[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"article-anthropic-watermark-copy-paste-dev-workflow-en":3,"article-related-anthropic-watermark-copy-paste-dev-workflow-en":29,"series-research-e4223a79-b705-4139-bd25-136f6115c851":76},{"id":4,"slug":5,"title":6,"content":7,"summary":8,"source":9,"source_url":10,"author":11,"image_url":12,"cover_image":12,"category":13,"language":14,"translated_content":11,"related_article_id":15,"keywords":16,"key_takeaways":22,"views":26,"created_at":27,"published_at":28,"topic_cluster_id":11},"e4223a79-b705-4139-bd25-136f6115c851","anthropic-watermark-copy-paste-dev-workflow-en","Anthropic's watermark fails the real dev workflow","\u003Cp data-speakable=\"summary\">\u003Ca href=\"\u002Ftag\u002Fanthropic\">Anthropic\u003C\u002Fa>’s \u003Ca href=\"\u002Ftag\u002Fclaude\">Claude\u003C\u002Fa> watermark survives copy-paste, but it breaks once code moves through real \u003Ca href=\"\u002Ftag\u002Fdeveloper-tools\">developer tools\u003C\u002Fa> and workflows.\u003C\u002Fp>\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.anthropic.com\" target=\"_blank\" rel=\"noopener\">Anthropic\u003C\u002Fa> has been testing a text watermark for \u003Ca href=\"https:\u002F\u002Fclaude.ai\" target=\"_blank\" rel=\"noopener\">Claude\u003C\u002Fa> outputs, and the basic idea is simple: make machine-generated text easier to identify after it gets copied around. The catch is that developer work rarely stays in one text box for long. Once code passes through editors, formatters, terminals, and build tools, the signal gets much harder to trust.\u003C\u002Fp>\u003Cp>The New Stack’s report points to a familiar problem in \u003Ca href=\"\u002Ftag\u002Fai-infrastructure\">AI infrastructure\u003C\u002Fa>: controls that look good in a demo often fail when they hit actual engineering workflows. That matters more now because teams are using AI assistants to write code, review patches, and generate snippets that get pasted into everything from pull requests to CI jobs.\u003C\u002Fp>\u003Ctable>\u003Cthead>\u003Ctr>\u003Cth>Item\u003C\u002Fth>\u003Cth>What the article says\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd>Company\u003C\u002Ftd>\u003Ctd>Anthropic\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Product\u003C\u002Ftd>\u003Ctd>Claude\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Core claim\u003C\u002Ftd>\u003Ctd>The watermark survives copy-paste\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Weak point\u003C\u002Ftd>\u003Ctd>Real developer workflows\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd>Publication\u003C\u002Ftd>\u003Ctd>The New Stack\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>Copy-paste is the easy test, not the real one\u003C\u002Fh2>\u003Cp>Watermarking text sounds straightforward until you think about how developers actually work. A snippet may start in a chat window, move into an IDE, get reformatted by a linter, then land in a shell command or a \u003Ca href=\"\u002Ftag\u002Fcode-review\">code review\u003C\u002Fa> comment. Each step can alter the text enough to weaken any hidden marker.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786775577462-u0zb.png\" alt=\"Anthropic's watermark fails the real dev workflow\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>That is why this story matters beyond Anthropic. If a watermark only survives the first hop, it is more of a lab demo than a practical control. The real question is whether a marker can survive the messy path from generation to shipping code.\u003C\u002Fp>\u003Cp>There is also a trust issue. Developers need to know whether a warning is reliable before they act on it. If a watermark is easy to strip by normal editing, then it may create false confidence for security teams and annoyance for engineers.\u003C\u002Fp>\u003Cul>\u003Cli>Text can be copied into IDEs like \u003Ca href=\"https:\u002F\u002Fcode.visualstudio.com\" target=\"_blank\" rel=\"noopener\">Visual Studio Code\u003C\u002Fa> and reformatted immediately.\u003C\u002Fli>\u003Cli>Code often passes through \u003Ca href=\"https:\u002F\u002Fprettier.io\" target=\"_blank\" rel=\"noopener\">Prettier\u003C\u002Fa>, linters, and build steps that rewrite spacing and punctuation.\u003C\u002Fli>\u003Cli>AI output can also move through \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Ffeatures\u002Fcopilot\" target=\"_blank\" rel=\"noopener\">GitHub Copilot\u003C\u002Fa>-style workflows where provenance gets blurred fast.\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>Verification matters more than branding\u003C\u002Fh2>\u003Cp>The deeper issue is not whether a watermark exists. It is whether anyone can depend on it during the last mile of software delivery. A marker that survives a copy-paste test but fails after a formatter or a diff tool has limited value for teams trying to track where code came from.\u003C\u002Fp>\u003Cp>That is where the security angle gets interesting. AI-generated code already raises questions about licensing, ownership, and review discipline. If a watermark cannot survive the same tools developers use every day, it will not help much in audits or incident response.\u003C\u002Fp>\u003Cblockquote>“A watermark is only useful if it survives the transformations that happen in real workflows,” said \u003Ca href=\"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc4086\" target=\"_blank\" rel=\"noopener\">security researcher\u003C\u002Fa> and cryptography author Bruce Schneier in a long-running discussion about weak signals and trust systems.\u003C\u002Fblockquote>\u003Cp>Schneier’s point maps cleanly onto this problem: detection systems are only as good as their weakest transformation step. For code, that step is usually not the chat window. It is the chain of tools between the AI and the repository.\u003C\u002Fp>\u003Cp>Anthropic is trying to solve a real pain point, but the bar for success in software is high. A marker must survive copy-paste, survive routine editing, and still tell a useful story after code has been massaged by humans and tools.\u003C\u002Fp>\u003Ch2>Other approaches already show the trade-offs\u003C\u002Fh2>\u003Cp>Watermarks are attractive because they are cheap to deploy and easy to explain. But they are also brittle when compared with stronger provenance systems. Signed artifacts, commit metadata, and policy checks give teams more context than a hidden text pattern ever will.\u003C\u002Fp>\n\u003Cfigure class=\"my-6\">\u003Cimg src=\"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786775572066-xbm2.png\" alt=\"Anthropic's watermark fails the real dev workflow\" class=\"rounded-xl w-full\" loading=\"lazy\" \u002F>\u003C\u002Ffigure>\n\u003Cp>That trade-off shows up in the broader AI tooling stack too. Developers want lightweight controls, but security teams want evidence that holds up under inspection. The more a system depends on invisible markers, the more it depends on users not changing the text in ordinary ways.\u003C\u002Fp>\u003Cul>\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fopenai\u002Fcodex\" target=\"_blank\" rel=\"noopener\">OpenAI Codex\u003C\u002Fa> and similar coding tools focus on generation, not provenance.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.slsa.dev\" target=\"_blank\" rel=\"noopener\">SLSA\u003C\u002Fa> focuses on software supply-chain integrity with verifiable build steps.\u003C\u002Fli>\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.sigstore.dev\" target=\"_blank\" rel=\"noopener\">Sigstore\u003C\u002Fa> gives teams cryptographic signing for artifacts and releases.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>That comparison is the real lesson here. Watermarks may help with casual detection, but software teams usually need something stronger when the goal is accountability. If Anthropic wants this idea to matter in production, it has to survive the exact tools developers use to clean, rewrite, and ship code.\u003C\u002Fp>\u003Ch2>The practical takeaway for teams using Claude\u003C\u002Fh2>\u003Cp>For now, the safest assumption is that a text watermark is a hint, not proof. Teams using Claude or any other coding assistant should treat provenance as a separate problem and use signing, review, and policy checks to back it up.\u003C\u002Fp>\u003Cp>If the watermark story pushes vendors to think harder about how AI output moves through real pipelines, that is useful. But the next test is obvious: can the marker survive formatting, refactoring, and editor round-trips without losing meaning?\u003C\u002Fp>\u003Cp>My bet is that the winning solution will combine detection with cryptographic provenance, because plain-text tricks will keep breaking the moment they meet a real developer workflow.\u003C\u002Fp>","Anthropic’s Claude watermark survives copy-paste, but it breaks once code moves through real developer tools and workflows.","thenewstack.io","https:\u002F\u002Fthenewstack.io\u002Fanthropic-claude-text-watermark\u002F",null,"https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786775577462-u0zb.png","research","en","a4b2608a-12d1-4e01-b1d7-9d5d05fd1515",[17,18,19,20,21],"Anthropic","Claude","watermarking","AI code provenance","developer workflow",[23,24,25],"Copy-paste is an easy test; real dev tools are the hard part.","Text watermarks are weak compared with signed provenance systems.","Teams should treat AI output provenance as a separate security problem.",1,"2026-08-15T06:32:25.82685+00:00","2026-08-15T06:32:25.819+00:00",{"tags":30,"relatedLang":35,"relatedPosts":39},[31,33],{"name":17,"slug":32},"anthropic",{"name":18,"slug":34},"claude",{"id":15,"slug":36,"title":37,"language":38},"anthropic-watermark-copy-paste-dev-workflow-zh","Anthropic 水印在真實開發流程失靈","zh",[40,46,52,58,64,70],{"id":41,"slug":42,"title":43,"cover_image":44,"image_url":44,"created_at":45,"category":13},"a9281570-db5d-4f07-82e5-5546cd022691","humantracker-human-aligned-motion-tracking-benchmark-en","HumanTracker fixes humanoid motion eval blind spots","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786690977850-fb9v.png","2026-08-14T07:02:31.016013+00:00",{"id":47,"slug":48,"title":49,"cover_image":50,"image_url":50,"created_at":51,"category":13},"6b0b3b1a-f397-44d3-ad83-207b4e87d877","omni-scientist-full-stack-ai-science-en","OmniScientist aims for full-stack AI science","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786689180533-adlk.png","2026-08-14T06:32:31.952472+00:00",{"id":53,"slug":54,"title":55,"cover_image":56,"image_url":56,"created_at":57,"category":13},"62360ad1-f133-491c-9389-966b8d532d46","autodesign-meta-harness-optimization-posters-en","AutoDesign learns better poster-making harnesses","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786687374399-4oto.png","2026-08-14T06:02:27.082839+00:00",{"id":59,"slug":60,"title":61,"cover_image":62,"image_url":62,"created_at":63,"category":13},"5a953549-e09c-43e6-856c-63c394e85997","test-time-harnesses-weak-model-transfer-en","Test-Time Harnesses Transfer Skills Without Retraining","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786604571709-b71l.png","2026-08-13T07:02:25.968754+00:00",{"id":65,"slug":66,"title":67,"cover_image":68,"image_url":68,"created_at":69,"category":13},"84526e03-6caf-4b7e-a910-64f2b712da66","dreamfly-aerial-vln-memory-planning-en","DreamFly improves aerial VLN with memory and planning","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786602779859-brjh.png","2026-08-13T06:32:24.41046+00:00",{"id":71,"slug":72,"title":73,"cover_image":74,"image_url":74,"created_at":75,"category":13},"84e73ffd-ac52-4e86-88cc-abb15eeb9c5e","ava-encoder-agent-native-video-representation-en","AVA-Encoder turns films into editable knowledge graphs","https:\u002F\u002Fxxdpdyhzhpamafnrdkyq.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Fcovers\u002Finline-1786600972460-6yms.png","2026-08-13T06:02:22.174937+00:00",[77,82,87,92,97,102,107,112,117,122],{"id":78,"slug":79,"title":80,"created_at":81},"a2715e72-1fe8-41b3-abb1-d0cf1f710189","ai-predictions-2026-big-changes-en","AI Predictions for 2026: Brace for Big Changes","2026-03-26T01:25:07.788356+00:00",{"id":83,"slug":84,"title":85,"created_at":86},"8404bd7b-4c2f-4109-9ec4-baf29d88af2b","ml-papers-of-the-week-github-research-desk-en","ML Papers of the Week Turns GitHub Into a Research Desk","2026-03-27T01:11:39.480259+00:00",{"id":88,"slug":89,"title":90,"created_at":91},"87897a94-8065-4464-a016-1f23e89e17cc","ai-ml-conferences-to-watch-in-2026-en","AI\u002FML Conferences to Watch in 2026","2026-03-27T01:51:54.184108+00:00",{"id":93,"slug":94,"title":95,"created_at":96},"6f1987cf-25f3-47a4-b3e6-db0997695be8","openclaw-agents-manipulated-self-sabotage-en","OpenClaw Agents Can Be Manipulated Into Failure","2026-03-28T03:03:18.899465+00:00",{"id":98,"slug":99,"title":100,"created_at":101},"a53571ad-735a-4178-9f93-cb09b699d99c","vega-driving-language-instructions-en","Vega: Driving with Natural Language Instructions","2026-03-28T14:54:04.698882+00:00",{"id":103,"slug":104,"title":105,"created_at":106},"a34581d6-f36e-46da-88bb-582fb3e7425c","personalizing-autonomous-driving-styles-en","Drive My Way: Personalizing Autonomous Driving Styles","2026-03-28T14:54:26.148181+00:00",{"id":108,"slug":109,"title":110,"created_at":111},"2bc1ad7f-26ce-4f02-9885-803b35fd229d","training-knowledge-bases-writeback-rag-en","Training Knowledge Bases with WriteBack-RAG","2026-03-28T14:54:45.643433+00:00",{"id":113,"slug":114,"title":115,"created_at":116},"71adc507-3c54-4605-bbe2-c966acd6187e","packforcing-long-video-generation-en","PackForcing: Efficient Long-Video Generation Method","2026-03-28T14:55:02.646943+00:00",{"id":118,"slug":119,"title":120,"created_at":121},"675942ef-b9ec-4c5f-a997-381250b6eacb","pixelsmile-facial-expression-editing-en","PixelSmile Framework Enhances Facial Expression Editing","2026-03-28T14:55:20.633463+00:00",{"id":123,"slug":124,"title":125,"created_at":126},"6954fa2b-8b66-4839-884b-e46f89fa1bc3","adaptive-block-scaled-data-types-en","IF4: Smarter 4-Bit Quantization That Adapts to Your Data","2026-03-31T06:00:36.65963+00:00"]