Dear Anthropic, We Need To Talk About The Watermark Because It Is More DangerousFor Your Users Than You Assessed

By Comms for A Cause

First, a disclaimer: This article is not about whether AI is good or bad. That is a real and important conversation, and one I engage with regularly, but it is not the conversation today. Today's conversation is narrower and more urgent. AI exists, it is being used by hundreds of millions of people across the world including in some of the most politically hostile environments on earth, and something that changed on August 2 has created a specific, documentable safety risk for the most vulnerable of those users that is not yet being discussed clearly. 

I amClaudeuser. I am writing this because I believeAnthropicneeds to hear it, and because I believe they have the capacity to act on it if they do. 

What This Is Actually About 

Someone, somewhere in the world, is using Claude right now to draft a document related to their work on abortion access in a jurisdiction where abortion is criminalized. Someone is using Claude right now to help format an advocacy report in a country where their existence as a queer person carries a prison sentence, or a death sentence. Someone is using it to find language for a letter they need to write, alone, without an organization behind them, in a place where the state is the primary threat to their safety. 

That document now carries an invisible, machine-readable watermark. The watermark travels when the text is copied and pasted. It may persist through editing. The person who made it does not know it is there, was not asked, and in a compelled disclosure scenario, it creates a technical thread connecting that document to a Claude account, and that account to a person. 

That is the concern. Everything that follows is my call in to Anthropic to protect that someone. What Changed on August 2 

On August 11, 2026, Anthropic confirmed that all Claude models launched on or after August 2, 2026 embed an invisible machine-readable watermark directly into generated text. The regulatory trigger was Article 50 of the EU AI Act, which became enforceable on August 2 and requires providers of generative AI systems to embed machine-readable marks in outputs so that downstream users, platforms, and regulators can identify AI-generated content. 

Anthropic chose to apply this globally, not only in the EU. Their own help center states: "Marking will apply to output from supported models wherever Claude is offered, worldwide" and "Claude markings cover output from supported models everywhere you use Claude."

The principle behind watermarking is legitimate. Transparency about AI-generated content matters. This article does not argue otherwise. What it argues is that a sound principle, applied without examining who bears its costs, can produce structural harm that nobody intended. The EU regulation was designed to give consumers a right. Applying it globally without the rights framework that was supposed to accompany it gives states a tool. 

The Scale of Use That Makes This Urgent 

Claude is used across 150 countries, per Anthropic's own Economic Index. 92% of nonprofits use AI tools in 2026, per the Virtuous Nonprofit AI Adoption Report, with civil society organizations among the most active users for drafting documents, translating materials, formatting reports, and writing communications, often without formal AI policies governing that use. The communities using these tools are not abstract. They are organizations and individuals working on abortion access, LGBTQI+ rights, environmental defense, and political dissent across every region of the world, including in jurisdictions where that work is criminalized. 

The Legal Architecture That Makes This Dangerous 

Anthropic is a US company. Under the Clarifying Lawful Overseas Use of Data Act, the CLOUD Act, US law enforcement can compel US-based technology companies to produce data regardless of where that data is stored globally. The Act shifts jurisdiction from where data sits to who controls it. Foreign governments with executive agreements under the CLOUD Act can also request data directly from US providers. 

This is not theoretical. Between 2014 and early 2025, Google, Apple, and Meta disclosed data from more than 3.5 million user accounts to US authorities. In the first half of 2025 alone, these three companies disclosed data from more than 282,000 accounts, more than 1,500 accounts per day, per research published by Proton. Government requests for social media user data have increased 770% over the past decade. As Proton's COO, Raphael Auphanstated: "All that's required for the government to find out just about everything it could ever need is a request message to Big Tech in California." 

What the watermark creates inside this legal architecture is something that did not exist before August 2, a technical mechanism for connecting a document to a Claude account without needing to access the account itself. 

Before August 2, a document existed. A Claude account existed. Connecting one to the other required something. Now it requires less. A watermark detection tool applied to a document found in the course of surveilling someone's communications creates a thread. That thread leads to an account. That account leads to a person. 

Who Governments Are Already Targeting, and How 

This is not a hypothetical risk being projected onto a future threat landscape. The pattern of governments using digital evidence to prosecute activists, LGBTQI+ people, and dissidents is documented, current, and expanding.

Human Rights Watchdocumented 45 cases of arbitrary arrest involving 40 LGBTQI+ people targeted through their online activity across four countries in the MENA region, Egypt, Jordan, Lebanon, and Tunisia. In every instance of arrest, security forces searched people's phones by force or under threat of violence. The evidence used to prosecute them was drawn directly from their digital activity, including social media posts, photos, private messages. Cybercrime laws across the region explicitly empower authorities to obtain user data from telecommunications firms and social media platforms, and have been used to monitor and punish online content deemed to threaten family values, with LGBTQI+ individuals as primary targets. HRW's documentation shows that security forces use social media platforms to entrap LGBTQI+ people, gather digital evidence, and prosecute them through tactics including creating fake profiles, monitoring public posts, and using illegitimately obtained photos and chat logs as criminal evidence. 

In East Africa, Uganda's Constitutional Court upheld its Anti-Homosexuality Act in April 2024. Since then, Amnesty International has documented a systematic pattern of authorities using online activity as the basis for arbitrary arrest, extortion, and prosecution, finding that online targeting consistently produced offline consequences including arbitrary arrest, torture, forced eviction, and dismissal from employment. Uganda has a documented history of legislation designed to criminalize the sharing of information prohibited under national law through digital channels, illustrating the broader pattern of legal infrastructure being constructed to enable digital prosecution of identity and advocacy. 

In Southeast Asia, political and religious leaders have used anti-LGBTQI+ sentiment from 2016 onwards to justify expanded surveillance and censorship, filtering internet content, conducting raids on private gatherings, and increasing monitoring of social media, documented by Human Rights Watch, Outright International, and regional digital rights organizations including SAFEnet. 

In Eastern Europe, Georgia's ruling party passed a law on transparency of foreign influence in May 2024, which took effect in August 2024, compelling civil society organizations and online media receiving foreign funding to register with the government. The law has been used as an instrument of surveillance and suppression against civil society, journalists, and human rights defenders, and represents a documented pattern of legislation designed to make visible, and therefore vulnerable, the networks through which dissent and advocacy operate. 

In South Asia, the world's most populous democracy passed a digital personal data protection act in 2023, with existing legal frameworks enabling state access to user data held by technology companies operating within the country. Civil society organizations working on LGBTQI+ rights, abortion access, and political dissent operate under active surveillance in multiple states. 

In West Africa, four countries passed or significantly strengthened anti-homosexuality laws between 2024 and 2026. 

In the United States, the Department of Homeland Security issued administrative subpoenas to Google, Meta, Reddit, and Discord seeking the identities behind accounts criticizing immigration enforcement operations, without judicial approval, in early 2026. Legal experts described these as mechanisms for compelling disclosure even in the absence of suspicion of a crime. Under Texas's Senate Bill 8 and similar abortion-related legislation in multiple states, civil liability can be imposed on anyone who aids or abets an abortion, creating a legal framework through which a compelled disclosure request to an AI company could connect a document to an account, and an account to a person seeking or facilitating abortion access.

The Specific Mechanism 

Consider what this legal and technical landscape means in practice, now that the watermark is live. 

An organization working on abortion access in a criminalized jurisdiction employs staff in multiple countries. One employee uses Claude to help draft a section of an internal protocol. That document carries a Claude watermark. It travels through the organization's communications. At some point, a fragment of it surfaces in a context accessible to a hostile legal actor. A compelled disclosure request is issued to Anthropic. The account is identified. The organization is identified. Depending on what account data includes, the individuals served by that organization may be identifiable. 

A LGBTQI+ activist in a criminalized jurisdiction uses Claude to help draft organizing materials. The document carries a watermark. Authorities monitoring the activist's communications find the document. A data request is made to Anthropic through existing legal channels. The account is identified. 

A person, acting entirely in individual capacity, uses Claude to find language for a letter about their rights, their healthcare, their safety. They have no organizational affiliation. They have no IT department. They trusted the tool. The document they made carries a machine-readable trace connecting it to their account. 

None of this requires a government to break into Anthropic's systems. It requires a legal request. Those legal requests are already happening at scale, across multiple technology companies, at a documented rate of more than 1,500 accounts per day. 

The Part That Cannot Be Solved by Better Organizational Policy 

The standard response to digital security concerns in civil society is to recommend better organizational practices. Implement AI use policies. Train staff on data hygiene. These recommendations are appropriate for organizations and worth making. 

They do not address the population most at risk here, which is not organizational. It is individual. 

The person seeking abortion information in a criminalized jurisdiction is not an employee with an IT department. They are a person alone with a browser, using a tool they trust, believing they are not being watched. A person in a criminalized jurisdiction who accessed Claude through a VPN specifically to avoid detection is still producing watermarked documents. The technical precaution they took does not solve the watermark problem. The watermark is at the model level. It follows the output regardless of how the access was obscured. 

Individual users will continue to use Claude regardless of what organizational AI policies say. The most vulnerable users are often precisely those operating outside organizational structures, with no protection under the current architecture. 

The Asymmetry 

The EU AI Act's transparency obligations were designed to give European consumers the right to know when they are consuming AI-generated content. That right exists within a legal framework

that also gives European citizens data protection rights, the right to object to processing, and access to regulatory enforcement mechanisms. 

The watermark has been applied globally. The rights framework has not. 

A user in the EU who discovers their content has been watermarked has legal recourse. A user in a criminalized jurisdiction does not. The mechanism designed to protect consumers in one jurisdiction has been deployed universally. The protections that were supposed to accompany it have not traveled with it. 

The communities with the least legal protection are the ones carrying the most risk from the watermark. That is the structural problem this letter is asking Anthropic to address. 

What This Letter Is Asking 

Three things. 

First: restrict the global application of the watermark to jurisdictions where the accompanying legal rights framework exists to protect users from the specific compelled disclosure vulnerability the watermark creates. Outside those jurisdictions, pause the global rollout until a civil society protection framework that addresses this risk is in place. 

Second: publish a clear, plain-language disclosure of the watermark's legal implications for users in criminalized contexts. Users in jurisdictions where their identity, their advocacy, or their access to healthcare is criminalized deserve to know what the watermark means for them specifically, in their specific legal context, before they use the tool. Right now, they don't know. 

Third: consult with civil society organizations working in criminalized contexts before finalizing the global watermark architecture. The people who understand this risk most precisely are the ones who work with the communities most exposed to it. They were not in the room when this decision was made. They need to be in the next one. 

A Note on Framing 

The mainstream backlash to Anthropic's watermark announcement has come from users frustrated that their AI use will be detectable. Writers, communications professionals, people who use Claude to clean up their work. That is a legitimate concern. 

It is not the urgent one. 

The urgent concern is not about professional credibility or embarrassment. It is about people whose physical safety depends on not being found. People who are using a tool that now, without their knowledge, leaves a machine-readable trace connecting their document to their account, their account to their identity, and their identity to a legal system that considers their existence, their work, or their healthcare a crime. 

The window is open right now. Documents are being produced with the watermark today, in every country where Claude is accessible, including jurisdictions where those documents could be used to identify and prosecute the people who made them.

That is the conversation this letter is asking Anthropic to have. Not because they are the villain of this story. Because they are the ones who can change it. 

Primary sources 

1. AnthropicHelp Center, "How Claude marks AI-generated content" (August 11, 2026);
2. TechCrunch,"Anthropic says it will watermark text generated by its AI models" (August 11,2026);
3. EU AI Act Article 50;
4. Clarifying Lawful Overseas Use of Data Act (CLOUD Act), 2018;
5. Proton, State Of Surveillance "Big Tech Handed 6.7 Million User Accounts to theGovernment" (April 2026);
6. , "'All This Terror Because of a Photo': Digital Targeting and Its Offline Consequences forLGBT People in the Middle East and North Africa" (February 2023);
7. Human Rights Watch, "Questions and Answers: Facebook, Instagram, and Digital Targetingof LGBT People in MENA" (January 23, 2024);
8. Amnesty International,"Uganda: Criminalization Shrinks Online Civic Space for LGBTQPeople" (October 2024);
9. Human Rights Watch, World Report 2025: Uganda; Human Rights Watch, "Ghana:President Should Veto Anti-LGBT Bill" (March 2024);
10. Human Rights Watch, "Ghana's Parliament Revives Dangerous Anti-LGBT Bill" (March2026);
11. , Ghana country profile;
12. Freedom House,"Freedom on the Net 2025";
13. Human Rights Watch, Outright International , SAFEnet - Southeast Asia Freedom ofExpression Networkdocumentation on Southeast Asia digital rights; 
14. Foreign Affairs Magazine,"The Global Threat to LGBTQ Rights" (July 2025);15. ILGA World,Pride Month 2026 LGBTI Maps and Data (2026);
16. 76 Crimes, "Homosexuality is now illegal in 66 nations" (June 2026);
17. Virtuous,2026 Nonprofit AI Adoption Report;
18. Anthropic Economic Index (March 2026);
19. The Washington Post, New York Times reporting on DHS administrative subpoenas (January-March 2026)

Next
Next

Self-Censorship in the Balkans: How Social Structures Shape Online Violence and Political Participation