AI Watermarking: Key Updates on New Transparency Rules

As generative artificial intelligence (AI) continues to advance, it’s becoming increasingly difficult to distinguish human-created content from AI-generated material. In turn, regulators are requiring certain AI systems to disclose where and how content is created. 

Two important examples are the European Union’s AI Act and California’s AI Transparency Act. While both of these laws address AI-generated content, neither requires businesses to use the same type of disclosure in every situation. Instead, the rules distinguish between different forms of transparency, including machine-readable markings that may not be visible to the human eye. These requirements may apply to both the provider of the AI system and the deployer, or the entity that makes the AI available to consumers.

The laws are falling into place, but how do they work in practice? For businesses developing or using generative AI, the challenge is not only whether AI-generated content should be watermarked, but how different types of media should carry that watermark. 

The EU AI Act 

Transparency requirements under Article 50 of the EU AI Act became generally applicable on August 2, 2026, with a grace to December 2, 2026, for certain products that were already on the market as of August 2, 2026. 

Among other requirements, providers of AI systems that generate synthetic text, images, audio or video must generally ensure that the output can be detected as artificially generated or manipulated. This may include machine-readable markings built into the content rather than displayed as a visible layer. 

The AI Act also creates separate disclosure requirements for certain users of AI-generated content. For example, deepfakes generally must be clearly disclosed as AI-generated or manipulated; AI-generated or manipulated text about matters of public interest may also require disclosure when it is published without human review. 

While the law provides the end goal, it does not necessarily define how to achieve it. For example, the EU AI Act was accompanied by the Guidelines on Transparency Obligations for Providers and Deployers of Certain AI Systems. These guidelines provide definitions and explain how compliance with the AI Act’s transparency obligations may be demonstrated. But still, these guidelines defer to “providers and deployers [who] can determine adequate measures themselves, while taking into account these guidelines.” In short, this means the EU AI Act sets the standard but leaves the means of meeting it to the AI provider or deployer. 

This means AI transparency can look different, both because of the media involved and because the provider or deployer can determine how best to meet these transparency standards. For example, a machine-readable watermark may help technology detect that AI was involved, while a visible or audible disclosure is meant to inform the person viewing or interacting with the content that it was AI- generated or altered. But the form and format of these transparency measures may largely be subject to the organisation’s discretion. 

The California AI Transparency Act 

California has also adopted AI-content transparency requirements through the California AI Transparency Act. Originally enacted through SB 942 and amended through AB 853, this law went into effect on August 2, 2026. 

The law generally requires providers of any “large online platform” – that is, a publicly available generative AI platform with over 2 million unique monthly visitors over the preceding 12 months – to provide tools that can help users determine whether covered image, video or audio content was created or altered by an AI system. 

The California AI Transparency Act distinguishes between two different types of disclosures: latent and manifest. A latent disclosure is built into the content, but it’s not readily visible to the average person. A manifest disclosure is one that a layperson can more easily see and understand. 

California’s requirements are also evolving. Businesses subject to the law may need to monitor legislative changes as lawmakers revisit how disclosure and detection requirements need to operate. 

What does AI watermarking look like? 

Anthropic’s recent changes to Claude provide one example of how companies may approach these requirements. 

In August 2026, Anthropic announced that the new Claude models would include machine-readable markings in response to the EU AI Act and other similar legislative requirements. For generated text, Claude uses an imperceptible watermark based on patterns in how the model selects words. According to Anthropic’s press release, the watermark is not a visible or hidden set of characters and does not identify the person or company who generated the content. 

However, these tools are far from perfect. Anthropic explains that a text watermark can disappear or weaken; they describe it as not “foolproof” if content is heavily rewritten, translated or combined with other materials. File-based provenance information can also get lost if files are converted, resaved or captured by screenshot. 

This means that businesses should not treat watermarking as a perfect way to determine whether something was created by AI. Instead, it may be one tool to provide more information about where content came from and whether AI was involved. 

Can EU rules affect U.S. businesses? 

United States companies may also feel the effects of the EU AI Act even when a particular use of an AI product occurs outside Europe. 

For a company operating in multiple countries, creating different versions of the same product for each jurisdiction can become expensive and technically complicated. A business may instead choose and decide to build one version that satisfies the strictest applicable requirements and use that version more broadly.

For example, Anthropic has said that although its Claude watermarking changes were driven by the EU AI Act, it is applying them globally rather than limiting them to European users. 

This can create a spillover, where a law passed in one jurisdiction changes how an AI product operates for users everywhere else.  Similar regulatory concepts are also appearing in U.S. state AI laws. California and other states have adopted requirements involving transparency, disclosures, and AI governance that overlap with themes found in the EU AI Act, even though the laws differ in their scope and specific requirements.

As AI regulations continue to develop across different jurisdictions, companies may consider whether maintaining different disclosure mechanisms per jurisdiction makes sense. Alternatively, companies may comply with the most stringent regulations across all markets, setting a higher standard of compliance across the board. 

What should businesses take away?

Businesses do not necessarily need to approach every type of AI generated content in the same way. However, companies developing or using generative AI may want to review how their systems identify AI generated content, and whether their disclosure practices meet the requirements that might apply to them. Some steps businesses may want to consider include:

  • Identifying what types of AI-generated content the business uses or provides to consumers, including text, images, audio and video. 
  • Determining whether applicable laws require machine-readable markings or visible disclosures.
  • Understanding how watermarks or provenance information may change if content is edited or redistributed. 
  • Checking if AI-generated content from outside vendors keeps its watermark or disclosure when the business edits, downloads, or republishes it into another product. 
  • Considering whether maintaining different product versions across jurisdictions is practical.
  • Monitoring United States, EU, and other developing AI transparency requirements and laws. 

AI watermarking is still rapidly developing both technically and legally. Businesses do not necessarily need to treat every AI-generated output the same way, but they may need to increasingly understand when AI-generated content should be identified and whether their current systems can provide that transparency. For businesses using AI-generated content in marketing, customer communications, and other business activities, understanding when and how that content must be identified can help reduce compliance risks as these rules continue to develop 

0

AI vendor management – human programming for machine learning

Machine learning and artificial intelligence (AI) have permeated the supply chain. The reasons are apparent. Low cost and efficiency are an easy sell in today’s economy, with rampant inflation in the supply chain and tight labor markets. Yet, the economic motivation for AI must be tempered by human (or human-programmed) review of AI systems. Rules are necessary to ensure that the fundamental privacy and moral rights of individuals are protected. From data input to disaster recovery, AI vendor management ensures both the protection of businesses and the broader society. In an Insight article written by Lily Li, Founder of Metaverse Law for Data Guidance, Lily discusses data minimization for AI vendors, algorithmic bias and disgorgement, considerations for AI terms and conditions, and business continuity and disaster recovery considerations for AI. Click here to continue reading.
Image of the United States Capitol Building at night.

Strengthening the U.S. Government Supply Chain: Cybersecurity under Executive Order 14028

Image Credit: Michael Jowen from Unsplash.

U.S. government agencies have a reputation for occasionally clinging on to outdated technology. Some illustrative examples include the U.S. Department of Defense (DoD) paying Microsoft $9 million to continue supporting the defunct Windows XP in 2015 and a U.S. Government Accountability Office (GAO) report from 2019 documenting multiple agencies using legacy systems with 8 to 50-year-old components. In its findings, the GAO unsurprisingly concluded that such legacy systems using outdated or unsupported software languages and hardware poses a cybersecurity risk.

In the wake of the SolarWinds, Microsoft Exchange, and Colonial Pipeline security incidents that impacted U.S. government agencies and/or U.S. critical infrastructure, President Biden issued Executive Order 14028 to update minimum cybersecurity standards for all software sold to the federal government and throughout the supply chain.

Existing Requirements under FedRAMP, DFARS, and CMMC

The new obligations arising out of Executive Order 14028 add to existing security regulations for certain government contractors and subcontractors.

The Federal Risk and Authorization Management Program (FedRAMP) oversees the safe provisioning of cloud products and services from a Cloud Service Provider (CSP) to any government agency. As part of the FedRAMP authorization process, an accredited Third-Party Assessment Organization (3PAO) assesses the CSP’s controls under NIST SP 800-53, a security framework for federal government information systems. The 3PAO also assesses additional controls above the NIST baseline that are unique to cloud computing.

Contractors who supply products or services specifically to the DoD are subject to the Defense Federal Acquisition Regulation Supplement (DFARS). The DFARS standards establish compliance with fourteen groups of cybersecurity requirements under NIST SP 800-171, meant to protect Controlled Unclassified Information (CUI).  

In November 2020, the DoD released the Cybersecurity Maturity Model Certification (CMMC) framework, which builds upon DFARS. Contractors undergo an audit by a CMMC Third Party Assessment Organization (C3PAO), which issues a certification for the contractors’ assessed cybersecurity maturity level. The certification ranges from CMMC Level 1, indicating a low, ad-hoc maturity, to CMMC Level 5, indicating a high, optimized maturity. As contractors progress further up the DoD supply chain all the way to prime contractors—those working directly with the DoD—the DoD scale requirements for those contractors to meet higher certification levels. Meeting all DFARS controls and 110 controls in NIST SP 800-171 roughly correlates to CMMC level 3.

Cybersecurity Requirements of Executive Order 14028

Read More
Cell phone with image of lock on the screen.

Reasonable Security: Implementing Appropriate Safeguards in the Remote Workplace

Photo by Franck on Unsplash

In 2020, with large portions of the global workforce abruptly sent home indefinitely, IT departments nationwide scurried to equip workers of unprepared companies to work remotely.

This presented an issue. Many businesses, particularly small businesses, barely have the minimum network defenses set up to prevent hacks and attacks in the centralized office. When suddenly everyone must become their own IT manager at home, there are even greater variances between secure practices, enforcement, and accountability.

“Reasonable Security” Requirements under CCPA/CPRA and Other Laws

Under the California Consumer Privacy Act (CCPA), the implementation of “reasonable security” is a defense against a consumer’s private right of action to sue for data breach. A consumer who suffers an unauthorized exfiltration, theft, or disclosure of personal information can only seek redress if (1) the personal information was not encrypted or redacted, or (2) the business otherwise failed its duty to implement reasonable security. See Cal. Civ. Code § 1798.150.

Theoretically, this means that a business that has implemented security measures—but nevertheless suffers a breach—may be insulated from liability if the security measures could be considered reasonable measures to protect data. Therefore, while reasonable security is not technically an affirmative obligation under the CCPA, the reduced risk of consumer liability made reasonable security a de facto requirement.

However, under the recently passed California Privacy Rights Act (CPRA), the implementation of reasonable security is now an affirmative obligation. Under revised Cal. Civ. Code § 1798.100, any business that collects a consumer’s personal information shall implement reasonable security procedures and practices to protect personal information. See our CPRA unofficial redlines.

Read More