Two weeks ago I wrote about a metadata block that dies in your export pipeline — the contains-synthetic-performer keyword Amazon wants embedded in images containing photorealistic AI-generated people, which any Save for Web preset will silently discard on the way to upload.
The whole failure mode there was that you could do the work correctly and still ship a non-compliant file, because the evidence of your compliance lived in a field a tool could delete without telling you.
Last week Anthropic documented the exact inverse, and almost nobody in this industry noticed. The provenance mark on generated text doesn't live in a field. It lives in the word choices. You didn't attach it, you can't see it, no export preset removes it, and it's already on a meaningful share of the copy sitting in your Seller Central account right now.
Here's the part that matters, and it isn't the part the coverage led with: by Anthropic's own account, that mark is sparsest on factual writing — which is a near-perfect description of a product bullet.
What happened
On August 14, 2026, Anthropic published How Claude's text watermarking works on its newsroom, expanding on marking that its own help centre says applies to models launching on or after August 2, 2026, across the Claude API, Claude, Claude Code, Claude Cowork and Claude Tag, globally, with no opt-out documented. Older models are being updated. It was covered by Axios on August 12, Forbes on August 13 and TechCrunch on August 15.
The method is a version of the SynthID-Text approach Google DeepMind published in 2024. When the model is picking between words that are equally viable — Anthropic's example is "overcast" versus "grey" — instead of using arbitrary randomness it uses a key plus the preceding few words to settle which one to pick. Any individual choice looks unremarkable. Across enough text, the pattern is detectable to anyone holding the key. Anthropic holds the key and says it "will soon be offering a watermark detection API," details still being worked out.
Separately, supported image files (.png, .jpg, .svg) get signed C2PA content credentials in their metadata. The driver for all of it is the EU AI Act's transparency obligations.
Why most brand owners will read this wrong
The dumb take is "Amazon is going to detect AI copy and suppress my listings."
No. Three reasons, and none of them require optimism.
Detection requires the key. Anthropic has it. The public detector products people are already pitching don't — those work by sniffing phrasing tells, which is a completely different and much worse method. (The two tells that keep coming up are the "this isn't X, it's Y" construction and heavy use of the word quietly. I use both constantly. So does every operator writing on LinkedIn. So, I assume, does about a third of the content that has ever accused something else of being AI-generated.)
Second, Amazon has published no policy requiring you to disclose that your copy was AI-generated. I went looking for that policy on August 4 when a "label everything by August 15" claim was circulating, couldn't source it to Amazon then, and it hasn't materialised since. The image rule is real, narrow, and about photorealistic synthetic people. There is no bullet-point equivalent.
Third — and this is the sentence to hold onto — a mark indicates the text may have been processed by Claude. It says nothing about whether the text is true, original, or compliant. Anthropic states plainly that the watermark cannot distinguish "Claude wrote this" from "Claude heavily edited this," and can't tell you whether a different model wrote it. It's a processing signal, not an authorship verdict and definitely not a quality one.
The real signal is smaller and more annoying: the provenance layer moved from something you can open and inspect to something you can't.
Every governance practice I've published this year assumes an artifact. Pin the model string, because a string is a contract you can read. Build a golden set of twenty real SKUs, because you need something you can re-run. Diary the price with a re-check date, because pricing lives on a page. Add a retirement column, because shutdowns have dates. Ask your creative vendor whether their delivery process preserves XMP metadata, because metadata is a field you can open a file and check.
This one has no artifact. You cannot look at a paragraph and tell. You cannot verify it's there, and you cannot verify it's gone.
What actually changes for a $200K/mo brand
Honestly? On your P&L this quarter, close to nothing. I'd rather say that than manufacture a threat. But four things genuinely move, and one of them is more interesting than the news itself.
1. The mark is weakest exactly where your listing copy lives. Anthropic's own stated limitations include that watermarking is "sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy," and that detection works poorly on short samples.
Now describe a product bullet. Short. Factual. Constrained by dimensions, material, count, compatibility, a character ceiling and a category style guide. There is almost no room for the model to make a stylistic coin-flip, which is the only place the signal can live. The same goes for Item Highlights, attribute values, and a 75-character title.
Then describe an A+ brand story module. Longer. Discretionary. Full of adjectives where "crafted" and "engineered" were equally available.
The watermark density across your catalogue is roughly inverse to how load-bearing the copy is. The text most likely to carry a strong signal is the text least likely to be checked, and the text you'd actually be nervous about — a compliance-adjacent claim in a bullet — is the text where the signal is thinnest. That's not a loophole to exploit. It's a reason the whole detection conversation matters less to marketplace copy than to almost any other kind of writing, and nobody covering this last week said so.
2. The mark tracks how little you touched it. Anthropic says light editing probably won't remove the watermark, a complete rewrite will, and when Claude edits your text there's very little for the mark to attach to. Stack those and the mark is, roughly, an index of how much of the word selection the model did. Which means the highest-signal copy in your account is the copy that went from a prompt to a listing with no human in between — and if you've got a lot of that, the watermark is the least of the problems it's creating.
3. It's a supply-chain question, not a compliance one. You do not know which of your vendors run Claude. Your agency's copy pass. Your VA's bullet rewrite. Your listing tool's "optimise" button. A Q&A generator. A translation vendor for your EU listings — where the regulation driving this actually applies. The question "does the copy on my detail pages pass through a watermarking model" now has a factual answer, and you cannot determine it by reading the copy. You have to ask.
4. Amazon writes text on your page too. Amazon's own AI has been proposing detail-page changes and generating title and Item Highlights replacements on brand-owner listings all year, on review clocks most catalogues are too slow to hit. If provenance regimes ever get teeth, "who generated this text" is a question that also points at sentences Amazon put on your listing while nobody was looking. I don't think that's this quarter's problem. I do think it's funny that the seller is the only party in that exchange anyone is asking to account for themselves.
What I'd do this week
Add one line to the vendor question set. You already have two: do you pin your model version, and does your delivery process preserve metadata. The third is which model writes my copy. A vendor who answers with a model name and a version has thought about it. A vendor who answers with a paragraph about their commitment to responsible AI has not, and that reply is the answer.
Don't buy an AI detector. They don't have the key. They're pattern-matching phrasing tells, which means they will flag your best copywriter's work and clear a machine-generated bullet, in whichever order is most expensive for you.
Separate the two questions that keep getting merged. "Was this generated" and "is this substantiated" are different questions and only one of them gets a listing suppressed. Nothing about a watermark makes a bullet non-compliant. An unsupported "clinically tested" makes it non-compliant, and it does that whether a human, a model, or a committee wrote it. That's the guardrail worth having, and it's the one I've built into every catalogue workflow I run.
Keep the human edit pass — for quality, not for evasion. If your reaction to a provenance signal is to work out how to remove it, the problem isn't the watermark. Edit because unedited model copy argues for the wrong things and repeats claims your product can't cash. The provenance side is a coincidence.
Add a provenance column to your automation inventory. You should already have one page listing every tool with write access to your catalogue: the tool, the model string, pinned or floating, the current rate, the re-check date, the retirement date. Add one more field for whether the output is marked. It costs you ten minutes and it means the next time this comes up you're reading a file instead of guessing.
What I'd ignore
The "AI content penalty" discourse, which has been circulating in some form for two years and has never once been traced to an Amazon policy page. The unsourced "label everything" claim from a fortnight ago now has a real news story to ride on, which will make it sound better and no more true.
The EU AI Act Article 50 compliance panic, if you're a US-only seller. It's the reason this shipped. It is not a thing you have to do something about.
Anyone asking whether the watermark can be removed. The only use for that answer is evasion, and you're not in a business where that's the fight worth picking.
And the benchmark reflex. No model got better last week. A compliance obligation produced a documentation page. That's it.
Four times this year I've written about something moving underneath an operator who did nothing wrong — a model swapped silently on Friday, a price that expired without a memo, an increase cancelled in an undated note, a retirement date buried in a changelog. Every single time, the fix was the same shape: go find the artifact, write it down, put a date on it.
This one has no artifact. The only control available is knowing who's in your supply chain, which is a much older and much more boring discipline than anything in the announcement — and the one nobody's automated yet.