Today's briefing
The watermark arrives before the rules do
Anthropic is marking what Claude writes and letting outsiders check for the mark. What that changes for schools, clinics and agencies — and what it doesn't.
The one that matters
Anthropic is now marking what Claude writes — and letting outsiders check for the mark
Anthropic has been embedding a watermark in the text its Claude models produce, and has published a detection service that lets third parties check whether a piece of writing carries that mark. The company did not announce it loudly; reporting surfaced it, a backlash followed, and Anthropic then put out a public explanation of why users should not be alarmed. At the same time, developers began testing how to strip or defeat the mark — which is the most useful fact in the whole story, and we will come back to it.
What this actually changes for you
Until now, the argument about whether a piece of text was written by a person or a machine was a matter of opinion, tone and gut feel. There is now a technical check for one vendor's output. That is a narrow change, but it lands in places you already have friction.
- A 600-student school: a teacher who suspects an assignment was generated has something more than a hunch — but only if the student happened to use Claude, and only if the text was not heavily rewritten afterwards.
- A 12-person marketing agency in Toronto or Gurugram: your client can run the copy you delivered through a checker. If your contract says nothing about AI use, that conversation will happen on your client's terms and at the worst possible moment.
- A 30-bed clinic: if staff draft patient letters, discharge notes or insurer correspondence with Claude, that text may be checkable by whoever receives it. That is fine if your policy is written down. It is embarrassing if it is not.
- Anyone hiring: cover letters, take-home assignments and written tests are now partially checkable. Partially.
What it does not mean, and who is overstating it
A watermark is not a lie detector and it is not proof of authorship. A positive result tells you a passage carries one vendor's mark. It does not tell you who typed the prompt, how much a human edited afterwards, or whether the person had permission to use the tool. More importantly, a negative result proves nothing at all: the writer may have used a different assistant, paraphrased the output, translated it through another language, or simply written it themselves.
Watch for three groups overselling this. Detection vendors who will now market their product as evidence rather than as a signal. Ed-tech and HR platforms that will bolt on a badge and imply certainty. And commentators claiming this ends AI-written work — when builders were already probing the mark within days, which means its durability against ordinary editing should be treated as unproven until someone independent demonstrates otherwise. Nothing in the reporting so far establishes that it survives a determined rewrite.
What a sensible owner should do this month
- Write the policy, not the purchase order. One page: where AI drafting is fine, where it must be disclosed, where it is not allowed. An afternoon of a manager's time. This is the whole job.
- Add a line to client and vendor contracts stating how AI is used in the work you deliver, and asking the same of suppliers. Costs nothing, prevents the expensive argument.
- Instruct teachers and managers never to accuse on detector output alone. Treat any flag as a reason for a conversation — an oral check, a look at draft history — not a verdict. A wrong accusation against a student or an employee costs you far more than a missed one.
- If you handle medical, legal or financial text, the watermark is the smaller question. The bigger one is what data leaves your premises and under whose terms. Ask that first.
- Buy nothing. There is no product here to procure this month.
Also worth knowing
-
OpenAI and Anthropic cut prices as Chinese rivals close the gap
The Financial Times reports the two largest Western AI vendors are competing on price under pressure from Chinese models. For a business, this is the most practically useful item on the list: the per-seat and per-use cost of the tools you already pay for is trending down. Do not sign a multi-year lock-in this quarter, and put your renewal date in the calendar with a note to renegotiate.
Financial Times ↗ -
Microsoft folds its two Copilot apps into one, and quietly drops some features
Personal and work accounts are being moved into a single Microsoft Copilot app, and as part of the same tidy-up Microsoft has cut a handful of features and retired its Mico assistant character. If your staff use both a personal and a work Microsoft account, expect a round of confusion and check that work documents stay inside the work account. Budget an hour of IT time, not a project.
Unite.AI ↗ -
Another strong open-weight coding model lands from a Chinese lab
GLM-5.3 drew heavy developer attention as a frontier-level coding model, with its release notes claiming emergent cyber capabilities — the material available says little more than that. For a non-technical owner, the model name does not matter; what matters is that capable open models keep arriving, which is what is forcing the price cuts above. Ask your software vendor whether they have an alternative to their current API provider, and what it would save you.
Hacker News ↗ -
Google shows a way to run AI on your data without the provider reading it
Homomorphic encryption lets a computation run on encrypted data without ever decrypting it, and Google says it is making this practical for AI workloads. If it works at reasonable cost, it is the eventual answer for clinics, accountants and law firms who cannot send client records to a third party. Nothing to buy today — but this is the question worth putting to your software vendors at next year's renewal.
Hacker News ↗ -
Samsung reportedly cut a month of chip verification to two days using Claude Code
This is a single company's reported claim about one narrow, highly structured engineering task, so treat the numbers as marketing until someone independent repeats them. The transferable lesson is not that AI is fifteen times faster at everything; it is that checking and verification work — going through a large set of cases against known rules — compresses much better than creative or judgement work. Look at where your business does that kind of grinding cross-check.
Tech My Money ↗ -
A Mac screen-sharing flaw is being exploited right now — patch this week
Ars Technica reports a vulnerability that lets a remote attacker log into a Mac without a password via screen sharing, and it is under active exploitation. This has nothing to do with AI and is easily the most urgent item here for any business with Macs in the office. Update every Mac now, and turn off Screen Sharing and Remote Management on machines that do not need them.
Ars Technica ↗ -
Microsoft switched off Copilot in Outlook Classic by accident
Microsoft has confirmed the removal was a mistake rather than a decision, which is its own kind of warning. If any step in your workflow depends on a vendor's button being there tomorrow, you do not own that step. Keep a manual fallback for anything a customer or regulator is waiting on.
Windows Latest ↗
How this briefing is put together
Every morning we read the day's AI announcements and reporting from the companies themselves and from the technology press, then pick the handful that actually change something for a working business. The analysis is ours and it is written for owners and managers, not engineers. Every story links to its original source above — read them, and disagree with us where we've got it wrong.