Invisible Ink: Claude Watermarking and the Canadian Legal Profession
One of the recurring themes of this column has been the extent to which the governance of artificial intelligence in Canada is increasingly being shaped by institutions outside the country while regulatory action within the country is largely stalled. Anthropic’s recent announcement that future versions of Claude will place an invisible watermark in generated text offers the most recent example of this phenomenon. A transparency requirement enacted in the European Union will alter the operation of Claude globally and may therefore leave a detectable signal in legal work prepared in Canada, including work produced through specialized legal-focused AI platforms that incorporate Claude within a broader and increasingly complex collection of models. The announcement from Anthropic was published on August 14, 2026, shortly before this column was written. Accordingly, there remains a genuine lack of information about how the watermark will operate across the products and workflows through which professionals actually use Claude. In my view, the announcement warrants attention beyond its immediate technical details because it raises some more challenging questions about disclosure as well as professional competence.
Anthropic describes the watermark as a statistical pattern created through the ordinary process by which a large language model selects one word or token at a time. When Claude reaches a point at which several words would be equally appropriate, a secret key, together with the words that precede the choice, influences the source of randomness used to select the next word. Repeated over a sufficiently long passage, these choices create a pattern that someone with access to the key can evaluate to determine the likelihood that Claude participated in producing the text. The technique is based on Google DeepMind’s SynthID-Text approach and, according to Anthropic, does not require hidden characters, additional metadata, extra tokens, or changes that would be apparent to a reader. It also carries no information capable of identifying the user, organization, or particular conversation. The more significant issue lies in what the watermark can establish. A detected signal indicates a probability that Claude was involved at some point, which may include drafting, translating, summarizing, or substantially editing material that originated elsewhere. It provides no conclusion about authorship, ownership, accuracy, the degree of human contribution, or the responsibility of the person presenting the finished work. Detection will also be less reliable in short passages, factual text, source code, and proofreading, where there are fewer discretionary choices available to the model, while extensive rewriting or paraphrasing may weaken or remove the signal. Anthropic has announced that a detection API will be made available but has not yet explained who will have access to it, what confidence thresholds will be applied, or how results should be understood in professional, disciplinary, or evidentiary settings. For the moment, the watermark remains a potentially useful provenance signal whose practical significance is still unsettled.
The explanation for this change is found in Article 50 of the European Union Artificial Intelligence Act. Article 50(2) requires providers of generative AI systems to ensure that synthetic text and other generated content are marked in a machine-readable format and detectable as artificially generated or manipulated. The legislation requires these measures to be effective, interoperable, robust, and reliable as far as technically feasible, while recognizing limitations arising from the nature of the content and an exception for systems performing standard editing that does not substantially alter a user’s input. Anthropic has also signed the EU Code of Practice on Transparency of AI-Generated Content, a voluntary compliance framework developed to support the implementation of these binding obligations. Approximately 190 organizations have signed the Code, including Google, Meta, Microsoft, Mistral, and OpenAI, although the particular marking and detection methods adopted by each provider may differ. Anthropic has stated that its watermark will be deployed globally because the company does not currently possess a durable means of limiting the change by region. The result is a clear example of European regulation exerting practical influence well beyond Europe. Canada remains without comprehensive federal AI legislation, yet a European transparency rule is already changing the technical environment in which Canadian professionals work. The watermark itself will not reduce hallucinations, prevent inappropriate reliance, or ensure responsible use, although it forms part of a broader regulatory effort to improve transparency and accountability around generated content.
For Canadian lawyers, the issues become more complicated when Claude is accessed through a specialized legal sector focused AI product rather than directly. For instance, Harvey has integrated models from Anthropic, Google, and OpenAI and has explained that its platform may automatically route different legal tasks, or different stages of a workflow, to the model considered best suited to the work. Thomson Reuters describes CoCounsel as having a multi-model architecture that includes Claude, OpenAI GPT, Google Gemini, and proprietary technology, while its next generation of CoCounsel Legal has been built on Anthropic’s Claude Agent SDK. LexisNexis Canada offers Claude alongside several OpenAI models through Protégé General AI. Even as this article was being prepared, that landscape became more complex. On August 20, Harvey announced Tenet, a research-stage model and four days later, Thomson Reuters formally launched Thomson, its own proprietary model. Thomson will initially power CoCounsel’s Tabular Analysis, although CoCounsel remains a multi-model system and its next-generation agentic architecture continues to use the Claude Agent SDK.
As of the date of the writing of this article, I have been unable to locate public guidance from these providers addressing what Claude’s watermark will mean within their respective platforms. It is unclear whether the signal will remain detectable after a legal product retrieves authorities, inserts citations, combines responses from several models, applies a firm template, or otherwise transforms the underlying output. It is similarly unclear whether a lawyer will know which model generated a particular portion of a document, whether vendors will provide access to detection results, and what audit record will remain after a multi-stage workflow has been completed. These questions fall comfortably within existing concepts of professional competence and technology oversight. Most Law Societies in Canada now provide some form of guidance that addresses competence, confidentiality, candour, supervision, information security, reasonable fees, and the lawyer’s continuing responsibility for technology-produced work. In this environment, competence may increasingly require an understanding of the technological supply chain beneath a legal product, sufficient to determine how the work was produced, what records exist, and whether the lawyer can comply with obligations owed to clients, courts, and regulators.
At this early stage, firm conclusions about the professional impact of Claude’s watermark would be premature. Anthropic’s detection tools have not yet been released, previously launched models are still being brought within the marking system, and the operation of the watermark inside multi-model legal platforms remains largely unexplained. Once detection tools become available, there is also a risk that a probabilistic signal will be asked to bear more weight than it reasonably can, particularly if courts, clients, employers, or professional regulators rely on detection results without a careful appreciation of their limitations. The fact that features of two leading legal AI platforms changed while this article was being prepared illustrates both the pace of development and the difficulty of governing products whose underlying models and architecture may change after they have been adopted. The broader significance of Anthropic’s announcement lies in what it reveals about the changing structure of AI governance. A European transparency obligation has reached Canadian professional work through the technical design of a foundation model, while the legal products that mediate access to that model have yet to explain fully how the change will appear within their own systems. For law firms and legal departments, a sensible response will include seeking information from vendors, reviewing internal disclosure and record-keeping practices, and ensuring that lawyers understand which models are contributing to consequential work. This oversight must continue after a product has been approved, particularly as vendors introduce proprietary models and alter the allocation of work among them. If a client, court, or regulator later asks how artificial intelligence contributed to a particular document, the relevant professional should be able to provide an account grounded in more than the appearance of the finished work and more complete than the probability reported by an invisible watermark.
____
Note: Generative AI was used in the preparation of this article.




Start the discussion!