# A watermark is not a disclosure

**Summary:** Marking AI text and telling a person they are talking to AI are two different obligations. A watermark announcement settles only one, and not the one support teams need.

**In short:** Two obligations, one announcement, and the gap between them.

**Published:** 2026-09-11

**Last updated:** 2026-09-15

In August the AI world got a run of headlines about watermarking, and a lot of teams running customer-facing AI read them as good news about their own obligations. Some of it is good news. It is just not news about the thing most of them were worried about.

The short version: marking AI-generated text so a machine can detect it, and telling a person they are dealing with AI, are two different obligations. One announcement settled one of them. This piece is about why the other one is still sitting on your desk, and what to check this week.

## Two duties, in the Commission's own words

When enforcement of the transparency rules began on 2 August 2026, the European Commission described the obligations in two separate clauses. Interactive systems will have to tell users they are dealing with AI rather than a human. And AI-generated content will also have to carry machine-readable marks.

Read that as two sentences rather than one, because they are two sentences. A mark is for machines. A disclosure is for people. They travel through different parts of a system, they are satisfied by different mechanisms, and a vendor doing an excellent job of the first has not touched the second.

We covered what actually landed on 2 August, and which deadlines moved and which did not, in [the EU AI Act deadline that didn't move](https://unless.com/en/blog/know-how/eu-ai-act-august-2-transparency-deadline/ "Unless: the EU AI Act deadline that didn't move"). That piece is the timeline. This one is about a specific confusion that has grown since.

## What the mark can and cannot do, per the people who built it

The useful thing about this particular story is that the vendor documented the limits themselves, plainly, in [How Claude's text watermarking works](https://www.anthropic.com/news/claude-text-watermark "Anthropic: How Claude's text watermarking works").

The mechanism is a statistical pattern in word choice. Where the model has several equally natural ways to continue a sentence, the choice is steered by a secret key. That is elegant, and it carries its own constraints, which Anthropic states rather than buries.

Detection works poorly on small samples, because there are fewer word choices and so less signal. It is sparser on factual passages, where fewer alternatives exist without making the text wrong. Where an exact output is required, and a different word would be factually incorrect, the watermark is not applied at all. And the question it answers is narrow: how likely is it that this was partly written by Claude. It cannot confirm that something was written by a human, and it cannot tell you a different AI wrote it.

Now do the arithmetic on your own traffic. A support answer is short. It is factual. It often has one correct phrasing, because a payroll threshold or a refund window is a fact and not a stylistic choice. The conditions under which the mark is weakest are a fairly precise description of what a support agent sends all day.

Nobody hid this. It is a property of the technique, and the same shape applies to statistical watermarking generally rather than to one company's implementation.

## What you still owe, and who decides it

Here we have to be careful, and being careful is more useful than sounding certain.

Who bears the interactive-disclosure obligation in a given deployment is a question with genuine disagreement in it, and it turns on details of your setup and on which paragraph of Article 50 applies to you. We are not going to resolve that for you in a blog post, and you should be wary of any vendor that does. Ask your own counsel, with your own deployment in front of them.

What we can tell you is how our own agreement allocates it, which is a fact about our contract rather than an opinion about the law. Our [EU AI Act appendix](https://unless.com/en/legal/resources/eu-ai-act-compliance/ "Unless: EU AI Act compliance") says that Unless provides functionality allowing end users to be informed they are interacting with an AI system, and that the customer is responsible for enabling and configuring that functionality in its deployments. We also provide technical means to mark AI-generated content, and the customer uses them where the law requires.

That split is worth quoting against ourselves, because it is the part vendors usually leave vague. We can hand you a switch. We cannot flip it in your product for you, and no announcement from any model provider flips it either.

## The check that takes ten minutes

Open your own customer-facing AI the way a customer would, on the surface a customer actually uses. Use the live product rather than the admin preview.

If it does not say it is AI before the interaction starts, that is your finding. A line in the footer does not count, and neither does a sentence in the terms. The disclosure has to be where the person is when they start talking.

Then write down who decided that, and when. The record is the part people skip, and it is the part that matters later, because the question in an audit is rarely "is it switched on today". It is "who decided, on what basis, and can you show me".

## Provenance is not accountability

The deeper reason a mark cannot carry this weight is that it answers a different question.

A watermark tells you a machine was involved. An audit trail tells you which model answered, which sources it used, when, and which human could have intervened. Only one of those is any use to an auditor asking why a particular customer got a particular answer on a particular Tuesday. That is why our own [trust architecture](https://unless.com/en/trust/ "Unless: trust and compliance") leads with the per-decision record rather than with provenance marking.

Marking is worth doing and the industry is right to be doing it. Just do not let it close a question it was never shaped to answer. The person on the other end of your agent does not need to detect that they are talking to AI. They need to have been told.
