What Zero Trust Can Teach Us About AI Watermarks Enterprise Management Associates VP of Research Chris Steffen argues that AI watermarking, such as Anthropic's move to comply with the EU AI Act's transparency rules, is insufficient on its own and should be supplemented with zero trust principles of continuous verification. Steffen contends that watermarks, like badges, can be cloned or stripped, and content should be evaluated for accuracy and citations regardless of origin. He advocates for a multi-layered approach where watermarking is one factor among many, not the sole test of trustworthiness. What Zero Trust Can Teach Us About AI Watermarks Published 08/28/2026 Written by Chris Steffen , VP of Research at Enterprise Management Associates . I recently wrote https://blog.enterprisemanagement.com/the-issues-around-watermarking-ai-generated-text about the mess that is watermarking AI-generated text and how Anthropic's move https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content to add watermarks in response to the EU AI Act's transparency rules https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content raises more questions than it answers. If you haven't read that blog, the short version is this: telling AI content apart from human content is getting harder every day – AI is a tool that should be used much in the same way that you use a calculator to do long division, and slapping a watermark on it doesn't change that. But there's another angle worth talking about, one that happens to be near and dear to my heart: zero trust. If you've spent any time around IT security, you've heard the phrase coined by my friend John Kindervag https://www.darkreading.com/perimeter/forrester-pushes-zero-trust-model-for-security that states: "never trust, always verify." While we're at it, can we all just take a moment and finally end the debate regarding the amazing contributions of John to the cybersecurity industry, especially as being the creator/originator/author/godfather/whatever of zero trust? Please and thank you. It used to be that if you had a badge that let you into a building, nobody questioned you once you were inside. Sounds reasonable, except that a little social engineering, a cloned badge, and some strategic tailgating proved that one credential, checked once, isn't worth much. So, security teams stopped trusting people just because they made it through the front door, and started verifying, continuously, no matter who you are or where you came from. A watermark is basically a badge for content. It's a single flag that says "trust me, I'm AI-generated" or, by its absence, "trust me, I'm not." And just like a badge, it can be cloned, stripped, or never issued in the first place. Anyone determined enough to get around it will. So why would we build a policy around trusting that one factor? The zero trust answer: we shouldn't. Instead of asking "does this have a watermark?" we should ask the same questions we ought to ask about the voracity of any piece of content: Is it accurate? Does it cite something real? Does it hold up when I check it myself? Those questions work whether a human or a machine did the writing, and they don't require an EU regulation to make them worth doing. The debates around AI watermarking have just started, but regardless of which side you come down on in this debate, we analysts, students, professionals, regulators, lawyers this one is continuously hilarious to me , and everyone else will continue to utilize the tools that are available. Penalizing those for using a new technology or productivity tool is ridiculous and practically impossible: those who want to find a workaround will likely do so, and those who benefit from using the latest technology to increase productivity will be ostracized. And this is the lesson in a multi-layered, zero trust-based cybersecurity strategy: the bad guys often find the workaround. It isn’t to say that watermarking is useless – it can be one data point or factor among many. But treating it as THE only factor/data point – the single test of whether something can be trusted – is exactly the kind of perimeter thinking that got network security into trouble for years. We eventually figured out we needed to verify everything, all the time. Content deserves the same lesson. This blog – as well as the referenced blog – was written poorly by a human, and not edited by AI or really anyone . Spell checker was used somewhat and the grammar detector was also used marginally . Unlock Cloud Security Insights Subscribe to our newsletter for the latest expert trends and updates Related Articles: We Asked an AI Agent to Close a Linear Ticket. It Dropped a Production Table. https://cloudsecurityalliance.org/articles/we-asked-an-ai-agent-to-close-a-linear-ticket-it-dropped-a-production-table Published: 08/21/2026 Governing AI Agent Identities: An Identity Maturity Model for AI Agents https://cloudsecurityalliance.org/articles/governing-ai-agent-identities-an-identity-maturity-model-for-ai-agents Published: 08/20/2026 Beyond Deepfakes: Zero Trust Security for the AI Economy https://cloudsecurityalliance.org/articles/beyond-deepfakes-zero-trust-security-for-the-ai-economy Published: 08/20/2026