Whose words are these anyway? Why everyone is a bit cross about Claude’s new watermark

Author: alex.steele@leadingai.co.uk

Published: 16/08/2026

AI and copyright

Just over a year ago, we published a blog about AI and copyright: You can’t break into the library, we said. Rather obviously. The argument was that, although the law around AI and intellectual property was looking a bit complicated, there was some common sense emerging from the fog of unhelpful headlines.

I was pretty pleased with the analogy we used to explain how to keep on the right side of the law—and your conscience. We already understand that you can go into a library, read everything, then use what you have learned to write something new. You can even quote bits, if you give appropriate credit. What you cannot do is break in at night, photocopy the books, put your name on the front and sell them as your own.

I mean, it was supposed to be an analogy. But in a US court’s account of how Anthropic built its training library, it sounds as though Anthropic did something edging rather close to our hypothetical library raid. Not literally, obviously. But in Bartz v Anthropic, a US court heard how Anthropic had acquired millions of books from pirate sites as part of building a huge digital library for training Claude. It had also bought physical books, cut off their bindings, scanned them and discarded the originals. Yeah, tossing actual books in a bin makes me shudder too.

In June 2025, the court found that Anthropic’s use of books to train its AI models was sufficiently transformative to count as fair use. It reached a different conclusion about the pirated copies Anthropic had acquired and retained in its central library. Which is an excellent reminder that if you dump enough AI analogies on the internet, eventually a court might validate one of them.

But quite a lot else has changed in the year since I wrote that blog. So, where have we got to?

Learning, copying and markets

Most of our readers care about US and European legal frameworks, so let’s cover those for now.

In the US, courts have started producing some of the first substantial decisions on AI training data: the material fed into large language models. Anthropic’s case was not the only important one. In Kadrey v Meta, another US federal judge found Meta’s use of books to train its Llama models to be fair use on the evidence before the court.

Important note: these decisions do not establish a sweeping principle that AI companies can train on anything they fancy. They are federal district-court rulings applying the US “fair use” test to particular facts. They may be influential, but they do not settle the issue for every US court or every AI company.

The transformative purpose of training mattered in each case. So did the evidence, or lack of evidence, that the use would substitute for or damage the market for authors’ books.

The Bartz case drew a narrower but important distinction between using a book to train an AI and building a lasting collection of unauthorised copies of that book. The court found that using books to train the model could, in principle, be fair use. But it found that downloading pirated books and keeping them indefinitely in a central library was a separate act of copying, which could not be justified simply by saying the books might later be used for training.

That does not mean that acquiring material lawfully will always decide a “fair use” case. But it does mean that “we only used it for training” is not a complete answer to every act of copying. In other words, learning from a book and building a library out of stolen copies of books are not necessarily the same thing.

Common sense is still doing surprisingly well.

The UK, meanwhile, has spent much of the past year arguing about where exactly to draw the line. At this point, it is less a clear line made with a Sharpie and a ruler, and more a wide, grey no man’s land, loosely sketched in pencil.

The Government consulted on options ranging from keeping the existing system, through requiring licences for AI training, to allowing much broader text and data mining. Its initial preferred approach was essentially to let AI developers train on copyrighted material unless rights holders had reserved their rights.

That produced what might generously be called… passionate feedback. Particularly from the creative industries.

The Government’s eventual March 2026 report on copyright and AI did not adopt a new copyright exception for AI training. Instead, it sets out the options, the evidence and the fairly substantial things we still do not know. So, for now, the existing copyright framework remains in place. The official line is, essentially: it is complicated.

What goes in, and what comes out

The EU has, characteristically, moved on to regulate another part of the problem. Under its AI Act, providers of general-purpose AI models must have a policy for complying with EU copyright law and publish a sufficiently detailed public summary of the content used to train their models.

Separately, from 2 August 2026, the Act requires providers of systems generating synthetic text, images, audio or video to make outputs detectable as artificially generated or manipulated, including through machine-readable marking where that is technically feasible.

The Act also recognises that not every use of AI is the same. Its labelling requirement does not necessarily apply where AI is being used for standard editing assistance, or where it does not substantially alter material supplied by the user.

Which, helpfully, is close to the distinction most of us would make instinctively. That does not necessarily mean you need a single universal watermark, or a perfect technical test for “AI-made”. But it does mean provenance is becoming a regulatory issue, not just a matter of organisational etiquette.

Which brings us back, rather neatly, to everyone being cross with Anthropic

Anthropic says that Claude models launched on or after 2 August 2026 embed an imperceptible watermark in generated text. It is introducing the feature progressively, rather than claiming that every historical Claude output is already marked. For certain generated image files, it is also adding provenance metadata.

There is an obvious attraction to this. We are increasingly surrounded by AI-generated content. Being able to establish where something came from could help with misinformation, fraud, deepfakes and people passing off AI-generated work as their own—and being given credit for work they did not really do.

It also feels like a natural extension of the transparency argument we made last year. I said then that we should be open about when and how we have used AI. Watermarking potentially makes some of that provenance visible by default.

But it also introduces a much harder question.

What exactly counts as AI-generated?

Imagine three people writing a blog. Person A types: “Write me 1,000 words about Claude watermarking”, copies the answer and publishes it.

Person B writes 1,000 words themselves, gives them to Claude, asks it to restructure the argument and tighten a few paragraphs, rejects half the suggestions and publishes the resulting version.

Person C writes the whole thing but gets stuck on one paragraph, asks Claude whether there is a better analogy, likes one of its suggestions and rewrites the paragraph.

Those are clearly not the same thing. But where, exactly, does the human-written document become an AI-generated one?

Whose words are these anyway?

This is not really a new problem. We just didn’t previously care very much about the tools people use to make things. Nobody expected a report to contain a disclosure saying: written in Microsoft Word, spellchecked by Microsoft, researched using a bit of Google, calculations checked in Excel, and improved after Dave in Finance said paragraph four would not make any sense to man nor beast.

We have traditionally cared about sources. Where did that fact come from? Whose idea are you quoting? Have you copied someone else’s work? AI is beginning to make us care more about process. What helped you make this? How much did it contribute? At what point did you stop being the author and become the editor?

I am not convinced there is a neat technical answer to that — and I write a lot of this kind of thing. The AI contribution to these blogs probably ranges from none at all to perhaps 40%, usually when I need help explaining a technical concept or deciphering a US court document.

But a percentage is not really the point. I edit heavily, fact-check, restructure, reject suggestions and use different tools to critique both the AI’s work and mine before I settle on something I am happy to let Leading AI publish. And someone else always reviews and edits it too. I leave in the odd typo just to make sure.

If I write something and Claude, or any other LLM, improves a sentence, the AI has contributed some words. If Claude writes something and I spend an hour challenging it, checking its facts, changing its structure, deleting half of it and rewriting the rest, I have contributed considerably more than adding some words.

The question now vexing people is: if I did that now, would the watermark still be there, on my blog?

Authorship has never simply meant being the person whose fingers pressed the keys. Writers dictate, collaborate with editors and commission research; responsibility for the finished work is more complicated than a record of keystrokes. That matters because there is a danger that we start treating provenance technology as something it is not.

A watermark will indicate that a particular AI system generated or processed some content. It is not a reliable verdict on who authored the work, whether the ideas are original, whether the content is accurate, or whether meaningful human judgement went into producing it. Those questions will still get decided in courts, universities, workplaces and contracts. The a watermark will not answer them on its own.

And the absence of a watermark does not magically prove something was written by a human either. There is a useful distinction here:

  • Watermarking is a technical signal attached to an output.
  • Provenance is a record—possibly spread across different documents and data items—of an asset’s history.
  • Disclosure is a human or organisational statement about how AI was used.
  • Authorship is a legal and ethical question about creative contribution and responsibility, as it has always been.

Those distinctions will matter particularly in education and workplaces, where I can easily imagine a machine-readable watermark acquiring the slightly creepy authority of a compulsory drugs test.

I think I would trust a watermark as a measure of authenticity about as far as I trust plagiarism software: not very far at all, and certainly not without human judgement.

Any organisation tempted to treat a watermark as conclusive evidence of misconduct should first decide what it is actually trying to police: undisclosed assistance, false claims of authorship, plagiarism, failure to exercise judgement, or just poor-quality work. Those are different problems. A technical marker cannot resolve them on its own.

The library is getting more complicated, but I am sticking with the analogy

It is good that we are starting to ask whether we should be able to tell that AI was involved in producing something at all. Transparency is generally useful. Provenance matters. Watermarking may turn out to be very handy indeed.

We just shouldn’t confuse provenance with authorship. Knowing that a machine touched the words is not the same thing as knowing who wrote them.

Believe me.