AI watermarking is not AI governance
AI watermarking is useful. It is also easy to mistake it for something much bigger than it is.
Anthropic has announced that newer Claude models will add machine-readable marking to AI-generated content, including embedded watermarks in text. The move is linked to the European Union's transparency requirements for AI-generated content. You can read Anthropic's explanation of how Claude's text watermark works for the technical detail.
That gives organisations a way to ask whether AI was probably involved in producing a piece of content. It does not tell them who wrote the instruction, who checked the result, who approved it, or who is responsible when the output causes harm.
What a watermark can tell you
A watermark can provide a signal about provenance. In the right setting, that may help a school, publisher, regulator or business identify content that was produced with the help of an AI system. It can support audits, transparency and compliance work.
That signal still has limits. A watermark is not a complete chain of custody. It does not explain the purpose for which the system was used, whether the user supplied confidential information, whether a person reviewed the answer, or whether the final decision was sensible.
This is where many AI conversations go wrong. The organisation buys a detection or labelling capability and then treats the presence of that capability as evidence that the workflow is controlled.
What governance has to decide
AI governance is the set of decisions that determines how a system may be used and who remains accountable for the outcome.
The NIST AI Risk Management Framework puts trustworthiness into the design, development, use and evaluation of an AI system. That is a much broader responsibility than detecting whether an output came from a model.
Before an AI workflow goes live, leaders need clear answers to five questions:
- Where is AI allowed, and where is it prohibited?
- What must a person check before an output becomes an action?
- What information may be entered into the system?
- Who owns the final decision and the consequences?
- What happens when the system is uncertain, biased or wrong?
If those questions have no named owner, a watermark will not solve the problem. It may tell you that a system was involved, but it cannot tell you whether the business designed a responsible process around that system.
The control that most businesses miss
The control most businesses miss is not another piece of software. It is a visible handover of responsibility.
Someone must own the use case. Someone must know what good output looks like. Someone must have the authority to stop the workflow when the result does not meet the standard. Those responsibilities should be written down before the tool is deployed, not reconstructed after a failure.
That also means keeping a useful record. Store what the system produced, what a person changed, what decision was made and why the decision was accepted. The exact record will depend on the risk of the use case. A draft marketing caption does not need the same control as a credit recommendation, employment decision or customer safety instruction.
Detection is a signal. Governance is a decision.
Watermarks, logs and content credentials all have a place. They can provide evidence after the fact and make some forms of transparency easier. They are supporting controls, though. They do not replace boundaries, review rules or accountability.
The practical sequence is straightforward:
- Define the use case and its boundaries.
- Name the human owner.
- Set the review and escalation rules.
- Record the system output and the human decision.
- Test the workflow against realistic failure cases.
Only then should you ask how watermarks and other provenance tools can strengthen the control environment.
The organisations that benefit from AI will not be the ones with the cleverest detection alone. They will be the ones that make responsibility visible before deployment.
If AI-generated content appeared in one of your high-stakes workflows tomorrow, would your team know who must review it, what they must check and who owns the consequence?










