Anthropic’s Watermark Could Turn Contract Terms Into Copyright-Like Control

Anthropic plans to embed invisible, machine-readable watermarks into text generated by Claude. The stated purpose is transparency and compliance with the EU AI Act—not copyright enforcement.

A watermark would not give Anthropic copyright over Claude’s output. But combined with Anthropic’s restrictions on model distillation, it could provide something almost as powerful: a technical mechanism for identifying Claude-generated material and controlling how it is used.

You own the output—but not every right to use it

Anthropic’s terms say users own Claude’s outputs. Yet Anthropic also prohibits customers from using those outputs to train competing AI models without permission.

Anthropic is not alone. OpenAI, Google and xAI have similar restrictions. Meta is an important exception: its Llama license expressly permits developers to use outputs to improve and distill other models.

However, Anthropic has taken an especially forceful public position. It recently accused DeepSeek, Moonshot and MiniMax of conducting “industrial-scale” distillation campaigns involving more than 16 million Claude exchanges and approximately 24,000 fraudulent accounts. It has also called for coordinated industry and government action against distillation.

Anthropic was notably absent from the recent “Open Weights and American AI Leadership” letter, signed by more than 270 organizations—including OpenAI, Google, Meta, Microsoft and NVIDIA. The letter described distillation as a legitimate and widely used model-development technique that should not automatically be conflated with misappropriation. Anthropic says it supports non-dangerous open-weight models, but refused to sign and continues to advocate a crackdown on industrial-scale distillation.

Violating terms is not automatically illegal

A company’s terms of service are not legislation. They become enforceable as a contract only when users receive adequate notice, agree to them and the provisions are otherwise legally valid.

Using Claude outputs for prohibited distillation could therefore be a civil breach of contract. It is not automatically copyright infringement, criminal conduct or illegal computer access.

The facts alleged by Anthropic may go further than an ordinary terms violation. Fraudulent accounts, proxies and attempts to bypass access restrictions could create additional legal exposure. But Anthropic would still have to prove its claims. Calling something a “distillation attack” does not itself establish illegality.

Anthropic also does not have to make distillation technically impossible before enforcing a valid contract. Nevertheless, a watermark could make enforcement considerably easier by helping identify Claude outputs inside another model’s training data.

Copyright law does not settle the issue

Publicly available information is not automatically free of copyright. Fair use is a case-specific defense based on the purpose of the use, the material copied, the amount used and the effect on the market.

But fair use applies to copyright infringement—not ordinarily to breach of contract. A person might have a copyright-law right to analyze material while having contractually promised the provider not to use it in that way.

That distinction allows Anthropic to say:

You own the output, but you agreed not to use it to train a competing model.

There is still an open question about people who never accepted Anthropic’s terms. If a researcher obtained publicly posted Claude outputs without using Claude, creating an account or agreeing to Anthropic’s contract, Anthropic might struggle to prevent their use. Purely AI-generated output may not be copyrightable under current U.S. law, and Anthropic assigns users whatever output rights it might possess.

The deeper double standard

Anthropic has defended its right to train AI on lawfully acquired copyrighted books. At the same time, it paid $1.5 billion to settle claims arising from approximately 500,000 allegedly pirated books. The court distinguished between training—which it found fair use under the circumstances—and acquiring and retaining pirated copies, which was not protected by fair use.

The broader asymmetry remains: AI companies learned from vast amounts of human-created work whose authors never agreed to their terms. But access to the resulting models is placed behind contracts preventing others from applying a similar learning process to the models’ outputs.

The watermark does not transfer copyright to Anthropic. The more immediate concern is that it could transform a private contractual restriction into a persistent system of downstream control.

Before such watermarks become standard, users deserve clear answers. What exactly does the mark prove? Who can detect it? Can it identify an account or transaction? How will disputed findings be challenged? And will Anthropic guarantee that watermarks will never be used to assert ownership over work its terms say belongs to users?

Transparency is valuable. But it should not quietly become infrastructure for permanent provider control.


Sources:

  • https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content
  • https://www.anthropic.com/news/detecting-and-preventing-distillation-attacks
  • https://www.anthropic.com/news/position-open-weights-models
  • https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/
  • https://www.anthropic.com/legal/commercial-terms
  • https://authorsguild.org/advocacy/artificial-intelligence/what-authors-need-to-know-about-the-anthropic-settlement/