Anthropic's plan to embed invisible watermarks in Claude-generated text drew an attack Wednesday from veteran venture investor Bill Gurley (@bgurley), who argued that Anthropic would control both the marking system and the means of identifying its output.
"This is only identifiable by Anthropic," Gurley wrote on August 12th. "Once again they are judge, jury, and prosecutor." He was responding to Steven Sinofsky (@stevesi), the former Microsoft Windows chief and current Andreessen Horowitz board partner.
Gurley spent decades at Benchmark and made one of the firm's defining investments in Uber. Before entering venture capital, he worked as a Compaq design engineer and covered personal-computer companies as a Wall Street analyst, including serving as the lead analyst on Amazon's initial public offering. His criticism centers on a technical implementation with direct consequences for developers, publishers and businesses using Claude to draft or edit material.
What Anthropic is rolling out
Anthropic documented the marking system on August 11th as part of its compliance with the European Union's AI Act. Claude models launched on or after August 2nd support marking at launch, according to Anthropic. Models released before that date are subject to a transition period, and Anthropic says it is working to add support to them.
That distinction means claims that every current Claude response already contains a watermark go beyond Anthropic's documentation. The system applies to output from supported models.
For text, Anthropic says the model weaves an imperceptible mark into the generated language. The mark remains when text is copied and pasted and may survive some editing. Anthropic says it operates at the model level across Claude, Claude Code, Claude Cowork, Claude Tag and the Claude API, including supported models accessed through AWS, Google Cloud and Microsoft Foundry. Anthropic plans to apply the system worldwide. Files receive a separate type of marking. Supported SVG, PNG and JPG files will carry signed provenance metadata based on C2PA, an open industry standard. That metadata can indicate that Claude processed a file and whether it was subsequently altered.
Anthropic has not published the technical method used to watermark text or released a public detection tool. Its documentation says tools for users and third parties are forthcoming. That leaves Anthropic as the initial authority able to explain how its text marks work and how reliably they can be detected, the control problem Gurley identified.
A mark does not establish authorship
Anthropic's own limitations narrow what any eventual detector can prove. A detected mark indicates that content may have been processed by Claude. It does not establish that Claude wrote the original material.
A person could write a document, send it through Claude for proofreading, translation or formatting, and receive text carrying the mark. Marked passages can also be edited, excerpted or combined with human writing. That creates a material distinction between "Claude processed this text" and "Claude authored this text," especially in schools, workplaces and publishing systems that may use detection results to enforce AI policies.
The inverse is equally important. Anthropic says a missing mark does not prove human authorship. Detection can fail when text is short, heavily edited, paraphrased, translated or mixed with other material. Output from older or unsupported models may also lack the signal.
The European Union's Article 50 requires providers of generative AI systems to make synthetic text, audio, images and video machine-readable and detectable as artificially generated or manipulated. The obligations took effect on August 2nd, while systems already on the market received a transition period until December 2nd. The European Commission's transparency code calls for marking and detection methods that are effective, interoperable, reliable and as technically robust as feasible.
Anthropic signed that voluntary code as a route to demonstrating compliance with the binding AI Act requirements. Its decision to deploy the marks worldwide avoids maintaining separate model behavior for Europe, although it also extends an EU-driven compliance system to Claude users in the United States and other markets.
Gurley's criticism lands before outside users can test the central claims: detection accuracy, false-positive rates, resilience to editing and any effect on output quality. Anthropic says the watermark does not change Claude's meaning, quality or readability. The technical documentation needed to independently examine that assertion remains unpublished.