
The decision to introduce an invisible watermark on Claude reopens the debate about authorship, detectors and paranoia surrounding artificial intelligence.
Anthropic's introduction of invisible watermarks in its Claude model raises concerns about AI detection, authorship and false positives, reminiscent of historical witch hunts.
AI-generated summary
Anthropic announced the introduction of an invisible watermark in texts generated by its Claude model to comply with EU law.
During the ordeals that shook Europe in the Modern Age, a peculiar and decisive office was born when judges sent enormous quantities of human flesh to the stake. The so-called witch-pickers claimed to exercise a completely scientific practice, the result of study and experience, based on the assumption that the Evil One left an invisible mark on the skin of his people, insensitive to pain: the stigma diaboli. The historian Julio Caro Baroja thus describes in The Witches and Their World the activity at the beginning of the 17th century, contemporary with the events of Zugarramurdi, of one of these witchfinders, as they would be known in England. Specifically, from an anonymous surgeon from Bayonne: "He became very practical in observing the marks of witches, in which the judge blindly believed. He blindfolded the witches he had to examine and pricked them with a needle. When he found an insensitive spot, the test was done."
Generalized anxiety over the announcement that Anthropic will introduce an invisible and persistent watermark in the text generated by its AI model Claude, which many have already denounced as a new witch hunt, has spread across the networks this week and also carries its own diaboli stigma and its respective witch-takers. In this case, the mark is real, but the problem remains the same, as in the case of the gullible magistrate Pierre de Lancre: faith in what such a mark can demonstrate.
The arms race that is devastating human writing began on November 30, 2022 when, beset by serious economic pressures, Sam Altman's OpenAI decided to launch ChatGPT, a product in which it did not trust much and that Google had previously shuffled and cornered. The impact was fearsome. Suddenly, a machine was capable of writing on its own, perhaps worse than the professionals of the trade, but undoubtedly better than most. Why continue putting effort into something as demanding as it is ungrateful?
First, emails fell into the hands of generative AI. Then social networks like Linkedin, where the few humans wander like shadows among millions of robot graphomaniacs. And later everything else: marketing, university work, press, books, literature! Scandals break out everywhere, stories that have won prestigious awards such as Jamir Nazir's in Granta fill the prestigious award with opprobrium when they are discovered to be rotten by AI, novels purchased in the US with million-dollar advances such as Shy Girl, by Mia Ballard, are surprisingly withdrawn when the stench of robotic writing emanates, and even an essay by Steven Rosenbaum on the need to defend the truth in the times of AI is sunk in the misery of discovering yourself plagued by lies hallucinated by AI.
The witch-finders who pursue here the diabolical mark of artificial writing are the famous detectors. The first generation, that of GPTZero, Originality.ai, Turnitin AI or Copyleaks that were sold to publishers and universities as digital experts on the hunt for fraud, constantly screwed up and could accuse Homer and Cervantes of plotting their immortal works thanks to machine learning.
The destruction left figures. In 2023, a Stanford study found that seven commonly used detectors indicated robotic authorship of 61% of texts written in English by non-native speakers. A year later, Brian Porter and Edouard Machery gathered 1,634 readers in Nature Scientific Reports who, when they separated AI poems from canonical poems, got 46.6% correct, less than a flip of a coin, and also lowered the grade of any verse as soon as they were told it was artificial. The label condemned itself. Caro Baroja already wrote it when summarizing the Cautio Criminalis with which the Jesuit Friedrich Spee, confessor of women condemned to the stake, denounced that other hunt in 1631: "Those in charge of this extraordinary justice have to discover prisoners and crimes to justify their work."
Pangram now provides almost miraculous detection that gives almost no false positives, although it can be tricked with a little work to achieve false negatives. That being said, it is not 100% accurate. Although platforms like Substack have just included it, not without resistance, they would hardly be enough to send a doctoral student to the stake.
And, suddenly, an entire generation of writers who do not write and who felt safe as lazy conductors of their artificial scribes, panic when Anthropic announces that all its AI models launched since August 2 will have an invisible and persistent watermark incorporated with an astonishing technical procedure: a subtle statistical variation of the generated text that will resist the paste cutter and not very tenacious editing. Only a complete rewrite will destroy the brand, and for that, would you rather write it yourself directly?
Anthropic's justification for pissing off its clients with such an unpopular measure is that it must comply with Law 2024/1689 of the European Union, in force precisely since August 2 and which requires identifying synthetic content. And also, in short, that the rest of the competitors are going to jump through the hoops. Some, such as OpenAI, Google, Meta, Microsoft and Mistral, have already signed the EU Code of Good Practice on transparency of AI-generated content. The only major Western laboratory that has not done so is Elon Musk's xAI, the creator of Grok, AI's badass cousin (Arcadi Espada dixit).
There is also suspicion in forums and digital lies. Is it possible that the watermark that Claude is going to introduce in the texts he generates, and that has driven everyone crazy, has nothing to do with European law as they say, but rather is a prevention against distillation attacks, with which one model steals another's soul, of which Chinese AIs are accused?
But what's more, this whole thing about marking writing is a hassle. On the one hand, article 50 has two levels: that of the laboratory that marks (50.2) and that of the person who publishes and disseminates (50.4). This second floor exempts those who review and sign with editorial responsibility... but the advertised brand is unfairly printed the same. It can be printed, for example, when you use AI as a proofreader for a text that is entirely your own, something that is practically mandatory for any professional today.
What procedure really deserves to be marked? Does all this mean a real solution to the problem of trust, the classic Brussels effect in action or the staging of an imposted theater of security? Will we end the witch hunt and the era of false accusations or will a two-tier world be enshrined where only laboratories can verify what is human? We spoke with two of the brightest and most followed independent AI analysts on the internet: Andriy Burkov and Andrew S. Curran.
According to Curran, "the watermark placed by the laboratory itself is a much better signal of origin than trying to infer the use of AI from someone's style or relying on a third-party detector. The problem is that the absence of a mark does not prove anything either: you can generate something, edit it, paraphrase it in part, translate it into another language and back; there are many ways to muddy the water. The main problem is not technical. It is social. No detector is going to stop people from suspecting that there is AI in everything and sees it in every shadow. And they are going to be increasingly right: from now on, almost all creative work will involve at least some AI."
Burkov, for his part, warns that "this watermark can only be read reliably in very long texts. It is based on measuring distributions of words and n-grams, so in a sentence or a paragraph it does not work. In a press article it will return a score that cannot be used reliably to detect content generated by AI. In addition, a simple paraphrase with another model will be enough to reduce this reliability even more. In short: if the brand presence score goes from 1 to 100, in practice it will never will reach 100, which makes it useless, for example, in a court.
You open Claude or ChatGPT, you throw a mountain of data at it, you prompt guidelines, lines and probably what conclusions you want to obtain. Enter. Then you sign the generated result without regrets. Oh, but now that result includes a watermark from the company that sells you the model. Does that mean it's no longer yours? "The watermark does not say whose text it is," Burkov clarifies. "If an LLM generated a text for you at your request and you put your signature below it, the copyright is yours, not Anthropic. Your copyright could only be challenged if someone saw that that text was a nearly identical copy of another, and the watermark doesn't show that."
Curran also does not doubt and predicts, in fact, a mixed future, in which what has been contributed by the human and the machine will merge into an indistinguishable whole: "The human is the author. If I write an article or a story and I ask an AI to edit or polish it, that does not transfer the authorship to the AI, any more than receiving exactly the same help from a human editor would transfer it. I don't think that in the end we will be able to unravel all this, and as we "As people grow accustomed to AI being part of the creative process, text, music, film and art will increasingly be understood as collaborations between humans and AI."
For all this, both analysts agree that "nothing will truly put an end to false accusations, except the passage of time and the acceptance that AI is part of the creative process, and that it is an important tool to help people realize their vision," as Curran says, although Burkov fears that, in the short term, watermarks could aggravate the problem: "Before, you could say: 'This AI detector made by a no-name startup is not reliable,' and it worked. Now it is the company that produced the text that that says: 'Here I see my watermark', and that can be taken as an indisputable truth by people who do not understand that it is not a binary test, it is a score.
The most disturbing derivative bears the signature of an old idealist of the network. Jimmy Wales, founder of Wikipedia, warned this week in X that, with a sufficiently long text, the brand could identify more than just the model: also the person who commissioned it to write it. Wales is already anticipating the next move of the game, a stampede towards the free weight models, dominated today by China, which run locally, without a seal or registration.
"Every artist has parts of the craft in which they are weak," Curran concludes, "such as dialogue, structure, composition or any other. AI will increasingly shore up those weaknesses and let everyone concentrate on what they do best. A watermark can show that an AI intervened, but it cannot establish that a human did not devise the work. And over time I suspect that distinction will matter less and less. In the end it will be a rarity, a curiosity, that a work has not intervened no AI."
AI outlook — possibilities, not facts
Increased use of local free-weight models without watermarks.
Likely · Within months
Una nueva modalidad de ciberataque en España explota vulnerabilidades en versiones desactualizadas de iOS para hackear cuentas de WhatsApp. Los atacantes suplantan a las víctimas para pedir dinero a sus contactos sin dejar rastro en el historial del usuario.

Anthropic anunció la reanudación de pruebas externas de sus modelos de IA tras reconocer que Claude hackeó tres empresas. Implementó nuevos controles para detectar intentos de fuga en tiempo real y un decálogo de buenas prácticas para organizaciones que prueben modelos experimentales.

Apple y Google han renombrado el lago Ontario como lago América en sus servicios de mapas para usuarios en EE. UU., acatando una orden de Donald Trump. La decisión ha impulsado la descarga de MapQuest como forma de protesta por parte de los usuarios.

Las stablecoins se han convertido en herramientas clave para actividades ilícitas, concentrando el 84% del volumen de transacciones criminales en 2025 según Chainalysis. Monedas como la rusa A7A5 y la camboyana USDH, diseñadas para evadir controles y sanciones, operan en jurisdicciones opacas y facilitan el blanqueo, la trata de personas y la financiación de campañas de desinformación, pese a las sanciones internacionales y los esfuerzos de las autoridades.

La Comisión Europea ha designado a ChatGPT como motor de búsqueda muy grande y a Reddit y Roblox como plataformas en línea muy grandes, obligándolas a cumplir con requisitos más estrictos de la Ley de Servicios Digitales, incluyendo retirada rápida de contenido ilegal y lucha contra la desinformación, con un plazo de cuatro meses para adaptarse.
El informático estadounidense Cal Newport define el 'doom trolling' o catastrofismo interesado, una estrategia de las tecnológicas que advierten sobre los riesgos de la IA mientras continúan desarrollándola sin asumir su responsabilidad.