你用Claude写的每一段文字,正在被悄悄盖上一个戳。
Anthropic宣布,将逐步在Claude生成的文本中嵌入隐形水印。这个水印对人眼完全不可见——你读的时候感觉不到任何不同——但它可以被计算机识别。换句话说,你写的东西是不是AI写的,技术上有办法查出来。
官方说法是为了满足欧盟《人工智能法案》(EU AI Act)的透明度准则要求。简单说:监管要求AI生成的内容必须能被识别出来,不能和人类创作的内容混在一起。
这件事听起来很技术,但它的影响可能比大多数人意识到的要深远得多。
水印怎么加的?为什么你看不见?
文本隐形水印的原理,说穿了不难。常见的做法有几种:
一种是零宽字符隐写——在文字之间插入人类看不见但机器能读的零宽字符,用这些字符的排列组合来编码信息。就像在白纸上用隐形墨水写字,肉眼看不见,用特殊的灯一照就显形。
另一种是同义词替换——在不改变语义的前提下,选择特定的同义词组合来传递信息。比如"因为"和"由于"意思差不多,但选哪个词本身就可以编码数据。
还有一种是标点和空格的微妙调整——在你注意不到的地方微调空格数量、标点使用习惯,同样可以嵌入信息。
Anthropic没有公开具体用的是哪种技术,但效果是一样的:你读起来完全正常的一段文字,里面藏着只有Claude系统才能识别的"指纹"。
这个指纹能干嘛?理论上,只要拿到一段文字,Anthropic就能判断它是不是Claude生成的,甚至可能追溯到具体是哪个用户、哪个会话生成的。
监管的正当性和个人的焦虑
站在监管的角度,这个逻辑非常通顺。
AI生成的内容越来越多,越来越逼真。如果没有办法区分AI内容和人类内容,会有什么问题?假新闻泛滥、网络水军自动化、学术造假成本为零、诈骗效率指数级提升……这些都是真实存在的风险。
所以EU AI Act要求通用AI模型的输出必须可识别,这个政策出发点是好的——让AI内容显形,让人类有知情权。
但站在个人用户的角度,事情就没那么简单了。
很多人用AI写工作邮件、做报告草稿、整理会议纪要。这些内容最终都是以"人的产出"的名义提交的。现在,如果你的老板、你的客户、你的同事,有办法查出来你这段文字是AI写的——
你用AI辅助工作这件事,就不再是你自己的秘密了。
学生用AI写论文更不用说了。以前老师抓AI写作,主要靠"文风不对"这种主观判断,准确率有限。有了隐形水印之后,检测就变成了客观、精准、百分之百的事情。
"监管说的是'透明度',用户听到的是'被监控'。同一个技术,不同的角度,完全是两回事。"—— 一位AI隐私研究者
更令人担忧的是边界问题。今天水印是为了满足监管要求,那明天呢?这个能力会不会被用来做更多事?比如检测员工有没有在工作中用AI、追踪信息泄露的源头、甚至给每个用户的AI输出打上独有的身份标记?
技术一旦被部署,它的用途往往会超出最初的设计目的。这是历史反复告诉我们的教训。
每个人都要面对的选择题
隐形水印不是Anthropic一家的事。EU AI Act是欧盟的法律,任何想在欧盟运营的AI公司都得遵守。可以预见,OpenAI、Google、DeepSeek——只要做欧洲市场,最终都会加上类似的水印机制。
这意味着什么?意味着未来你从任何主流AI产品里拿到的文本,都可能带着看不见的标记。
对于普通用户,这不是一个可以选"用不用"的功能——因为它是默认开启的,而且你看不见。你能选的只有:你要不要继续用这些会给你输出打水印的AI工具?
当然,也会有对策。比如专门去掉水印的工具、本地运行的开源模型(它们的输出没有水印)、各种"AI内容洗白"的服务……监管和反监管的军备竞赛,在内容溯源这个领域又要开始新一轮了。
但更深层的问题是:当AI内容和人类内容可以被精确区分的时候,我们评判一段文字的标准,会从"写得好不好"变成"是不是人写的"吗?
如果答案是肯定的,那损失的可能不是效率,而是我们对好内容本身的定义。
明天见。
Every paragraph you write with Claude is getting quietly stamped.
Anthropic has announced it's gradually embedding invisible watermarks in Claude-generated text. These watermarks are completely invisible to the human eye - you can't tell the difference when reading - but they're machine-detectable. In other words: whether something you wrote was actually AI-generated can, technically, be found out.
The official line is that this meets the transparency requirements of the EU AI Act. Simply put: regulators are demanding that AI-generated content be identifiable, not mixed in with human creation.
This sounds like a technical detail, but its implications may be far deeper than most people realize.
How Do Watermarks Work? Why Can't You See Them?
The principle of invisible text watermarking isn't hard to explain. Common approaches:
One method is zero-width character steganography - inserting invisible zero-width characters between words, using their arrangement to encode information. Like writing with invisible ink on white paper - invisible to the naked eye, but revealed under a special light.
Another is synonym substitution - without changing meaning, choosing specific synonym combinations to convey data. "Because" and "since" mean roughly the same thing, but which word you choose can itself encode data.
And there's subtle punctuation and spacing adjustments - micro-tweaks to spacing and punctuation habits in places you'd never notice, also capable of embedding information.
Anthropic hasn't disclosed which specific technique it uses, but the effect is the same: a paragraph that reads perfectly normally contains a "fingerprint" only Claude's system can recognize.
What can this fingerprint do? In theory, given any text, Anthropic could determine whether it was generated by Claude - and possibly even trace it back to a specific user or conversation.
Regulatory Legitimacy vs. Personal Anxiety
From a regulatory perspective, the logic is straightforward.
AI-generated content keeps growing and getting more realistic. Without a way to distinguish AI from human content, what happens? Fake news floods in, bot armies automate, academic plagiarism becomes zero-cost, scam efficiency explodes exponentially - these are real risks.
So the EU AI Act requires general AI model output to be identifiable. The policy starts from a good place - making AI content visible, giving humans the right to know.
But from an individual user's perspective, it's not that simple.
Many people use AI for work emails, report drafts, meeting notes. This content is ultimately submitted as "human output." Now, if your boss, your client, your colleague could detect that this text was written by AI -
the fact that you use AI to help with work is no longer just your secret.
For students writing papers, it's even more straightforward. Before, teachers caught AI writing mainly through subjective judgments like "this style feels off" - accuracy was limited. With invisible watermarks, detection becomes objective, precise, 100%.
"Regulators call it 'transparency.' Users hear 'surveillance.' Same technology, different angles - two completely different things." - An AI Privacy Researcher
More concerning is the boundary problem. Today watermarks are for regulatory compliance - but tomorrow? Could this capability be used for more? Detecting whether employees use AI at work, tracing information leaks, even stamping each user's AI output with a unique identifier?
Once a technology is deployed, its uses tend to expand beyond the original purpose. That's a lesson history has taught us repeatedly.
A Choice Everyone Faces
Invisible watermarks aren't just an Anthropic thing. The EU AI Act is EU law - any AI company operating in Europe has to comply. We can expect OpenAI, Google, DeepSeek - anyone serving the European market will eventually add similar watermarking mechanisms.
What does that mean? It means in the future, any text you get from any mainstream AI product may carry an invisible tag.
For ordinary users, this isn't a feature you can opt into or out of - it's on by default, and you can't see it. Your choice is only: do you keep using AI tools that watermark their output?
Of course, countermeasures will emerge. Tools specifically designed to remove watermarks, locally-run open source models (their output has no watermarks), various "AI content laundering" services - the cat-and-mouse game between regulation and countermeasures starts a new round in content traceability.
But the deeper question is: when AI content and human content can be precisely distinguished, will our standard for judging a piece of writing shift from 'is it good?' to 'was it written by a human?'
If the answer is yes, what we lose might not be efficiency - it could be our very definition of good content.
See you tomorrow.
Anthropic,Claude,invisible watermark,EU AI Act,AI regulation,content traceability