On August 14, Anthropic published a plain-English explanation of how its Claude models watermark the text they generate. The timing was no accident. The EU AI Act's transparency obligations became enforceable on August 2, and Anthropic — along with roughly 190 signatories to the EU's Code of Practice on Transparency of AI-Generated Content, including the other major model providers — had committed in July to marking AI-generated content. The watermark now ships globally in new Claude models. There is no setting to turn it off, and no US-only version without it; Anthropic states plainly that it has no durable way to scope the marking by region.

So a rule your bank never voted on, written by a legislature an ocean away, arrived anyway — the same way most AI change arrives at a community bank: inside the products. If your staff drafts with Claude today, the words carry a machine-readable signature. As other providers implement their own marks under the same Code of Practice, the tools around them will follow. That deserves a clear-eyed governance read, and most of what's being written about it is aimed at AI companies rather than at the institutions using their tools.

A European law, arriving through your vendor stack

Article 50 of the EU AI Act requires providers of generative AI systems to mark their outputs in a machine-readable way, and layers disclosure duties on top for defined situations — when people interact with an AI system, when deepfakes are published, and when AI-written text informs the public on matters of public interest without human editorial review standing behind it. Penalties for transparency violations run up to €15 million or 3% of global annual revenue. The obligations became applicable August 2, 2026; generative systems already on the market before that date have until December 2 to meet the marking requirement, and Anthropic says watermarking will reach its older models over the coming months.

None of that binds a Wisconsin community bank directly. It binds the companies whose tools the bank licenses — and those companies, facing one strict regime and many lenient ones, chose to build to the strict one everywhere. Compliance officers have seen this pattern before: it is how GDPR reshaped privacy notices at institutions with no European customers. The practical effect for a US bank is identical to being regulated, minus the comment period.

What the watermark actually is

The mechanism is worth understanding, since its design determines what it can and cannot prove. A language model writes one word at a time, and at many points several candidate words would serve equally well. Ordinarily the model settles those low-stakes choices with a random number. A watermarked model settles them using a cryptographic key instead. The words are still effectively random to any reader — but someone holding the key can check a passage after the fact and compute the likelihood that the model made those choices. Claude's implementation follows the SynthID-Text method Google DeepMind published in Nature in 2024.

Three properties matter for a bank's read of it. Nothing is added to the text — no hidden characters, no metadata, no formatting tricks. The mark carries no information about the user, the organization, or the conversation; it can say Claude was likely involved and nothing more. And detection requires the provider's key: Anthropic says a detection API is coming, and third-party "AI detectors" that guess from writing style are a different, far less reliable animal.

Generated image files travel a separate road: Claude now attaches cryptographically signed provenance metadata to the images it produces, using the C2PA standard that camera makers and photo editors have begun adopting. That label sits in the file rather than in the pixels, which means it verifies origin when present and vanishes when someone strips or re-saves the file.

What it can tell someone — and what it can't

Detection answers exactly one question: the probability that the model participated in producing a passage. Even that answer arrives hedged. The watermark lives only in words the model chose freely, so it runs thin where choice runs thin — short passages, heavily factual text, code, and light proofreading of a human draft may carry too little signal to register. The Act reflects the same logic: purely assistive editing that leaves a text's substance intact sits outside the marking obligation altogether. A complete rewrite strips the mark; ordinary editing usually leaves it intact. And the method cannot distinguish text the model drafted from text a person wrote and the model heavily revised.

The inverse matters just as much. Absence of a watermark proves nothing. Text from another provider carries a different key or no mark at all, older models remain unmarked through the transition, and human writing has never carried one. Any control, vendor claim, or fraud procedure that treats “no watermark detected” as evidence of human authorship is built on sand.

Assume the question “did AI write this?” now has a technical answer — and make sure your bank can answer it from its own records before anyone else answers it with a detector.

What this means inside a community bank

Your drafting is now discoverable

Policies, procedures, board memos, customer letters, committee minutes — wherever staff use AI assistance today, the output carries a signature that a future detection API can read. The uncomfortable version of this future is a bank learning from an outside party which of its documents were AI-drafted. The comfortable version is a bank that already knows, from its own AI inventory and usage policy, exactly where AI participates in its work — and for whom a watermark merely confirms its own records. Which version a bank gets is a governance choice being made right now.

Accountability didn't move

Anthropic's FAQ addresses this directly: the watermark changes nothing about ownership or responsibility for an output. Supervisory reality says the same. A memo the bank issues is the bank's memo; the officer who signs it owns its accuracy whether the first draft came from a keyboard or a model. The watermark makes AI involvement visible — it does not, and cannot, transfer a single ounce of responsibility to the tool. Programs built on that principle from day one lose nothing here.

Your vendors write with AI too

The marketing agency drafting your product pages, the compliance vendor selling policy templates, the core provider generating customer communications — their deliverables now inherit the same marks from the same tools. Vendor oversight gains one plain question worth adding to due diligence: where does AI participate in the deliverables we buy, and what does the vendor disclose about it? A vendor who can answer cleanly is telling you something about their own governance. A vendor who can't is telling you something too.

Provenance rails cut both ways

As C2PA credentials spread through cameras, editing software, and AI tools, verifying where a document or image came from slowly becomes possible in a way it never was — a genuine long-term gain for fraud teams staring down deepfakes and voice cloning. The discipline is patience: provenance signals are arriving unevenly, absence of a credential means nothing for years yet, and no verification standard replaces callback procedures and out-of-band confirmation today.

Three moves this quarter

None of this calls for new machinery. It slots into the same inventory, policy, and reporting discipline a working AI governance program already runs. Three concrete actions cover it:

  1. Add a column to the AI inventory. For each tool: do its outputs carry a watermark or provenance credential, and does a detection route exist? Ten minutes per system, and the bank's answer to “where does marked content originate here?” is documented before anyone asks.
  2. Give the usage policy a disclosure standard. The AI Usage Policy should state where AI drafting is permitted, what human review each category requires, and when the bank discloses AI involvement — to customers, to the board, or internally. Most policies written before this year are silent on disclosure. One added section closes the gap.
  3. Put one paragraph in the next board report. The board should hear, in plain language, that AI-generated text is now marked at the source across the industry, that accountability for bank work product is unchanged, and that the bank's inventory and policy already cover the shift. Three sentences, minuted, and the institution is on record ahead of the question.

The direction of travel

Marking will spread — the Code of Practice signatures make that certain — and detection tooling will follow it. US supervisors watch European practice the way builders watch a neighbor's addition, and the examiner question this points toward is already familiar in shape: how does the bank know where AI touches its content? Institutions running a real program will answer from the inventory in a sentence. Institutions without one will discover that the world outside can now answer it for them.

That's the lens that makes this month's news useful rather than alarming. A bank that knows where AI touches its work has nothing to fear from a watermark that says so.

From the Handbook

Transparency questions, answered by a working program.

The Community Bank AI Governance Handbook builds the inventory, usage policy, vendor oversight, and board reporting this shift calls for — sized for community institutions, with a 90-day Quick Start and 27 editable program templates in the companion Toolkit.

Explore the Handbook →