
Anthropic, the company behind Claude, announced it will embed invisible, machine-readable watermarks into all text generated by its newer models. The watermarks survive copy and paste, and even light editing. Anthropic is also publishing the detection tools — meaning any organization can scan its own documents to check whether Claude generated them.
The stated reason is compliance with the EU AI Act's transparency rules (Article 50), which require AI-generated content to be machine-detectable. But here's the detail that matters: the watermarks aren't limited to Europe. They apply to every piece of Claude-generated text, everywhere.
Why RIAs should care:
If anyone at your firm is using Claude — to draft client emails, summarize meeting notes, prepare investment commentary, or support compliance documentation — that output now carries a mark. It's invisible to the human eye, but readable by software.
For the first time, there's a technical mechanism to detect whether AI touched a document. That changes the conversation from "we trust our people not to misuse AI" to "we can actually verify it."
The limits matter as much as the capability:
Before anyone panics or celebrates, the caveats are important:
- One vendor only. This covers Claude. Text from ChatGPT, Gemini, Copilot, or any open-source model carries no watermark at all. If your team is using multiple tools — or tools you don't even know about — watermarking only catches a fraction.
- Not proof of authorship. A watermark means Claude was involved, but not how. The AI might have written the entire document, or it might have edited two sentences a human wrote. The mark doesn't distinguish between the two.
- No watermark doesn't mean no AI. Heavy editing degrades the signal. Short passages may not carry enough data to detect. And every other AI vendor's output is completely unmarked.
- Partial detection is dangerous. Scanning your documents and finding no Claude watermarks doesn't mean your firm is AI-free. It might just mean your team is using a different tool.
Shadow AI is the real risk:
"Shadow AI" is the AI equivalent of shadow IT — employees using AI tools that the firm hasn't approved, evaluated, or even identified. No policy. No training. No audit trail.
For three years, an employee pasting AI-generated text into a client deliverable has been essentially undetectable. That's been true across every model from every vendor. Anthropic's watermarking changes that — but only for their own product.
The gap between "one vendor is detectable" and "all AI use is governed" is where the real compliance risk lives. Watermarking is a tool, not a strategy.
What SEC and FINRA are watching:
Neither regulator has issued prescriptive AI rules for RIAs yet. But the trajectory is clear:
- SEC examination priorities have increasingly referenced technology governance and cybersecurity controls. AI-specific questions in exams are a matter of when, not if.
- FINRA has published guidance on AI in communications and supervision. The expectation is that firms treat AI-generated content with the same review and approval standards as human-generated content.
- The EU AI Act (which applies to any firm with EU clients or data) explicitly requires disclosure and detectability of AI-generated content.
When the formal guidance lands, firms that already have an AI governance framework in place will be in a very different position than firms scrambling to write one.
What RIAs should do now:
- Write an AI acceptable use policy. Define which tools are approved, what data can and can't be entered into AI systems, and what disclosure is required when AI assists in client-facing work. If you don't have this, start here.
- Inventory what your team is actually using. Shadow AI is invisible by definition. Ask the question directly, and don't assume the answer is "nothing." The tools are free, they're easy to access, and your people are almost certainly using them.
- Establish a review process for AI-assisted content. Client emails, investment memos, compliance documentation — if AI touched it, a human should review it before it goes out. This isn't new; it's the same supervision standard that already applies to communications.
- Don't wait for detection tools to solve the problem. Watermarking and AI detection will improve, but they'll never cover every model or every use case. Policy and training are what close the gap.
- Document everything. When an examiner asks "what is your firm's AI governance framework?" the answer should be a document, not a conversation.
The bottom line:
AI watermarking is a meaningful development, but it's one piece of a much larger puzzle. The firms that will fare best — with regulators, with clients, and with their own operational risk — are the ones that govern AI use proactively, not the ones that wait for technology to catch up.
The question isn't whether your firm uses AI. It's whether you can prove you're using it responsibly.
S.T. Royer is the founder of Royer Networks, a business risk and compliance advisory firm based in Frederick, Maryland. He works with RIAs and financial services firms to adopt AI safely — protecting client data and meeting regulatory expectations without slowing down the business.

