On 2 August 2026, text written by one of the large AI models started carrying an invisible mark. Not a disclaimer, not a symbol. A statistical fingerprint woven into the words themselves.
If anyone has written, edited or proofread copy for your website using AI in the last fortnight, some of that text is marked. You cannot see it. Neither can your customers.
The coverage that followed has been loud and, in two important places, wrong. This article sets out what actually happened. It covers what a detected mark can and cannot tell anyone, and which parts of it reach an Australian business at all.
This is general information, not legal advice. Where a rule affects your business, read the source and take your own advice.
Key takeaways
- A detected mark means the text was processed by AI. It does not mean AI wrote it, and it does not name an author.
- Two claims doing the rounds are wrong: the mark is not hidden characters, and there is no duty to go back and label old content.
- Google has not made these marks a ranking signal, and its published position on AI-written content has not changed.
- The EU rule that does exist lands on publishers only for text informing the public on matters of public interest.
- Substantive human review by a named person removes that duty. It is a process, not a disclaimer.
What changed on 2 August
Anthropic, the company behind Claude, now marks what its models produce. Claude models launched on or after 2 August 2026 support marking from launch, and older models are being brought across (Anthropic, retrieved 2026-08-11).
Two different mechanisms are in play, and mixing them up is where most of the confusion starts.
A text watermark is a statistical pattern in which words the model picked. It is not a symbol, a tag, or a character you could search for. C2PA is a separate open standard for recording where a file came from, signed so that tampering shows up. Text gets the first. Supported image files, meaning .svg, .png and .jpg, get the second.
The scope is wider than most headlines suggested. Marking applies wherever the product is offered, worldwide, not only in Europe. It covers the API, the chat apps, the developer tools and the versions running on Amazon, Google and Microsoft cloud platforms. No opt-out is listed anywhere in the documentation, on any paid tier.
The reason is European. Article 50 of the EU AI Act requires providers of generative systems to mark their outputs in a machine-readable format (EU Artificial Intelligence Act, retrieved 2026-08-11). Anthropic chose to apply it everywhere rather than build two versions.
What a detected mark proves
Set aside the headlines and read what the vendor says the mark means. It is narrower than almost every write-up implies.
- It says the text was processed, not authored. Anthropic states plainly that Claude may not be the original author, and that content may have changed after Claude handled it.
- It cannot tell generated from edited. Ask AI to fix your spelling and the corrected text carries the same mark as an article written from a single prompt.
- It needs length. The mechanism works by accumulating statistical confidence across many word choices. A meta description or a one-line fix does not give it enough to read.
- It survives copying and some editing. Paste it into a document and the mark travels with it.
- Ordinary editorial work degrades it. Heavy rewriting, paraphrasing, translation and format conversion all weaken or remove it.
- Nobody outside Anthropic can currently read it. The company says it is working to let users and third parties detect the marks, with technical details still to come.
That last point is worth sitting with. There is, right now, a mark that no external tool can reliably verify.
For example, take a 900 word article you wrote yourself over two evenings. You paste it in and ask for the typos to be fixed. What comes back is your argument, your examples and your voice, and it is marked. Now take an article produced from one prompt in nine seconds. It is marked in exactly the same way. No detector can separate those two, because the mark was never designed to.
Two things nearly every write-up got wrong
Two claims spread faster than the facts did, and both are the kind that make businesses spend money they do not need to spend.
We checked both on 11 August 2026. The sources were the vendor’s own documentation, the European guidance, and the sales pages of two removal services advertising a fix that week. The method was dull and worth stating. Read what each primary source says, then compare it against what the coverage claimed.
The claim: the mark is hidden characters slipped between the letters. It is not. Several outlets described invisible Unicode characters inserted into the text, and paid removal services launched within days advertising that they strip zero-width and invisible characters. That is not the mechanism. The mark lives in which words the model chose, not in anything sitting between them. Tools built to delete hidden characters cannot remove something that was never a character.
The claim: regulators intend to go back and scan everything already published. The opposite is closer to true. The final European guidance says there is no duty to label old content. Anything made before 2 August 2026 can stay as it is (Bird & Bird, retrieved 2026-08-11). Businesses are welcome to label old material. But the guidance names combing through a content database as exactly the kind of effort nobody is expected to make.
One more correction, because it keeps being cited as proof that rewriting is unsafe. A well-known 2024 research paper showed that watermarks are radioactive, meaning traces survive into a model trained on marked text (Sander et al., NeurIPS 2024). That is a finding about training data contamination. It says nothing about running a paragraph through a different tool once.
Will this hurt your Google rankings
There is no evidence that it will, and the position has not moved.
Google’s published line since 2023 is that how content is produced does not matter, provided it is helpful to the person reading it. The March 2026 core update did not target AI content, and no ranking signal that detects AI-written text has been announced (Ahrefs, retrieved 2026-08-11).
The provenance work Google has shipped is about media, not article text. Its labelling for AI images, video and audio runs on the same C2PA standard used for files. Those signals are not publicly identified as ranking factors (Capconvert, retrieved 2026-08-11).
So the honest summary is this. Thin, interchangeable content has been a ranking problem for years and remains one. A watermark does not add a new penalty on top. It also does not rescue anything.
Where an Australian business is actually exposed
You run a business in Sydney and sell to customers in Australia. So does any of this reach you?
The AI Act is European law. It reaches you when you place an AI system on the European market, or when the output is used there. A deployer, in the language of the Act, is whoever publishes the content, as distinct from the company that built the model. For most Australian trade businesses, clinics and service providers, neither role applies, and borrowing European urgency would be dishonest.
The real exposure is second-hand, and it arrives through three doors. Your client contracts, if you supply content to someone who does sell into Europe. Platform and marketplace rules, which are written by private companies and can change without a parliament. And the simple fact that the mark travels globally even where the law does not.
That is a smaller problem than the headlines suggest. It is not nothing.
The date that catches your unpublished drafts
There is a genuine timing trap here, and it is not the one being reported.
Take text published to inform the public on matters of public interest. The date that counts is the date of publication, not the date it was written. Text generated before 2 August but published on or after it falls inside the rule, unless the editorial exception applies (Bird & Bird, retrieved 2026-08-11).
Anyone sitting on a content backlog should read that twice. A draft written in July and published in October is treated as October content.
Two deadlines also sit apart from each other. The duty to tell readers, under Article 50(4), started on 2 August 2026. The duty to mark text so a machine can read it, under Article 50(2), has a later date of 2 December 2026 (Reed Smith, retrieved 2026-08-11).
The exception that does the work
A named person who actually edits the text removes the disclosure duty entirely. That is the part worth building a process around.
The duty on a publisher falls away where the text has been through human review or editorial control. It also asks that a person or company owns what goes out. The guidance adds the condition that makes it real. Those checks must be substantive, not superficial matters or cursory approval (EU Artificial Intelligence Act, retrieved 2026-08-11).
Read that as a description of decent publishing practice, because that is what it is. It also happens to be the honest answer to the question everyone is asking about detection. If a real editor reworks a draft, the mark degrades as a side effect of the editing. There is no separate laundering step to buy, and anyone selling you one is selling a fix for the wrong mechanism.
What this looks like in practice on a business website:
- One named person holds editorial responsibility for what is published, and that name is on the page.
- Review is recorded, so you can show when a draft was checked and by whom.
- Facts get verified against sources, not accepted because a draft sounded confident.
- Your policy says what a mark means, in writing, before anyone raises it as an accusation. Processed is not the same as authored.
Frequently asked questions
Does an AI watermark hurt my Google rankings?
No, on current evidence. Google has announced no ranking signal that detects AI-written text, and its position that production method does not matter has not changed. The provenance labelling it has shipped covers images, video and audio, not article text.
Can I remove the watermark from my content?
Services advertising watermark removal are targeting hidden characters, which is not how the mark works. Heavy editing, rewriting and translation do degrade it, but that is a side effect of editing properly rather than a product you need to buy.
If my copywriter used AI, does my website break the law?
Almost certainly not, if you are an Australian business selling to Australian customers. The AI Act is European. The publisher duty it creates is narrow, covering text published to inform the public on matters of public interest, and substantive human review removes it.
Does the mark appear if AI only proofread my writing?
Yes. The mark attaches to text the model produces, including corrected or translated versions of writing you did yourself. This is precisely why a detected mark cannot be read as proof of authorship.
What about images on my site?
Different mechanism. Image files carry a signed record of where they came from, rather than a mark buried in the content. That record is more fragile than the text mark. Changing the file type, or simply saving it again, usually wipes it.
What to do this month
Nothing here calls for a panic, and nothing here calls for doing nothing.
- Ask whoever writes your content whether AI is part of the process. Not to catch them out. So you can answer the question if a client or a platform asks it.
- Put one name against editorial responsibility for your site, and make sure that person genuinely reads what goes up.
- Check your unpublished backlog against its publication date rather than its writing date.
- Ignore watermark removal tools. They address a mechanism that does not exist.
- Keep judging content the way buyers do. Whether it is useful, specific and true has always mattered more than how it was typed.
If you want a second opinion on how your website content is produced and reviewed, talk to us about it. We will tell you plainly if the answer is that you are already fine. If the site around that content needs work too, that is our WordPress website design and development service.
About the author. Vasilii Aldukhov founded Web Ways Tech in Sydney and has built websites for ten years, mostly in WordPress. He works with Australian businesses on rebuilds, ecommerce and the search foundations underneath them.