
Ai Water Marking: Could this become another way of tracking users across the internet
September 28, 2026
The invisible mark
Anthropic, the creators of one of the most powerful family of Ai models, Claude, has declared,
"Future Claude models will generate text that contains a watermark."
This watermark is invisible to the naked eye but contains a statistical signature that can be used to infer its likely origin.
It is burnt into the text through an algorithm to influence statistically predictable, but invisible, word choices.
The reason given is that the watermark will enable a piece of text to be checked to determine the likelihood that Claude was involved in creating it.
In Anthropic's case, it will help to distinguish from content created by their Ai models and content created by humans, or other providers.
A negative result doesn't necessarily establish human authorship, another Ai may have created it, but it can help as one check on the authenticity on human creative ability.
If other Ai model providers follow suit, that check could become considerably stronger.
A watermark like this could be useful in the real-world.
Publishers, researchers and online platforms could use similar tools to identify content that may have been generated or substantially edited by Ai.
In education, where there is still a desire to exclude Ai generated content, watermarking could help to check whether a student's work was actually their own creative output.
It could also be used to help determine whether Claude substantially generated a message from the other end of a messaging app helping to distinguish the authenticity of the other user.
The uses are potentially extensive, and many of them are beneficial.
However, could this ability to imprint invisible identification into Ai generated content have further reaching consequences?
From one key to millions
How precisely could watermarking ultimately be attributed?
While Anthropic report this is about checking the likelihood a piece of work has been produced with the involvement of one of their own Ai models, they explicitly say that the watermark carries no identifying information and cannot be traced to a particular person, organisation or conversation.
Buit that is now.
Could this method of watermarking could be expanded into tracking the creator of the Ai generated content?
Consider two different systems.
In the first, every Claude conversation uses watermark key A.
A detector finds a long passage of text on a website and concludes there is a high probability Claude was used to create it.
That is approximately what Anthropic is proposing.
But theoretically the provider could create a hierarchy:
Claude -> organisation -> account -> session
User one might generate text using a watermark derived from key A-18492.
User two could receive A-73821.
A corporate customer could have another family of keys.
The watermark would still not need to contain someone's name, email address or account number. The provider could simply retain a database connecting the watermark key to the account that has generated it.
A passage subsequently published on a website, copied into a document or posted on a social platform could then potentially be tested against those keys and connected back to the account from which it originated.
At that point, the question would no longer simply be:
"Was this generated by AI?"
It could become:
"Whose AI account generated this?"
This, of course, is a hypothetical extension of the technology and Anthropic has not announced that it intends to do this but are we ready for each piece of content to be trackable to the originating account.
But the technology raises a broader question.
Would we accept that level of invisible attribution if refusing it meant losing access to technologies becoming increasingly central to work, education and everyday life?
Community Discussion
Comment Policy