Explained: What Anthropic's Text Watermark Could Mean For Privacy In India
Anthropic will soon embed an invisible watermark in text generated by Claude. It cannot identify who used the AI — but it could tell investigators where to start looking.
Anthropic has announced that future versions of Claude, its AI assistant, will embed an invisible watermark in the text they generate. The company says the measure is part of its effort to comply with the European Union's AI Act and make AI-generated content easier to identify.
The watermark is designed to answer one question: was Claude involved in producing this text? But privacy advocates and legal experts warn that the answer could set off a chain of further questions — who used Claude, when, and what else might that reveal?
The concern stems from AI tools increasingly being used for sensitive work — journalists translating confidential interviews, activists editing statements, whistleblowers organising documents — without intending to disclose that AI was involved. For them, a detectable trace in the text could draw attention to sources, unpublished reporting, political activity or private communications.
What The Watermark Can And Cannot Do
Anthropic says the watermark is a statistical signal, not a fingerprint. It can flag Claude's involvement even when the model was used only to translate, edit or restructure text that someone else wrote. But it contains no identifying information and cannot be traced to a specific user, account or conversation. It cannot establish that Claude wrote a document from scratch.
On its own, a watermark cannot tell you who used Claude, what they asked it to do, or how much of the final text came from the model.
But It Could Change Where An Investigation Starts
That distinction may matter more than it appears, according to Suman Saurav, co-founder of Comms for a Cause, an organisation that works on storytelling and digital security for grassroots and movement-led groups.
Previously, if authorities wanted to establish who wrote a document, they would have to work outward from the document itself — tracing its source, access or circulation. A watermark pointing to Claude offers a different starting point: the company behind it.
"Now the document points to a single US company that keeps account records," Saurav said. "The question 'who wrote this?' becomes 'send a legal request to Anthropic.'"
Saurav does not describe this as proof of wrongdoing or direct surveillance. The concern is that the watermark could make the first step of an investigation easier.
"It is a reduction in the cost of the first step, and the first step is usually the hardest one," they said.
What A Data Request Could Seek
Alvin Antony, Chief Compliance Officer at GovernAI, told Decode that the potential trail from a data request could include basic account details — a name, email address or phone number — along with connection data such as IP addresses and timestamps.
If legally obtainable and still retained, the scope could extend to prompts, outputs, uploaded files and conversation records. There may also be less obvious records, such as trust and safety reports or enforcement history.
"The exact scope would depend on the nature of the offence, the terms of the order and the categories of data that the company retains," Antony said.
There is an important limitation. "The practical question is not only whether investigators can ask for the information, but whether the information still exists when the request is made," Antony said. Data that no longer exists cannot be produced.
How This Plays Out For India
The legal route from a detected watermark to user data depends on what investigators are seeking and where the data is held.
In India, Antony explained, investigators would first need a lawful basis. "An FIR must be registered for a cognizable offence. The information being sought must be relevant to that offence, rather than based only on a suspicion that the content may be connected to one."
For basic account information, a US company may respond to a valid government request. But content — prompts, conversations, uploaded files — requires a different process.
Indian authorities seeking such evidence from a US provider would generally use the India-US Mutual Legal Assistance Treaty (MLAT), a formal process through which one country asks the other to help obtain evidence for a criminal investigation. That process can be slow.
The US CLOUD Act created a framework under which certain foreign governments can enter into executive agreements with the US, allowing them to send qualifying legal orders directly to US providers. India does not currently have such an agreement and continues to rely on the MLAT route.
The reverse works differently. The CLOUD Act also allows US legal process to compel a US-based provider to produce data in its possession, even when that data is stored outside the US. US authorities can potentially seek an Indian user's data directly from a US company without asking Indian authorities first.
"It still requires valid US legal process; it is not blanket access to anyone's data," Antony added.
The result is an asymmetry: India needs a cross-border legal request to reach a US provider's data, while the US can use its own legal system to compel a US company to produce data belonging to someone in India.
What happens after that lead is pursued depends on the legal environment. In a jurisdiction with strong protections for journalists and political speech, a watermark may trigger scrutiny without leading to disclosure. Where dissent is criminalised or surveillance powers are broadly used, the same signal could carry greater consequences.
Who Is Most Exposed
The people most affected are unlikely to be ordinary users. They are journalists working with confidential sources, whistleblowers sharing evidence, activists documenting state violence, political organisers communicating across borders, and civil society groups operating where dissent is closely monitored.
Many of them may not be using Claude to generate original writing at all — just translation, grammar correction, summarisation or accessibility. Ordinary functions that can still leave a detectable trace.
"That trace gives authorities a concrete, legally actionable place to send a request, and the person will not know the mark was there," Saurav said.
"India is not a hypothetical here," they added, pointing to government requests for user data from companies such as Meta, Apple, Google and Microsoft. Indian authorities already use legal channels to seek information from US-based technology companies.
"The realistic risk is not mass surveillance. It is targeted," Saurav said. For most users, little may change. But for someone already under scrutiny, a layer of friction that once stood between a document and their identity could be gone.
What Safeguards Are Being Proposed
Saurav argued that Anthropic should clearly explain what the watermark contains, what data it retains and for how long, publish country-wise transparency reports on government data requests, and commit to challenging overly broad requests.
They also questioned why the same watermark should apply in every jurisdiction when legal protections vary widely. "The same mark that is transparency in Berlin is exposure in a jurisdiction where the state is the threat," Saurav said.
Antony raised a separate concern about the detector itself. Since the detection key is held by the provider, a person cannot independently reproduce or audit the result.
"Any decision based on a detection result should therefore consider its false-positive rate, the amount of text tested, the detector's version and how the test was conducted — alongside independent human review."
A watermark, Antony said, should never be treated as proof of authorship, identity or wrongdoing. At most, it should be one piece of evidence, subject to challenge and corroboration.
There is also the problem of manipulation. Watermarked text can be inserted into someone else's document, creating suspicion where none belongs. Rewriting can weaken or remove the signal — Anthropic itself acknowledges this. The watermark is unreliable in both directions: it could implicate people who had no meaningful connection to Claude, while failing to detect AI involvement after text has been altered.
"The people most likely to suffer from those errors are often those with the least power to challenge them," Antony said.
For Saurav, the deeper question is who gets to shape these systems.
"Well-intentioned policies get built for the median user, and the people at the margins are the ones who bear the cost when those policies are misused," Saurav said. "It is that the people most likely to bear the consequences should have a voice before these systems are built, rather than being consulted after the harm has already happened."