Restricted analysis, made public daily.
Declassified under standing order Edition No. 042 Friday, August 14, 2026

The Detector Is the Eraser.

The EU’s Code requires that Claude’s new watermark be checkable by third parties, and Anthropic has committed to exactly that. A July forensic study measured what a public check is worth for the watermark class — not Claude’s unpublished mechanism, but three representative published methods: one meaning-preserving paraphrase pass removed every detected mark for two of the three tested, 98.3% for the third. The layer that verifies the mark and the layer that confirms its removal are the same instrument.

Yesterday, this record filed what Anthropic’s new watermark can’t prove. It also noted the one thing nobody outside Anthropic can do yet: check for the mark at all. That check is coming. Anthropic’s help center commits to it plainly — “We’ll support users and other third parties to detect Claude’s marks, as the Code requires, and we’ll share details in forthcoming documentation.” The commitment is compliance with a real European obligation. It is also, structurally, the missing half of a removal tool.

A public verifier answers one question: is the mark present in this text? That is also the only question an eraser needs answered. Nothing gets breached and nothing gets reverse-engineered — the loop asks only for the access the Code obliges providers to support, in whatever form that ships, and its final pass writes the receipt: this text now reads as unmarked. The property belongs to the architecture of public verification, not to Anthropic’s engineering. Any lab that exposes a sufficiently repeatable detector opens that loop the day detection becomes accessible.

The eraser barely needs the loop; what the loop supplies is the certainty. A forensic evaluation submitted July 17, sixteen days before the EU transparency rules became applicable and before Anthropic publicly described its marking regime, tested three representative statistical text watermarks against ordinary meaning-preserving paraphrase, 846 valid runs. A single pass removed every detected KGW and Unigram mark. One hundred percent. SynthID-Text held on to 1.7% of its marks. The rewritten passages stayed faithful to the originals, median semantic similarity 0.84, and the tools required are, in the study’s own words, “freely available.” Claude’s mechanism is unpublished; no outside lab has measured it. But Anthropic’s own documentation discloses the same weakness in Claude’s mark — text that has been “heavily edited, paraphrased, translated, or mixed into other writing” may carry no detectable mark — and that is the same category of weakness the study just measured.

Paraphrase already removes a detected mark. What a public detector adds is the receipt that it’s gone. Verification doesn’t fight erasure — it completes it.

The dial with no safe setting

Trust Transfer Failure, machine-side: trust that dies in transit — the machine’s own

The obligation is real. The EU’s Article 50 transparency rules became applicable August 2, and the Code of Practice Anthropic signed implements them for AI-generated text — third-party detectability is part of what it signed up to. A public detector isn’t overreach. It’s the compliant move.

The failure is forensic, not cosmetic. The July study went past removal rates: it scored watermark evidence against the Daubert factors courts apply to scientific evidence and the NIST SP 800-86 forensic process. No method tested met the standard. These marks fail hardest at exactly the moments an institution would want to lean on them.

Access to that loop is a dial with no safe setting, and between its two ends everything is a price. Open the detector to everyone and it doubles as an erasure oracle. Gate it, and third parties can’t verify, which is the purpose the Code names. Every position in between limits the oracle without closing it. That dial is the transit where the machine’s own trust signal dies.

Where trust has to live

Digital Derangement Syndrome files the practitioner’s version of this as Trust Transfer Failure: a career’s worth of authority that never becomes machine-readable in the first place. The watermark earns the machine-side entry in the same family — trust that did become machine-readable and still dies in transit, a paraphrase away from never arriving. Different mechanism, same clinical outcome: a signal the next system can’t trust. A watermark lives inside word choices and dies with them. Paraphrase isn’t an attack. It’s what editing is.

Recognition that has to outlive its wording can’t be stored in the words themselves. It has to live above them — in the entity, the accumulating record, the third-party corroboration no single rewrite can reach. That is the difference between marking text and encoding authority. A paraphrase strips the first. It can’t touch the second, because there’s nothing in the sentence for it to strip.

Sources

Anthropic’s commitment to third-party detection of Claude’s marks, “as the Code requires,” with details promised in forthcoming documentation, is stated in its own help center: Anthropic; TechCrunch (August 11, 2026) corroborates the marking program. As of publication, no public detection tool has shipped. The same page carries Anthropic’s own limitation language: text “heavily edited, paraphrased, translated, or mixed into other writing” may carry no detectable mark.

The paraphrase-removal figures (846 valid runs; 100% conditional removal for KGW and Unigram, 98.3% for SynthID-Text as implemented in MarkLLM; median semantic similarity 0.84) and the Daubert and NIST SP 800-86 findings are from Tamim & Khan, “AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation,” submitted July 17, 2026: arXiv. The study tested three representative published watermark methods, not Claude’s unpublished mechanism.

The Mark Lives in the Words.

Your Authority Can’t.

Answer Engine Authority installs recognition where a paraphrase can’t reach it — entity architecture first, third-party corroboration fourth: trust that lives in who you are on the record, not in which words carried it today. What survives restatement is the only authority the Inference Era keeps. That’s a question for SIA — the Intelligence Officer, briefed on every edition
of this record the morning it releases.

Every edition, in order, from No. 001 — the record only holds together read in sequence. A new edition releases daily, 05:30 CT.

Open the Record
‹ Edition No. 041 Edition No. 043 ›