AI Watermarking Has Arrived. But Accountability Matters More Than Detection
Imagine I write a client report.
I conduct the interviews. I examine the client’s systems. I identify the problems. I develop the recommendations.
Then I give the draft to an AI system and ask it to restructure one section and tighten the language.
Who authored the report?
I did. The AI assisted. I remain accountable for every conclusion carrying my name.
Calling the report ‘AI-generated’ would be a remarkably poor description of what happened. More importantly, it would tell you very little about the quality of the work or the accountability behind it.
AI watermarking can indicate that an AI system was involved in producing or processing content. It cannot establish who developed the argument, checked the evidence or accepted responsibility for the result. Detection is a useful provenance signal. It is not a substitute for professional accountability.
Why AI watermarking matters now
This is no longer a theoretical debate, and Anthropic is not first to move. Google has been watermarking Gemini text with SynthID for some time, and image tools from Adobe, OpenAI and Microsoft already attach C2PA provenance data. Anthropic has now confirmed that supported Claude models will embed machine-readable marks in generated text and attach digitally signed provenance data to supported files. What stands out is the scope: applied worldwide, across every product surface at once.
According to Anthropic’s marking guidance, the text watermark is woven into the output at model level. It travels when text is copied and pasted and may survive some editing. Marking applies to supported models across Claude, the API, Claude Code and cloud platforms including Microsoft Foundry, wherever Claude is offered worldwide.
Claude models launched in the EU on or after 2 August 2026 support marking from launch. Anthropic is working to add support to earlier models and says broader detection support for users and third parties is still to come.
The limitations matter. A detected mark indicates that content may have been processed by Claude; it does not establish its complete provenance. Heavily edited, translated or very short text may not retain a detectable signal. The absence of a mark does not prove that AI was not used.
That is why detection cannot be the foundation of an organisation’s AI governance.
The same label can describe two very different pieces of work
Now consider the opposite situation.
Someone gives an AI system a client’s name and a vague instruction:
Write me a data strategy.
They make a few cosmetic edits and send the result to the client.
Both documents involved AI. However, the governance, professional judgement and value behind them are completely different.
A watermark cannot tell you who developed the argument. It cannot tell you whether the evidence was checked, whether the recommendations make sense or whether a competent person reviewed the final result.
The better question is not detection. It is accountability.
I was worried about competence before watermarking
In April 2026, after chairing the Will AI Replace Us? panel at SQLBits, I wrote about the questions we did not get to discuss.
One audience question concerned organisations confusing AI-generated output with genuine expertise.
My concern was what I called ‘competence-shaped output without competence behind it’.
AI can produce something that looks as though it was written by somebody who knows what they are doing. The terminology is right. The structure looks professional. The argument sounds confident.
That appearance of competence can make the output more dangerous.
A weak junior draft often looks like a weak junior draft. An experienced reviewer instinctively challenges it.
AI-generated material can arrive looking finished. It can therefore bypass some of the psychological triggers that would normally cause us to scrutinise the work.
The conclusion I reached then still stands:
Nobody should present AI output to a client or a board if they could not defend it themselves under questioning.
Whether a detector says that ChatGPT, Claude or Copilot was involved is secondary.
If your name is on the report, recommendation, board paper, analysis or email, you own it.
You should understand it, have checked it and be prepared to defend it. That is a much more useful governance control than attempting to classify every document as either ‘human’ or ‘AI’.
‘Was AI used?’ is becoming the wrong question
Most organisations I speak to are already using AI in some capacity.
People use Microsoft Copilot, ChatGPT, Claude and specialist AI products. Developers use coding assistants. Marketing teams generate copy. Analysts summarise information. Managers ask AI to restructure documents and who they should lay off.
Trying to divide every piece of work into ‘human’ or ‘AI’ quickly becomes meaningless.
Consider a fairly normal workflow:
Human research → human draft → AI restructure → human edit → peer review → final approval
Is the result AI-generated?
You can argue about the terminology, but the label tells the business very little about the risk, quality or value of the work.
Provenance still has a role. Standards such as C2PA Content Credentials are designed to record information about the source and history of digital content. That can support transparency.
But provenance is evidence about the production process. It is not a verdict on truth, quality, competence or accountability.
What organisations should record instead?
I would rather see organisations answer a short set of practical questions:
- Ownership: Who is accountable for the final output?
- Purpose: What role did AI play in producing it?
- Information: What data or client material was supplied to the AI system?
- Tooling: Were approved tools, models and accounts used?
- Verification: Which important claims, calculations and recommendations were checked?
- Protection: Was confidential, personal or commercially sensitive information handled appropriately?
- Review: Was the required human or peer review completed?
- Evidence: Could the organisation explain the process to a client, regulator or auditor?
This does not require a bureaucratic form for every rewritten email.
The control should be proportionate to the consequence of getting the answer wrong. Tightening an internal meeting summary is not the same as producing financial analysis, legal advice, a clinical recommendation or a client strategy.
For higher-impact work, organisations need a clear accountable owner, an appropriate review process and enough evidence to show how the output was produced and checked.
This is consistent with the UK Government’s guidance on AI assurance, which emphasises effective oversight and clear lines of accountability across the AI lifecycle.
It also reflects the wider AI enablement operating model I use with organisations. Governance, skills, workflow, ownership and measurement have to move together. A policy document sitting in SharePoint is not an operating model.
Professional services firms should pay particular attention
There is an uncomfortable commercial implication here. AI is compressing the amount of time required to produce professional work. If something previously took a consultancy 40 days and AI-assisted working reduces that to 12, what exactly is the client paying for?
That question becomes uncomfortable if the consultancy’s answer is essentially:
Forty days.
It becomes much easier to answer if the client bought:
Diagnosis → expertise → judgement → recommendations → outcome → accountability
The value of a £20,000 strategy engagement should never have been the number of hours somebody spent typing the strategy document into Microsoft Word.

The value should come from understanding the organisation, gathering evidence, identifying the real problem, challenging assumptions, applying experience, designing appropriate recommendations and being accountable for the advice.
AI might make producing the final document considerably faster.
Good. That is productivity.
The commercial problem arises when a supplier represents AI-generated work as something it is not, or when there is so little expertise behind the output that the document itself was effectively the entire product.
If the value disappears when the production time disappears, the business was probably selling the wrong thing.
Detection is a signal, not a governance strategy
Watermarking, detection and provenance technologies may help organisations understand how content was created. They can support transparency, investigation and assurance. They cannot replace professional judgement. They cannot tell you whether the evidence is sound, whether the analysis fits the organisation or whether the person presenting the recommendation understands its consequences. Use detection as one signal where it is useful. Do not confuse it with governance.
The standard should be straightforward:
If you put your name on AI-assisted work, you remain responsible for its accuracy, quality and consequences.
Professional services firms should take that principle seriously. They should also move away from selling production time and towards selling what clients actually need: expertise, outcomes and accountability.
AI watermarking: frequently asked questions
What does an AI watermark actually prove?
An AI watermark indicates that content passed through a supported AI model at some point. It does not establish who developed the ideas, whether the evidence was checked, or who is accountable for the result. It is a provenance signal about processing, not a verdict on authorship or quality.
Can AI watermarks be removed by editing?
Sometimes. Anthropic states the mark survives copy and paste and may persist through some editing, but heavily edited, translated or very short text may not retain a detectable signal. Treat the watermark as fragile evidence rather than a permanent record, and never as the sole basis for a decision about a document.
Does the absence of a watermark mean no AI was used?
No. Absence of a mark proves nothing. Older models, other vendors’ tools, and heavily reworked text can all produce unmarked content that involved AI. This asymmetry is exactly why organisations should build governance around ownership and review rather than around detecting AI involvement.
Should businesses use AI detection tools to check staff work?
Probably noyt but if yo do, use them cautiously, as one signal among several. A detected mark tells you a model processed the text, nothing more. A better control is requiring that whoever puts their name on a piece of work understands it, has verified the important claims, and can defend it under questioning.
How ready is your organisation for accountable AI?
Good AI governance should help people use these tools productively without losing control of quality, data or responsibility. My free AI Readiness Assessment will help you identify where your organisation is ready to move and where the governance gaps still need attention.
Editorial note: I used AI as part of the research and editorial workflow for this article. I checked the sources, shaped the argument and accept responsibility for the final text. All images are AI generated
Useful Links
AI enablement programme delivers a $400k saving
What Is a Consultancy AI Operating System?
Will AI Replace Us? The Chair’s Answers I Never Got to Give
The post AI Watermarking: Accountability Beats Detection appeared first on Gethyn Ellis.
PakarPBN
A Private Blog Network (PBN) is a collection of websites that are controlled by a single individual or organization and used primarily to build backlinks to a “money site” in order to influence its ranking in search engines such as Google. The core idea behind a PBN is based on the importance of backlinks in Google’s ranking algorithm. Since Google views backlinks as signals of authority and trust, some website owners attempt to artificially create these signals through a controlled network of sites.
In a typical PBN setup, the owner acquires expired or aged domains that already have existing authority, backlinks, and history. These domains are rebuilt with new content and hosted separately, often using different IP addresses, hosting providers, themes, and ownership details to make them appear unrelated. Within the content published on these sites, links are strategically placed that point to the main website the owner wants to rank higher. By doing this, the owner attempts to pass link equity (also known as “link juice”) from the PBN sites to the target website.
The purpose of a PBN is to give the impression that the target website is naturally earning links from multiple independent sources. If done effectively, this can temporarily improve keyword rankings, increase organic visibility, and drive more traffic from search results.
