Start free trial
AI Governance

The watermark problem AI providers can't solve for you.

The watermark problem AI providers can't solve for you.

Same pattern, different provider: a major AI company makes a technical decision to comply with a regulation, and it takes the rest of the market weeks to notice what that decision actually asks of everyone else.

Since 2 August 2026, Anthropic has embedded invisible watermarks in every word Claude writes, worldwide, across Claude Platform, Claude, Claude Code, and Claude Cowork. The trigger is Article 50(2) of the EU AI Act, which requires providers generating synthetic text, audio, image, or video to mark that output so it can be identified as AI-generated. Google, Meta, Microsoft, OpenAI, Black Forest Labs, and Synthesia have made comparable commitments. Fines for getting this wrong run up to €15 million or 3% of global turnover, so the whole industry has converged on the same answer inside a few weeks of each other.

What Anthropic actually did

Anthropic is embedding watermarks directly into Claude-generated text at the model level, so the mark survives copy-paste into another document. For files, it is using the C2PA open standard to attach digitally signed provenance metadata, recording that the content came from an AI system.

Every Claude model released after 2 August 2026 carries this by default, and Anthropic is retrofitting older models during the EU’s transition period. The marking applies globally, not only to EU users, including third-party deployments through AWS, Google Cloud, and Microsoft Azure.

That is a real, useful step. It is also not the part of this story most enterprises are watching closely enough.

The problem it doesn’t solve

Everyone is adopting Microsoft 365 Copilot, Power Platform AI, and third-party agents, without a plan to know what those agents produced or who reviewed it.

The result? Content moving through Teams and SharePoint with no record of whether a person or a model wrote it, provenance metadata nobody in IT can read, audit requests answered from memory instead of evidence, and a growing gap between what a regulator can now ask for and what most organisations can actually show.

Anthropic’s watermark tells you something was AI-generated, if you know how to check for it and the mark survives whatever happened to the file afterwards. It does not tell you which of your own Copilot extensions, SharePoint Agents, or Power Automate flows produced it, what that agent could access, or whether anyone signed off on it before it went out the door. Watermarking is a provider problem. Governance is an enterprise problem. They are not the same problem, and solving the first does not solve the second.

Why this is the real signal

Organisations have kept adopting Microsoft 365 and Power Platform faster than they could govern it. SharePoint sprawled first. Teams and guest access followed. Power Platform brought citizen developers building on production data with no formal review. Copilot and AI agents are simply the fastest-moving version of that same pattern, and Anthropic’s watermarking rollout is the clearest evidence yet that regulators intend to hold providers and enterprises to a real evidentiary standard, not a policy document nobody reads.

Rencore helps organisations stay in control of exactly this. We bring visibility, automation, and lifecycle governance to Microsoft 365, SharePoint, Teams, Power Apps, Copilot, Azure AI, and now the agents and extensions running across all of it. That means a live inventory of every Copilot extension and AI agent in a tenant, mapped against the sensitivity labels and access rights of the content they touch, so provenance metadata from a provider like Anthropic becomes one more data point inside a system that already knows what happened, rather than a signal nobody in the business can act on.

What to do about it this week

Confirm which AI tools generating customer-facing content in your organisation already need to disclose that under Article 50(1), and check that disclosure is visible at the point of interaction, not sitting in a terms of service page.

Build or extend a live inventory of every AI agent, Copilot extension, and generative tool active across Microsoft 365 and Power Platform, so you know what exists before a regulator or an auditor asks. A Copilot readiness assessment is a fast way to get that first pass done.

Then treat provenance metadata from providers like Anthropic as one input into that inventory, not the whole answer. The watermark tells you something was machine-made. Your own governance layer has to tell you the rest.

Common questions on this

Does this apply outside the EU?

Yes. Anthropic’s watermarking applies worldwide, and Article 50 covers any AI system reaching people in the EU, wherever the provider or the deploying organisation is based.

Does watermarking replace the disclosure requirement?

No. Article 50(2), marking synthetic content, is separate from Article 50(1), disclosing that a person is interacting with AI at all. Both apply.

Can we rely on the watermark as our compliance evidence?

Treat it as a supporting signal, not a guarantee. Removal tools already exist for image and file metadata, and Anthropic has said itself that a detected watermark isn’t conclusive proof, nor is an absent one. Pair it with your own visibility into AI activity across the tenant.

Where does this sit against the rest of the AI Act timeline?

Article 50 transparency applied from 2 August 2026 and was not deferred by the Digital Omnibus, while the high-risk regime moved to 2027 and 2028. For the full picture of what moved and what did not, see the EU AI Act was not delayed, three parts of it were.

The part that is yours to answer

Providers are marking their output because a regulation told them to. That work is now largely done, and it happened without any of us having to do anything. The part nobody can do for you is the record of what ran inside your own tenant: which agent produced what, on which data, and who signed it off.

See how Rencore covers the EU AI Act for Copilot and agents: EU AI Act, Copilot, and agent governance.

Last updated 13 August 2026

Related articles

Rencore newsletter

Subscribe to our newsletter

Get the latest Microsoft 365 governance insights delivered to your inbox.

Loading form