Developers got lucky. Marketers did not. The mechanism behind AI text watermarking needs many equivalent ways to say the same thing in order to hide a signal. Source code has almost none, which is why developers' actual exposure is narrow.
Marketing copy has more equivalent phrasings than any content type in existence. A 1,500-word blog post, a nurture sequence, a landing page, a video script — these are the ideal carriers. If you produce content for a living, the marked surface is your entire deliverable.
TL;DR — the exposure by asset type
| Asset | Marks reliably? | Why |
|---|---|---|
| Long-form blog post | Strongly | Maximum length, maximum phrasing freedom |
| Newsletter / email sequence | Strongly | Same, and usually generated in one pass |
| Landing page body copy | Yes | Enough prose to accumulate signal |
| Video / podcast script | Strongly | Long, conversational, very high entropy |
| Social posts | Weakly | Usually too short to carry reliable signal |
| Headlines, taglines, CTAs | No | Far below the length threshold |
| Product feeds, specs, SKUs | No | Near-zero entropy |
| Heavily human-rewritten drafts | Degrades sharply | The carrying word choices get replaced |
The table above comes down to how much "open choice" a piece of writing has — try the mechanism directly:
A model doesn't know "the next word" — it has a shortlist with preferences. Roll the dice and watch it land somewhere on the shortlist, matching the odds.
The results of the study were quite …
A teaching model with illustrative parameters — not any provider's actual watermarking scheme.
Update, August 16: summarizing your own material marks far less than writing new
Anthropic published an interactive explainer that adds a distinction this table was missing, and it is the most useful thing marketers can take from the whole rollout.
The watermark can only live in open choices — points where several continuations are equally good and a random number decides. Writing a blog post from a brief is nearly all open choices. But summarizing, repurposing, or restructuring text you already have is not, because the facts, figures, and phrasing are pinned by your source document. In Anthropic's summarization example, the entire factual payload came from the user's input; chance only reached the connective tissue between the facts.
Extraction and light editing are the extreme case: zero open choices. Ask a model to pull names and dates out of a paragraph in a fixed format, or to fix the grammar in a sentence you wrote, and there is exactly one valid output. Nothing to mark. The one caveat is framing — if the reply wraps your answer in "Here's the corrected version:", that sentence is the model's own and can carry a sliver of signal, so strip framing lines before you ship.
The practical consequence for content operations:
| How you produce it | Watermark carried |
|---|---|
| Generate a post from a topic brief | Strong — the worst case for exposure |
| Generate from your own detailed outline | Reduced — your structure pins the shape |
| Summarize or repurpose your existing copy | Weak — the facts and framing are yours |
| Have the model edit or proofread your draft | Near zero — most words are already yours |
| Extract fields into a fixed format | None |
This is not a loophole to game, and treating it as one misreads the risk. But it does mean the "repurpose one strong human-written asset across channels" workflow — already the better content strategy — happens to be the one that carries the least mark. The teams most exposed are the ones generating net-new long-form from thin prompts, which is also the content platforms are most motivated to demote.
The risk is distribution, not detection

The instinct is to worry about a client or an editor running a detector. That is the smaller problem, and it does not exist yet — no public detector has shipped, though Anthropic has announced a text detection API.
The larger problem already has a working precedent. Spotify began labeling AI-generated artist profiles and removing them from default recommendations — and the demotion, not the label, is what reprices the business. That is the template every platform with a recommendation algorithm now has in front of it.
The pattern to internalise: provenance is graduating from metadata into a ranking input. Once a platform can cheaply tell that content was machine-generated, the question stops being whether to disclose it and becomes how much reach it deserves. A badge you can absorb. A distribution cut you cannot.
On search specifically, the honest answer is that nothing has changed yet. Google's stated position remains that it rewards helpful content regardless of production method, and it has announced no watermark-keyed ranking signal. But the AI slop problem that made all of this politically urgent is a search problem first, and a provenance signal is a much cheaper filter than quality assessment. Planning as though that stays free forever is optimistic.
What this changes about how you produce content
Not much, if you were already producing content worth reading. Quite a lot, if your model was volume.
The mark scales with the thing you were doing anyway. Publishing forty lightly-edited generated posts a month produces forty strongly-marked documents under one domain. Publishing four genuinely researched pieces where a model helped with structure and a human wrote the argument produces four weakly-marked ones. The mechanism does not punish AI assistance; it accumulates on AI substitution.
Heavy editing is the only removal method that is also good practice. Paraphrasing through a second model destroys the mark, but it also destroys whatever specificity made the draft worth publishing, and it costs another inference call. Substantial human rewriting destroys the mark as a side effect of making the work actually yours. That is a rare case where the compliance-safe path and the quality path are the same path.
Short assets are effectively unaffected. Headlines, ad copy, subject lines, and social posts are below the length threshold where statistical detection means anything. If a large share of your AI use is there, your exposure is close to zero.
Client contracts: get ahead of it now
This is the concrete, do-it-this-quarter item, and it costs nothing.
Agencies and freelancers are about to face a conversation they have not scripted: a client runs a deliverable through a detector, gets a hit, and concludes they paid for something a machine wrote. Every part of that conclusion may be wrong — a hit means the text was processed by a model, which includes proofreading your own copy — but you do not want to be establishing that mid-dispute.
What to put in the SOW or master agreement:
- A stated AI-use policy. What you use models for (research, outlining, first drafts, editing) and what humans do. Specific beats vague.
- The caveat, in writing. "A provenance mark indicates that content was processed by an AI system. It does not indicate authorship, proportion, or quality." This is the vendor's own framing and it is the sentence that resolves most disputes.
- A disclosure standard for the client's own obligations. If the client publishes into a jurisdiction where EU AI Act Article 50 transparency duties apply to them, that is their obligation, not yours — but they will appreciate being told, and it makes you the adult in the room.
- Which deliverables are human-first. Thought leadership, founder bylines, and anything with a named human author are worth committing to a different standard than a product-comparison page. Say which is which.
The agencies that handle this well will do it proactively as a trust signal. The ones that wait will do it as damage control.
The ghostwriting problem is the sharp edge
There is one category where this genuinely bites: content published under someone else's name.
Executive bylines, founder LinkedIn posts, expert-attributed thought leadership, testimonial copy. The whole product is the reader believing a specific person wrote it. A provenance mark does not reveal that a ghostwriter was involved — that has always been an open secret — but it does introduce a machine-readable signal into an artifact whose value depends on perceived authenticity.
There is no clever mitigation here, only an editorial one. If a named human is the credibility of the piece, that human's actual thinking and language have to be in it substantively enough that the draft is genuinely theirs. That was always true. The mark just makes the shortcut more legible.
Bottom line
Marketing content is the best carrier this technology has, so if you produce it at volume, assume it marks. Then notice that the consequential risk is not a detector — it is platforms doing what Spotify just did, and wiring provenance into how much reach content gets.
The defensible position is not evasion, and it is not abstinence. It is producing fewer, better pieces where a human's judgement is materially present in the text, and writing an honest AI-use clause into your client agreements before anyone asks. Both of those were the right call before watermarking existed. They are now also the risk-managed one.
Related on explainx.ai
- How AI text watermarking actually works — the mechanism, and why prose marks best
- What AI watermarking changes for developers — the companion piece, and a very different exposure
- Spotify labels AI artists and demotes them — provenance as a distribution decision
- Anthropic is watermarking Claude text — the policy behind all of this
- Are AI watermarks monetisable? — who ends up paying for detection
- What is AI slop? — the content-quality problem driving platform policy
- The slopocalypse — why distribution, not generation, is the constraint
- LinkedIn's C2PA Content Credentials — the same push on the image side of your campaigns
- EU AI Act and US policy: complete guide — the disclosure obligations that may reach your clients
- What actually changes after the EU AI Act — Article 50(4) puts the disclosure duty on you as deployer, not on the model provider
Primary sources: Anthropic Help Center, "How Claude marks AI-generated content" (August 11, 2026) · Anthropic engineering commentary on X (August 11–12, 2026) · Reported Spotify AI-labeling policy, August 11, 2026
Accurate as of August 12, 2026. No public Claude watermark detector existed at the time of writing, and no search engine has announced a watermark-keyed ranking signal. Contract guidance here is practical, not legal advice. Follow @explainx_ai for updates.
