Same pattern, different provider: a major AI company makes a technical decision to comply with a regulation, and it takes the rest of the market weeks to notice what that decision actually asks of everyone else.
Since 2 August 2026, Anthropic has embedded invisible watermarks in every word Claude writes, worldwide, across Claude Platform, Claude, Claude Code, and Claude Cowork. The trigger is Article 50(2) of the EU AI Act, which requires providers generating synthetic text, audio, image, or video to mark that output so it can be identified as AI-generated. Google, Meta, Microsoft, OpenAI, Black Forest Labs, and Synthesia have made comparable commitments. Fines for getting this wrong run up to €15 million or 3% of global turnover, so the whole industry has converged on the same answer inside a few weeks of each other.
What Anthropic actually did
Anthropic is embedding watermarks directly into Claude-generated text at the model level, so the mark survives copy-paste into another document. For files, it is using the C2PA open standard to attach digitally signed provenance metadata, recording that the content came from an AI system.
Every Claude model released after 2 August 2026 carries this by default, and Anthropic is retrofitting older models during the EU’s transition period. The marking applies globally, not only to EU users, including third-party deployments through AWS, Google Cloud, and Microsoft Azure.
That is a real, useful step. It is also not the part of this story most enterprises are watching closely enough.
The problem it doesn’t solve
Everyone is adopting Microsoft 365 Copilot, Power Platform AI, and third-party agents, without a plan to know what those agents produced or who reviewed it.
The result? Content moving through Teams and SharePoint with no record of whether a person or a model wrote it, provenance metadata nobody in IT can read, audit requests answered from memory instead of evidence, and a growing gap between what a regulator can now ask for and what most organisations can actually show.
Anthropic’s watermark tells you something was AI-generated, if you know how to check for it and the mark survives whatever happened to the file afterwards. It does not tell you which of your own Copilot extensions, SharePoint Agents, or Power Automate flows produced it, what that agent could access, or whether anyone signed off on it before it went out the door. Watermarking is a provider problem. Governance is an enterprise problem. They are not the same problem, and solving the first does not solve the second.
Why this is the real signal
Organisations have kept adopting Microsoft 365 and Power Platform faster than they could govern it. SharePoint sprawled first. Teams and guest access followed. Power Platform brought citizen developers building on production data with no formal review. Copilot and AI agents are simply the fastest-moving version of that same pattern, and Anthropic’s watermarking rollout is the clearest evidence yet that regulators intend to hold providers and enterprises to a real evidentiary standard, not a policy document nobody reads.
Rencore helps organisations stay in control of exactly this. We bring visibility, automation, and lifecycle governance to Microsoft 365, SharePoint, Teams, Power Apps, Copilot, Azure AI, and now the agents and extensions running across all of it. That means a live inventory of every Copilot extension and AI agent in a tenant, mapped against the sensitivity labels and access rights of the content they touch, so provenance metadata from a provider like Anthropic becomes one more data point inside a system that already knows what happened, rather than a signal nobody in the business can act on.
What to do about it this week
Confirm which AI tools generating customer-facing content in your organisation already need to disclose that under Article 50(1), and check that disclosure is visible at the point of interaction, not sitting in a terms of service page.
Build or extend a live inventory of every AI agent, Copilot extension, and generative tool active across Microsoft 365 and Power Platform, so you know what exists before a regulator or an auditor asks. A Copilot readiness assessment is a fast way to get that first pass done.
Then treat provenance metadata from providers like Anthropic as one input into that inventory, not the whole answer. The watermark tells you something was machine-made. Your own governance layer has to tell you the rest.
The part that is yours to answer
Providers are marking their output because a regulation told them to. That work is now largely done, and it happened without any of us having to do anything. The part nobody can do for you is the record of what ran inside your own tenant: which agent produced what, on which data, and who signed it off.
See how Rencore covers the EU AI Act for Copilot and agents: EU AI Act, Copilot, and agent governance.
Common questions on this
Does this apply outside the EU?
Yes. Anthropic's watermarking applies worldwide, not only to EU users, and it covers third-party deployments through AWS, Google Cloud and Microsoft Azure. Article 50 reaches any AI system whose output reaches people in the EU, wherever the provider or the deploying organisation is based, so an entity outside the EU serving EU customers is inside its scope. Geography does not decide whether you need the record. Your user base does.
Does watermarking replace the disclosure requirement?
No. They are two separate obligations and both apply. Article 50(2) is the marking of synthetic content so it can be identified as machine generated, which is the part providers such as Anthropic have now done on your behalf. Article 50(1) is telling a person they are interacting with an AI system at all, which is yours to do, and it has to be visible at the point of interaction rather than sitting in a terms of service page. A watermark inside the output does not perform that disclosure.
If someone pastes Claude output into a SharePoint document, does the watermark travel with it?
The two markings behave differently, and it matters which one you are counting on. Anthropic embeds the text watermark at the model level, so it survives a copy and paste of the words into another document. The C2PA content credentials are a different thing: they are signed metadata attached to a file, so they travel with that file and not with text lifted out of it. A screenshot, a retyped paragraph or a paste into a Teams message is a new object carrying none of the original file's credentials. Plan around the form of content your people actually pass around, not the pristine file.
Can we rely on the watermark as our compliance evidence?
Treat it as a supporting signal, not a guarantee. Removal tools already exist for image and file metadata, and Anthropic has said itself that a detected watermark isn't conclusive proof, nor is an absent one. Pair it with your own visibility into AI activity across the tenant.
Do Microsoft Purview or Entra already tell us which content our AI produced?
They cover a real part of it and are worth turning on first. Purview classifies and labels content, applies data loss prevention and records Copilot interactions in the audit log, and Entra manages identity and access for the accounts and service principals behind the tooling. What none of that answers is which Copilot extension, SharePoint agent or Power Automate flow produced a particular document, who owns that agent today, what data it was allowed to reach, and whether anyone still needs it running. Rencore Governance keeps that inventory with a named owner per object, extending the Microsoft controls rather than standing in for them.
How do we find the AI-generated content already circulating inside our tenant?
Scanning for marks is the wrong starting point. Each provider marks its own output in its own way, checking depends on that provider's detection, and a watermark you do find still will not say which of your agents produced the file or whether anyone approved it. The route that works runs the other way round. List every Copilot extension, Copilot Studio agent, Power Automate flow and third-party AI tool live in the tenant, and record for each one who owns it, what content it can reach and when it last ran. An open-ended hunt for AI content becomes a finite list you can review, retire or approve.
Who inside the organisation should own this, IT, legal, or the business?
Split it the way the obligations split. Legal owns the reading of which uses fall under Article 50 and what has to be disclosed to customers, because that is an interpretation of the regulation and of your contracts. IT owns the record: which agents exist, what they can reach, and who is accountable for each one. The business owner of an agent signs off on what it produces. The failure mode sits in the middle, where a policy lives in a document and nobody holds the inventory that would show it is being followed.
What would we actually have to show if a regulator or an auditor asked about AI-generated content?
Evidence rather than intent. A policy document states what should have happened. What an auditor can test is the record: which agent produced a given output, on which data, under whose ownership, and who approved it before it went out the door. A provider watermark contributes exactly one field to that record, the fact that something was machine made, and nothing more. Rencore Governance holds the other fields, a live inventory of every AI agent and Copilot extension in the tenant mapped against the sensitivity labels and access rights of the content it touches, so the answer comes out of a system instead of out of memory.
We have no inventory of AI agents at all. Where do we start this week?
With one pass over what is already running, not with a policy rewrite. Pull the list of Copilot extensions, Copilot Studio agents and Power Platform flows active in the tenant, and note against each one an owner, the data it can reach, and the date it was last used. Then check a single point on the customer-facing side: where an AI tool talks to customers, the Article 50(1) disclosure has to be visible at the moment of interaction rather than buried in a terms of service page. Those two passes give you the shape of the problem before anyone asks you for it.
Where does this sit against the rest of the AI Act timeline?
Article 50 transparency applied from 2 August 2026 and was not deferred by the Digital Omnibus, while the high-risk regime moved to 2027 and 2028. That split is what catches teams out. The obligation already in force is the transparency one, the fines behind it run up to 15 million euros or 3% of global turnover, and a programme replanned around the Omnibus dates can quietly leave it unowned. Treat it as live now, and name who holds the disclosure and who holds the record.
Last updated 13 August 2026