A watermark is not proof:
What Anthropic’s commitment means for classrooms
Anthropic announced this month that Claude will begin embedding invisible, machine-readable marks in content it generates. If you teach, you may have had one of two reactions: either the detection problem just got solved, or here we go again.
In my opinion, this is a step in the right direction, but it is also important to note that this is not a cheating detector. Anthropic’s own documentation on the limits of watermarking explains why.
How did this come about?
Anthropic signed the EU AI Act’s Article 50(2) Code of Practice on Transparency of AI-Generated Content: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content). Article 50 requires providers of covered generative AI systems to make synthetic output machine-readable and detectable as artificially generated or manipulated. The Code is a voluntary framework for demonstrating how providers may meet those obligations; it does not replace the legal obligation itself.
Be careful about the limitations:
A detected mark tells you content may have been processed by Claude. It does not tell you Claude wrote it. There are several ways that people use GenAI to interact with test - proofread, translate, summarize, and convert files, and the output carries a mark in all of those situations. A student who ran their own paragraph through Claude to fix the grammar produces marked text. So does a student who typed “write my essay” and pasted the result. The mark does not distinguish between them.
I often run my text through for a proofread - including this article. I can honestly say I wrote all but one paragraph this article. Claude cleaned up grammatical errors and wrote the paragraph about what other companies and platforms offer similar services. I proofed that paragraph for content errors. Pangram detects 0% human writing… which is both good and bad.
The absence of a mark tells you even less. Anthropic lists the ways generated content comes back clean: text from a model released before marking was supported, text that was heavily edited or paraphrased or translated, passages too short to carry a reliable signal, files whose metadata was stripped by a format conversion or a screenshot, and any product or file type where that marking type isn’t supported.
Google is the only other company watermarking text, through SynthID in the Gemini app, and its detector is still gated behind a waitlist for journalists rather than open to anyone teaching a class. OpenAI marks images and audio and offers a public checker for them, but ChatGPT text output carries nothing. Adobe, Microsoft, Meta, TikTok, and several camera manufacturers attach C2PA metadata to media files, which disappears on a screenshot or a re-save. Roughly 190 organizations signed the EU Code, 82 of them as providers, so agreement to mark content is not the constraint. Text is the hardest modality and almost nobody has solved it. A student who uses ChatGPT instead of Claude turns in prose that no tool currently claims to detect. The signal is asymmetric, and it fails in the direction that matters least to us. Clean text proves nothing. Marked text proves something small.
This distinction is particularly important because the EU AI Act itself recognizes that ordinary editing assistance is not the same thing as the generation of new synthetic content. Its transparency provisions include an exception for AI used solely for standard editing assistance that does not substantially alter the input or its meaning. (https://artificialintelligenceact.eu/transparency-rules-article-50/)
The signal is asymmetric, and it fails in the direction that matters least for academic-integrity decisions.
Clean text proves nothing. Marked text proves something small.
What this changes
Less than the announcement’s headlines may suggest. If a mark cannot separate a student who translated their own sentence from a student who generated an entire assignment, it cannot resolve an academic-integrity case. A watermark might justify a conversation, particularly if it conflicts with other evidence. It cannot establish authorship, intent, or a violation by itself.
The equity problem arrives quickly.
Students who use AI most often for legitimate and permitted assistance may be disproportionately represented among marked submissions: multilingual students, students with disabilities, students developing academic-English fluency, and students using tools in ways an instructor has explicitly allowed. Meanwhile, students who can substantially revise, paraphrase, or route output through another system may leave no reliable signal at all.
That is not a reliable basis for enforcement. It is a recipe for uneven scrutiny.
The practical response has not changed: design assignments for evidence of process rather than post hoc certainty about provenance.
- Ask students to submit notes, outlines, drafts, revision histories, or decision memos.
- Include brief oral, in-class, or recorded components in which students reconstruct their reasoning.
- Build disclosure into the assignment itself, so students have a legitimate way to describe what tool they used, for what purpose, and what they changed afterward.
- Treat discrepancies as invitations to ask questions—not as proof.
A disclosure statement can tell you more than a watermark: “I used Claude to translate my outline, then rewrote the English myself” is actionable pedagogical information. A detected technical signal is not.
Article 50 does not stop with AI providers.
Paragraph 4 also addresses deployers: organizations that publish AI-generated or manipulated text to inform the public on matters of public interest generally must disclose that fact. There is an important exception where the content has undergone genuine human review or editorial control and a natural or legal person takes editorial responsibility for publication.
For universities, this is primarily a communications and governance question, not a classroom-detection mandate.
Institutions publishing public-facing, AI-assisted content should clarify who conducts editorial review, who assumes responsibility for the final material, and when disclosure is appropriate. Universities with substantial EU operations or public-facing EU communications should review those practices with institutional communications staff and legal counsel.
Provenance is not Authorship.
Origin marking is a context signal. Like image metadata, it can offer useful information about a piece of content’s history. It is reasonable for the industry to build better tools for that purpose.
A detected Claude watermark may support a conversation with a student. It should not, by itself, trigger an allegation, grade penalty, or disciplinary finding. Academic-integrity policies can acknowledge watermarking as one limited source of contextual information, but they should state plainly that it is not dispositive evidence of authorship or misconduct.
The goal is not to become better at catching marks. It is to build assignments, policies, and classroom relationships that make students’ thinking visible.

