the model makers, Anthropic, Google and the rest, not on the firms using their tools. As the legal-tech commentator Richard Tromans put it in Artificial Lawyer, implementation is the makers’ job, not yours. Your own direct obligation under the EU AI Act is narrow: it bites on AI text published to inform the public on a matter of public interest, and not even then where a person has genuinely reviewed the work and holds responsibility for it. Routine client work isn’t that. And for a UK firm, the duties that actually bind you today come from the SRA and the ICO rather than any future AI statute. This is ground we cover in our guide to AI governance for law firms.
None of which stops the mark appearing on your outputs, since Claude applies it globally. For most work you aren’t breaking a rule. The sharper question is where a detectable trace might create an awkward conversation:
- Client or court expectations. Where disclosure of how a piece of work was produced would be expected, presenting AI-assisted output as entirely hand-drafted becomes harder to sustain once the text can be checked.
- Engagement terms. Some client contracts now restrict AI use outright, and a watermark is exactly the kind of thing that could surface such a term in a dispute or an audit.
- Artefacts carried forward. As Tromans notes, AI-generated wording from an old document, mark and all, can be pulled into a new contract, so its provenance travels further than anyone intended.
The question to put to your AI stack
This is the one most relevant to a head of IT, and almost nobody is asking it. Claude and the other frontier models sit underneath many of the legal AI platforms firms are now deploying. So, as the legal-tech site Non-Billable frames it, what happens to the outputs those platforms generate: do they carry a watermark, and is that your vendor’s answer to give or yours to ask for? It belongs on the evaluation checklist before the next tool goes live, which is where a question like this is cheapest to settle. It’s the approach we set out in choosing and deploying AI tools.
Keep this separate from confidentiality
One thing worth pulling apart, because it’s easy to confuse. The watermark carries no identifying information about your firm or your client, and nothing leaves a document that wasn’t already in it. This is a provenance signal, not a data leak. The real confidentiality questions, who controls your data, and what your contract with a provider actually permits, are serious, but they sit elsewhere, and we deal with them in client confidentiality and AI.
The mirror image of shadow AI
If this feels familiar, it should. We spent much of the last year helping firms work out how much unapproved AI use was happening inside the building. Our research with YouGov found 62% of UK firms already using AI in some form, with only one in three saying it had delivered what they expected, which is the visibility problem behind our piece on shadow AI. Watermarking turns the same lens outward: not what your team is using unnoticed, but how visible what you produce has become to a client or a court. Either way, the SRA’s expectation holds: a qualified person remains responsible for the work and has to be able to stand behind it.
Where this leaves you
There’s very little to do about the watermark itself. What’s worth settling consciously is the policy around it. When AI involvement gets disclosed to a client, which tools are sanctioned, and what your engagement letters now say, so that each fee earner isn’t reaching a different answer case by case. That’s the job of a short, usable AI policy, which is worth having in place before a client asks the question for you. If you’d rather start from a working document, our pre-deployment governance checklist is built for exactly that.
The watermark is a small operational fact. The conversation it forces, how your firm talks to clients about AI, is the part worth getting right.