- Home
- The Thinking Wire
- One Lab Added an Invisible Watermark. The Other Shipped the Delete Button.
One Lab Added an Invisible Watermark. The Other Shipped the Delete Button.
On August 14, 2026, Gizmodo reported that Google VP Josh Woodward had announced that users can now “decide if your image, video, and music creations made with Gemini will have visible watermarks,” a toggle rolling out everywhere “except in countries where it’s required by law to keep them.” On August 18, 404 Media reported that Anthropic had shipped a text watermark that works in the opposite spirit: invisible to readers, embedded by biasing low-stakes word choices under a hidden key, detectable by Anthropic.
In the same week, the two biggest model labs moved provenance in opposite directions. One made its mark removable at the user’s discretion. The other added a mark nobody can see and only the vendor can read. Take both moves together and a single conclusion follows: content provenance at the model layer is a vendor choice, revisable at any time, in either direction. An enterprise that built its authenticity story on top of that layer just watched the foundation become a settings page.
The delete button
Google’s toggle covers images, video, and music generated with Gemini. Visible watermarks, the one form of provenance an ordinary viewer can check without tooling, become optional. The rollout exception Woodward described is telling in its precision: visible marks stay only “where it’s required by law to keep them.” Everywhere else, removal is now a user choice.
What remains after the visible mark is gone? Per Gizmodo’s report, two invisible safeguards: C2PA metadata and SynthID. Both are weak in practice. The metadata strips easily, and commercial tools already claim to bypass SynthID. So the practical state after the toggle is: a viewer sees nothing, a platform may detect something if it invests in detection, and a motivated actor can likely defeat both layers.
We argued in the case against watermark mandates that regulators could not force durable text watermarks into existence because the technical substrate would not hold. Google’s move demonstrates a blunter version of the same conclusion: the vendor made removal a product feature, and scoped compliance to the jurisdictions that compel it.
The invisible stamp
Anthropic’s move looks like the opposite of Google’s, and in one narrow sense it is: a new mark appeared rather than disappearing. We covered the mechanism when the watermark shipped, so the short version suffices here. The system biases word choices the model considers low-stakes, patterned under a hidden key, so that Anthropic can later test whether a passage came from its models. Readers see normal prose. Writers see normal prose. Detection is Anthropic’s alone.
The criticism arrived fast. Jeff Jarvis, quoted in Jason Koebler’s 404 Media piece, condensed it into one line: “Anthropic declares words fungible, language random, choice meaningless.” Whatever you make of the literary objection, the governance objection is sharper and less debatable. A watermark that only the vendor can detect is provenance for the vendor. Your compliance team cannot query it. Your customers cannot verify it. If you need to prove that a document did or did not come from a model, you are dependent on Anthropic’s detection service existing, remaining available to you, and answering honestly, for as long as your retention obligations run.
Two moves, one fact
Read separately, the two announcements support opposite narratives. Google is abandoning provenance; Anthropic is investing in it. Read together, they establish the same fact twice: the mark on model output is set by vendor discretion, and vendor discretion moves.
Google exercised that discretion toward removal, because visible watermarks on creative output are friction its users apparently did not want. Anthropic exercised it toward a proprietary mark, because detection capability has value to the lab that holds the key. Both decisions are rational for the vendor that made them. Neither was made for you, and both can be reversed, re-scoped, or repriced without your consent. The toggle that removes visible marks today could tomorrow gate them behind a paid tier, or restore them under regulatory pressure. The invisible watermark detectable only by Anthropic could become a paid verification API, or be quietly retired.
This is the practical reversal of the mandate conversation. The policy debate assumed the open question was whether governments could compel labs to watermark. The answer arriving in August 2026 is that even a watermark the lab ships voluntarily tells you nothing durable, because the lab retains the delete button, the key, or both.
What an enterprise can no longer assume
If your organization generates content with models, three assumptions quietly died this month.
First, the assumption that model output arrives marked. With visible watermarks user-optional on Gemini media output, any pipeline, partner, or employee that touches the toggle produces unmarked synthetic content. A policy that says “AI-generated assets carry the vendor’s watermark” is now a policy about a checkbox someone else controls.
Second, the assumption that invisible marks are a fallback. The surviving layers under Google’s toggle, C2PA metadata and SynthID, strip easily or face commercial bypass tools, per the Gizmodo report. Treating them as a control is optimism, and treating them as an audit trail is negligence.
Third, the assumption that a vendor watermark serves your verification needs. Anthropic’s text mark is real and probably useful to Anthropic. It gives you no self-service way to answer the question your regulator, your counterparty, or your own incident review will actually ask: where did this content come from, and can you prove it?
The conclusion each of these points toward is the one we keep arriving at across the control problem: a guarantee you do not operate is a guarantee you do not have. Provenance has joined the list.
Build provenance where you hold the key
The control that survives vendor discretion is the one recorded in your own pipeline at generation time. Do this now, this quarter, before the next toggle ships.
Inventory every path where model-generated content leaves your organization: marketing assets, code, documents, support responses, media. For each path, record provenance at the moment of generation, in a system you operate: which model, which version, which prompt or job, which human requested it, timestamped and stored where your retention policy already lives. Where the asset format supports it, attach your own signed metadata rather than relying on the vendor’s. Then write down, explicitly, which vendor marks you currently benefit from, and label each one as a courtesy, subject to product decisions you do not control.
The labs told you their position in the same week, from both directions at once. Provenance is their feature, not your guarantee. Build yours accordingly.
This analysis synthesizes Google Opens the Gates of AI Slop Hell (Tom McKay, Gizmodo, August 2026) and Anthropic’s Text Watermarking Proves AI Companies Do Not Care at All About Writing (Jason Koebler, 404 Media, August 2026).
Victorino Group helps organizations build content provenance and AI governance controls inside their own pipelines instead of renting them from model vendors. Let’s talk.
All articles on The Thinking Wire are written with the assistance of Anthropic's Opus LLM. Each piece goes through multi-agent research to verify facts and surface contradictions, followed by human review and approval before publication. If you find any inaccurate information or wish to contact our editorial team, please reach out at editorial@victorinollc.com . About The Thinking Wire →
If this resonates, let's talk
We help companies implement AI without losing control.
Schedule a Conversation