Anthropic’s watermark for Claude text is drawing criticism from three directions at once, and the objections do not overlap. One says the mark degrades what Claude writes. One says it barely slows down anyone who wants it gone. One says it hands verification power to a single party. The Decoder collected all three on 17 August, and each deserves to be judged on its own terms rather than folded into a single “backlash” narrative.

The quality objection comes from John Gruber, who has run the blog Daring Fireball since 2002 and co-created Markdown. In a lengthy post, Gruber argues that Claude’s watermark works by nudging the model toward one synonym over another using a hidden key rather than semantic fit, and that no two synonyms mean exactly the same thing. He points to the choice between “overcast” and “grey” as an example where the system can favor the weaker word. He also rejects the study Anthropic cites to defend the technique, a SynthID-Text paper Google DeepMind published in Nature, arguing that thumbs-up and thumbs-down ratings do not capture whether one synonym reads worse than another. Gruber goes further and speculates that Gemini’s reputation as the weaker writer among frontier chatbots may partly trace back to Google’s own watermarking already running underneath it.

The robustness objection comes from James Padolsey, who built the paraphrasing tool Declaude specifically to strip Claude’s watermark from a document. His point is not that the mark fails outright but that it fails selectively: casual paraphrasing removes it, which means the people with the strongest reason to evade the mark, those deliberately laundering AI text through a human-looking rewrite, can do so with a free tool. Padolsey calls the EU rule behind the mark arbitrary on the same grounds: it catches ordinary users who never intended to hide anything while doing comparatively little against anyone determined to circumvent it.

The verification and asymmetry objection comes from Artificial Lawyer, a legal trade publication that examined what the watermark means for law firms. Its overall read is calmer than Gruber’s or Padolsey’s: most clients and courts will not object to AI use, and some clients now request it. But the publication flags a structural problem. A watermark travels with the text itself, so a clause drafted with Claude years ago can persist inside a contract template long after nobody remembers it was AI-assisted, and a document built from multiple tools could carry overlapping marks from different systems. If a client has banned AI outright, or a judge takes a dim view of it, that history becomes provable even when the finished document is accurate. Fee negotiations could shift too, since a client demanding a discount for AI-assisted work would, in principle, be able to verify the AI share. The catch, which Artificial Lawyer does not dwell on but which follows from Anthropic’s own design, is that only the key holder can currently perform that verification. An individual associate’s drafting choices become permanently checkable while institutions, including Anthropic itself, answer to no equivalent scrutiny until outside parties can run the check themselves.

Anthropic’s side of this deserves the same directness. The company is rolling the watermark out to satisfy the EU AI Act and applying it worldwide because it cannot easily restrict a generation-time feature by region; every Claude model released after 2 August carries it, with older models to follow. Anthropic also says marking gets sparser in fact-heavy passages, since fewer synonym substitutions are available there, a caveat with real implications for technical and legal writing that nobody has yet studied empirically. None of that answers Gruber’s quality complaint or Padolsey’s evasion complaint. But a mark that survives ordinary copying and pasting still raises the cost of passing AI text off as human-written at scale, which is a real deterrent even against an adversary who has not gone looking for a stripping tool, and Anthropic has said a detection API for outside parties is coming.

That API is the test worth watching. A watermark that only its creator can read is a compliance artefact: it lets Anthropic answer regulators without giving anyone else the ability to check a claim. It becomes an accountability mechanism only once a party outside Anthropic, a court, a bar association, a competing lab, can run the detection independently, alongside published data on how much the substitution actually costs in writing quality. Until both exist, any law firm, publisher, or enterprise team relying on Claude output should treat “AI-marked” as a promise made by the company doing the marking, not a fact anyone else can confirm.

The Decoder’s Maximilian Schreiner reported this roundup of watermark criticism on 17 August 2026.