Watermarking Is Now a Vendor Decision Your Legal Team Did Not Approve

In August 2026, watermarking moved out of the policy binder and into the product. For the newest models, it now ships as a default setting.
Article 50 of the EU AI Act began applying on August 2. Interactive systems must tell users they are talking to AI. Providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable, detectable format. Deployers must label deepfakes and certain AI-generated text published to inform the public. Systems already on the market before August 2 received a short grace period for machine-readable marking, until December 2, 2026. Anything launched from August 2 onward has to comply at launch.
California’s AI Transparency Act (SB 942, as amended by AB 853) became operative the same day. It targets large generative-AI providers and covers images, video, and audio: a free public detection tool, an option for a visible label, and a hidden provenance disclosure. Text sits outside its scope, but the direction on both sides of the Atlantic is the same.
Then Anthropic made the commercial implication explicit. Claude models launched on or after August 2 are required to mark from launch. Older models fall under the Act’s transition window, which ends December 2, 2026; Anthropic says it is adding marking to those models over the coming months. Generated text carries an imperceptible watermark that survives copy and paste and light editing. Generated files such as PNG, JPG, and SVG carry signed C2PA content credentials. The company said it signed the EU Code of Practice to comply with the AI Act, and that it is applying watermarking globally because it does not yet have a durable way to scope it by region. Google, Meta, Microsoft, OpenAI, and Mistral signed the same provider section of the Code.
That is the point most buyers missed. The mark has moved from your disclosure policy into the vendor’s output.
If the model you bought stamps every draft, the legal question changes. You no longer ask whether you chose to label AI content. You ask whether you can explain what that stamp means for client work, privilege, evidence, and professional responsibility.
What actually changed
The August 2 rules are practical. They did not move with the high-risk deadlines, which the Digital Omnibus pushed to December 2027 and August 2028. They apply to systems that talk to people and to content that can pass as authentic.
For a company that only publishes marketing copy, a machine-readable mark may look like a compliance detail. For a law firm, an accounting firm, a clinic, a bank, or any team that drafts advice, the same mark sits on material that may later become a contract, a memo, a filing, a patient note, or an exhibit.
Three things are now true at the same time.
First, the vendor can change how output is marked without negotiating with your general counsel.
Second, the mark travels with the text when an employee pastes it into Word, an email, a matter file, or a client portal.
Third, you still own the professional act. The model did not sign the advice. The firm did. Anthropic says as much: the watermark does not change who owns the output or who is legally responsible for it.
Why legal and compliance should care now

Watermarks and provenance signals carry consequences. They can shape how a document is later read by a detector, a regulator, opposing counsel, an auditor, or a client’s own AI tool.
A hidden mark can keep a draft detectable as machine-assisted after a lawyer has edited it, because light editing is not enough to remove it. The mark says a model was likely involved at some point, and it cannot tell whether the model wrote the text or heavily edited it. A C2PA credential can ride along inside an image or chart that ends up in a client deck. The detection asymmetry is also real. Anthropic’s detection API is in private preview, open to regulators, law enforcement, media, researchers, and enterprises with their own compliance obligations. A regulator may be able to read the mark on your deliverable before your own team can.
None of this makes watermarking a bad idea. The EU rule exists because unmarked synthetic content is a fraud and impersonation problem. The business problem is different. Most organizations have a policy for “do not paste client data into public chatbots.” Far fewer have a policy for “what happens when the approved model silently marks the output we send to a client.”
There is also a records problem. If two versions of the same memo exist, one carrying the model’s mark and one rewritten in the document system, which one is the work product? Who decided to rewrite it? Was that decision logged? If a dispute arrives in 2028, can the firm show the human review and editorial responsibility that Article 50 treats as the line between automated publication and a professional’s own work?
Your approved model may already be watermarking every completion. Which of your live workflows put a machine mark on a client deliverable without a lawyer noticing?
The false comfort of “the vendor handles compliance”

Buying a model that complies with the AI Act does not give you a compliant system.
The vendor can mark its generations. It cannot decide whether your chatbot discloses itself at the start of a customer session. It cannot decide whether a deepfake used in training material is labelled; visible disclosure to readers is largely the deployer’s duty under the Act, which makes it yours. It cannot decide whether a public-interest text went through genuine human review. It cannot accept professional liability for the advice your people issued after they edited the draft.
A global watermark, applied because the vendor cannot yet scope by region, shows how these systems actually work. Your EU exposure, your California exposure, and your Israeli client file now share one output pipeline. Any regional legal analysis that assumes you can switch a feature off in one market is already behind the product.
DNLA Playbook for Output Provenance
- Inventory where generated text, images, audio, and video leave the model and enter real work: matter files, email, CMS, EHR, ERP, slide decks, and client portals.
- Separate internal drafts from external deliverables. A mark on a working note carries different weight than a mark on a signed opinion.
- Define who may rewrite, override, or remove provenance signals, including C2PA metadata on files, and require that action to be logged.
- Write the human-review rule in operational language: what editorial responsibility means in your firm, who signs it, and what evidence is kept.
- Test detection on your own stack. Where you have access, run the vendor’s detector and at least one independent method against typical edited drafts, not raw model output.
- Update client and vendor contracts. State who is responsible for labelling, what happens when the vendor changes marking behavior, and what must not leave the firm with hidden provenance attached.
- Treat chatbot disclosure as a product requirement. A homepage footnote does not count. If a customer or a patient is talking to a system, the system has to say so.
DNLA Take
Watermarking is the first August 2026 transparency rule most companies will meet in the product rather than in the policy binder. That is convenient for vendors and dangerous for buyers who confuse a stamped token stream with a governed system.
The mark does not prove the advice was reviewed. It does not prove the source data was allowed. It does not prove the final document is the one the professional meant to issue. It only proves that a model touched the text somewhere in a pipeline you may not fully control.
If legal did not approve the vendor’s marking behavior, the organization is already making a disclosure decision by default. And a default is a verdict waiting for the first client, regulator, or opposing expert who knows how to read the stamp.
Want the same rigor applied to your own AI system?
That's what a QAi Health Check is for.