Sylwia Lask's post on Claude's watermark is the best-natured thing I have read on this topic in a while, and it is right about the two things people keep getting wrong: the EU AI Act asks for machine-detectability, not a ban, and a watermark hit tells you a model was involved, not that it wrote anything.

I want to add to it rather than argue with it, because that announcement has two halves and the comment threads only ever reach one of them.

Half one is text. A keyed statistical mark, spread across token choices. It is the half everybody is discussing and, as I will get to, the half you personally cannot test.

Half two is files. Anthropic began attaching C2PA content credentials to generated images on 11 August. C2PA is an open standard with an open reference tool, so this half is checkable by anyone, today, with no key and no vendor cooperation.

I build a PDF signal engine, so the second half is my problem. On 14 August I put a signed image through every PDF generator on this laptop to find out what a downstream reader can still see. That is the measured part of this post. First, though, two things about the text half, because both keep coming up in that thread.