Your AI disclosure position just got decided for you

Your AI disclosure position just got decided for you

On August 14, Anthropic announced that every word Claude writes now carries a watermark: a statistical fingerprint hidden in the pattern of word choices, invisible to any reader, detectable by software built to look for it. And not just for European users: it applies to everyone, worldwide, because Anthropic says it doesn't "yet have a durable way to scope it by region." If you've been treating AI disclosure requirements for accountants as a question for later, the industry just answered it for you.

That was the fourth event in four weeks. On July 21, Substack switched on reader-facing AI detection: any subscriber can now scan any post and get a percentage estimate of how much a human wrote. In late July, LinkedIn added a "seems like AI slop" report option, and flagged posts get suppressed beyond the poster's own network. And on August 2, the EU became the first major jurisdiction to make AI disclosure a legal duty rather than an ethics preference.

Three layers of the stack moved in a month: the platforms you publish on, the law, and the models themselves. Nobody in the profession voted on any of it. I flagged the watermark story in Monday's roundup; this piece is the full walk-through. So the question for your practice splits in two: what does this actually require of you, and what does it merely do to you? Those are different questions, and the second one is bigger.

The EU AI Act binds four kinds of organizations, and you need to know which one you are

The EU AI Act's disclosure rules aren't written for "companies that use AI." They attach to specific roles, and the word people keep reaching for, "vendors," blurs exactly the distinction that decides who owes what. Four roles matter.

Model developers like Anthropic, OpenAI, and Google are "providers" under the Act. The duty to mark AI output in machine-readable form sits on them, and only them. That's what the watermark is: Article 50(2) compliance, shipped worldwide because region-scoping turned out to be harder than global rollout. Anthropic signed the EU's Code of Practice on AI content transparency alongside roughly 190 other organizations, and says the other major model developers will be shipping their own watermarks. This is the industry's new default, not a Claude quirk.

Software products with a model built in are providers too, and it doesn't matter whose model that is. A tool that rents Claude or GPT behind the scenes is treated the same as one that built its own: the Act covers anyone who has an AI system developed and puts it on the market "under its own name or trademark." What triggers the duty is the name on the product, not the origin of the model. If your workflow tool, ledger, or tax software drafts text with an AI feature, the marking duty for that feature belongs to the software company. Their problem, not yours; but it hands you a question worth asking at renewal time: what's your Article 50 position, and will your output carry marks?

A firm that uses AI in its process is a "deployer": the Act's word for an organization that simply uses an AI system under its own authority. Deployers carry no marking duty at all. For text, exactly one provision can ever reach you, and it's narrower than you'd guess.

The fourth role is the edge case: a firm that publishes AI-generated output for others to take away and use. That's not your blog or your LinkedIn feed, which are ordinary deployer territory covered by the scope test below; it's benchmark data, industry reports, and public tools, output that is itself the product. Still a deployer, but the one live limb of the disclosure rule applies to published content, so these firms sit closest to the line. And the provider line is crossed on capability, not content: selling a subscription to AI-generated reports still leaves you a deployer, but putting an AI-powered tool customers run under your own brand makes you the provider of that system, marking duty included. Some firms are drifting into this category without noticing.

One more thing before you place yourself, because it matters: the classification runs per AI system, not per firm. Becoming the provider of one product doesn't reclassify anything else you do; the duties attach to each system separately. Here's where a firm's typical activities land:

Here's what the distinction buys you. If any provider row is yours, you carry the provider duties for that product: mark its synthetic output in machine-readable form, the way Anthropic just did, and make sure people know when they're interacting with a machine. That's a product-compliance project, and it belongs with legal counsel, not this article. Everything from here on assumes the role your practice is almost certainly in: deployer, where exactly one obligation can ever reach you.

Run the AI disclosure scope test before you spend a dollar on compliance

The one provision that can touch a deployer is Article 50(4), and its text limb needs three conditions stacked on top of each other: the content is published, it's published "with the purpose of informing the public on matters of public interest," and no exemption applies.

Client deliverables exit at the first gate. The monthly pack, the tax return, the advisory memo, the auto-generated reminder email: none of it is published, so none of it is in scope, no matter how much AI touched it. That isn't an interpretation; it's what the text says.

Your published content, the blog and the newsletter and the LinkedIn posts, reaches the second gate: is it "informing the public on matters of public interest"? The term is undefined and genuinely unsettled. And even content that clears the second gate is saved by the exemption the EU wrote in: no disclosure duty where the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication."

Read that carve-out again, because it's the most consequential sentence in the whole regime. The EU's position, in operative legal text, is that machine-written content is fine so long as a human reviewed it and somebody's name is on the file. That's the wringable neck, the human accountability clients actually pay for at partner level, written into a statute.

And suppose you fail every gate anyway: the content is published, it's informing the public on a matter of public interest, and no review process saves you. The obligation that lands is disclosure itself: you must say, clearly and visibly with the content, that it was AI-generated. No filing, no regulator to notify, no prescribed wording; a label. Which gives you two ways to comply: add the label, or restructure the workflow so the carve-out applies, with real human review and a named person holding editorial responsibility. Take the second one, because it's also the answer to everything else in this article.

The penalty if you do neither runs to EUR 15 million or 3% of worldwide turnover, with reduced caps for SMEs. It's a number built for model developers, and it sits behind gates your work mostly never reaches. An EU-based firm runs the same analysis with two differences: your public marketing content is more plausibly "used in the Union," and the enforcer is your national authority rather than a distant one. The carve-out is still your exit.

Two things the statute genuinely doesn't settle: whether output "used in the Union" requires targeting EU readers or merely being readable there, and what "matters of public interest" means. You can't resolve either from your desk. Which is the point: position yourself inside the carve-out, with real review and a named person, and both ambiguities stop mattering.

(The usual caution: this is analysis, not legal advice. Scope questions turn on your specific facts, and if real money rides on the answer, ask counsel.)

The AI watermark doesn't measure what everyone thinks it measures

Here's where "you're not at risk" stops being the story. Four different instruments are now pointed at your writing, and they measure four different things. Style classifiers like Substack's Pangram guess from prose patterns, and they're known to flag genuinely human writing. Watermarks record provenance: which words a model produced.

The EU rule tests something else entirely: responsibility. Did a human review it, and is someone accountable? And "slop," the word everyone reaches for, measures a fourth thing, care: was this worth anyone's attention.

The public is about to read all four as one dial. They are not one dial, and the needle points backwards. Anthropic's own documentation says the watermark weakens on short passages, factual passages, and edited text; hand Claude a paragraph to proofread and the watermark can only live in "the handful of corrections, which might be too few to register."

Now walk the cases. Genuine slop lightly paraphrased by hand sheds its watermark word by word and passes clean. The auto-generated monthly summary, short and numeric, sits exactly where detection is weakest. And long-form content produced under the heaviest editorial control flags as maximally AI. The instrument is strongest precisely where the human was most involved, and weakest where the automation runs unattended.

Let me make that concrete with the most awkward example I have: this article. Every published word of The AI Accountant is generated by Claude. I don't hand-edit the text. I shape the argument, challenge the drafts, order rewrites, kill the paragraphs that don't survive scrutiny, and approve what ships, and my name is on all of it.

Under the EU rule, that's editorial control with named responsibility: exempt. Under the watermark, it's 100% machine-generated: flagged. Both verdicts are correct. They're answering different questions, and only one of them is the question that matters.

Because editorial direction never touches a token, the watermark measures who typed the surviving words, not who controlled them. Detection tracks keystrokes. Responsibility tracks judgment. The strongest AI flag in your feed can sit on the most heavily governed content in it, and the cleanest "human" reading can sit on paraphrased junk.

You can't edit your way out, so write the story that arrives with the flag

Could you strip the watermark? Sure: retype everything, paraphrase by hand, do the tinkering that changes words without changing substance. That's exactly the work that adds no value, performed purely to hide the tool, and it burns the hours AI just handed back. The off-switches aren't much better: Substack lets a writer disable detection on a post, and readers then see "AI detection unavailable," which is its own kind of disclosure.

That leaves one lever, and it's the one the law and the platforms are independently pointing at: adopt a disclosure position on purpose instead of inheriting one by default. Substack already built the slot, a "How I make this" statement that appears whenever a reader scans your work. The EU already defined the safe harbor: review plus a name. What's missing at most firms is the sentence to put in the slot.

So write it. Run the scope test above. Place your outputs on two axes: who produced the words, and who stood behind them before they moved. Then write the position down and name the person: "We use AI in production. Every deliverable passes human review before it reaches you. [Name] holds responsibility for what we publish and deliver."

The firms that get hurt over the next two years won't be the ones whose content flags as AI. They'll be the ones whose flag arrives with no story attached, or worse, with a story the flag contradicts. "100% handcrafted" is about to become a checkable claim.

The detectors are live. The watermark is already in your tools. When the first client runs the scan, will your answer be written?

I've put the whole framework in one place: the scope test, the exposure matrix for your firm's outputs, the questions to ask your software providers, and a template disclosure position you can adapt this week. Download The AI Disclosure Position Kit at theaiaccountant.ai/disclosure-position.