클로드가 쓴 글에 보이지 않는 표식이 붙기 시작했습니다. 엿새 뒤, 그 표식을 찾아내고 다루는 오픈소스 도구가 나왔습니다.
그 사이 구독을 끊은 사람들이 있었습니다. 앤트로픽은 취소가 늘어난 추세는 없었다고 밝혔습니다.
표식을 붙이는 쪽과 그 표식을 다루려는 쪽이 같은 주에 움직였습니다.
■ 구독을 끊은 사람들
비즈니스 인사이더에 따르면 앤트로픽이 워터마크 적용을 밝힌 10일 이후, 수십 명이 클로드 구독을 취소했다는 글을 엑스에 올렸습니다.
미국 공공정책 분야에서 일하는 아르투로 비야로야는 클로드 맥스를 끊고 커서와 그록으로 옮겼습니다. 단순 맞춤법 검사나 인용 수정에도 워터마크가 붙을까 우려했습니다.
조지아주의 AI 컨설턴트 리처드 에콜스는 12일 클로드 맥스를 취소했습니다. 기업 문서를 쓸 때 기본 자료는 직접 쓰고 챗봇은 편집에만 썼는데도 표식이 남을까 걱정된다고 했습니다.
둘의 걱정은 같습니다. 내가 쓴 글인데 AI 표식이 남으면 어떻게 되느냐는 것입니다. 그런데 더 세게 반응한 쪽은 따로 있었습니다.
■ 개발자가 걱정한 것은 코드의 저작자
체코의 프리랜서 개발자 블라디슬라프 라이트마이어와 몬테네그로의 소프트웨어 엔지니어 스테반 보고사블레비치도 구독을 해지했습니다.
고객에게 넘기는 최종 코드에서 AI 라벨이 감지되면 저작자 문제나 계약상 불이익이 생길 수 있다고 봤습니다.
전문적으로 배포되는 문서나 코드에서는 저작권과 규정 준수가 걸립니다. 개인 취향의 문제가 아닙니다.
■ 특수문자도 숨은 문자도 아닌 것
앤트로픽은 14일 워터마크가 어떻게 작동하는지 설명했습니다. 2024년 구글 딥마인드가 발표한 신스아이디 텍스트를 기반으로 했습니다.
숨은 문자나 별도의 코드를 문장에 넣는 방식이 아닙니다. AI가 다음 단어를 고를 때 비밀키와 앞서 생성된 단어를 이용해, 자연스러운 여러 표현 가운데 하나를 일정한 규칙으로 선택하게 합니다.
사람이 읽으면 자연스럽지만 긴 글에서는 일정한 통계적 패턴이 만들어집니다. 탐지 시스템은 그 패턴을 분석해 클로드가 관여했을 가능성을 판단합니다.
새 문자나 토큰을 더하지 않아 토큰 사용량과 비용에 영향이 없고, 이용자나 소속 기업, 특정 대화를 식별할 개인정보도 담기지 않는다는 것이 회사 설명입니다.
그러면 개발자들이 걱정한 코드는 어떨까요? 답이 정해진 내용은 다른 단어를 고를 여지가 거의 없습니다. '2+2=4'가 그렇고, 프로그래밍 코드도 명령어나 문법을 바꾸면 프로그램이 작동하지 않을 수 있어 워터마크 적용이 제한됩니다.
교정도 비슷합니다. 기존 문장을 고치는 경우 수정된 소수의 단어에만 영향이 가서 감지가 어려울 수 있습니다.
사용자와 제3자가 직접 워터마크 유무를 확인할 수 있는 전용 API 도 무료로 내놓겠다고 했습니다. 전 세계에 한꺼번에 적용한 이유로는 지역별로 적용 범위를 정할 확실한 방법이 아직 없다는 점을 들었습니다.
앤트로픽은 검출 결과만으로 글의 저자나 소유권, 이용 목적을 판단하거나 부정행위의 증거로 삼을 수 없다고 밝혔습니다.
■ 엿새 만에 나온 오픈소스
16일 오전, 카르다노 창립자 찰스 호스킨슨이 엑스에서 오픈소스 프로젝트 '앤트로피스(anthropies)'를 공개했습니다. 오데일리가 전했습니다.
프로젝트가 처리 대상으로 삼은 것은 셋입니다. 텍스트에 들어가는 통계적 워터마크, 이미지에 붙는 C2PA 콘텐츠 증명, 그리고 깃 커밋에 남는 'Co-Authored-By: Claude' 서명.
앞의 둘은 앤트로픽이 이번에 도입한 표식이고, 마지막은 개발 과정에서 클로드가 코드 작성에 관여했음을 남기는 메타데이터에 가깝습니다.
그러면 표식을 정말 지울 수 있을까요? 프로젝트는 한계를 스스로 적었습니다. README 는 앤트로픽이 공개하지 않은 탐지 체계를 완전히 피할 수 있다고 보장하지 않는다고 명시했습니다.
도구가 표식의 존재를 다루더라도, 비공개 검출 방식까지 제거하거나 우회한다고 단정할 수는 없다는 뜻입니다.
■ 같은 주, 반대로 움직인 구글
이 모든 일의 배경에는 지난 2일 시행된 유럽연합 AI법 제50조가 있습니다. AI 생성물에 기계가 읽을 수 있는 표시를 요구하는 조항입니다.
그런데 모두가 같은 방향으로 가는 것은 아닙니다. 구글은 14일 이미지와 영상, 음악 생성물의 워터마크 표시 여부를 사용자가 고를 수 있게 했습니다. 대상은 이미지 모델 '나노 바나나', 영상 모델 '옴니', 음악 모델 '리리아'입니다.
눈에 보이는 표시는 선택제로 돌리되, 콘텐츠 안에 신호를 심는 신스아이디와 출처 정보를 담는 C2PA 메타데이터는 그대로 둔다는 것이 구글 설명입니다. 개발자가 앱 안에 검증 기능을 넣을 수 있도록 오픈소스 라이브러리 '크레덴티오'도 내놨습니다.
지디넷코리아는 그록이 텍스트 생성 표시에는 참여하지 않고 있다고 전했습니다.
보이는 표시는 줄이고 기계가 읽는 신호는 남긴다. 미국 빅테크가 공통으로 향하는 지점입니다.
■ 숫자는 서로 다르게 말한다
그러면 실제로 얼마나 빠져나갔을까요? 앤트로픽은 일부 사용자가 구독을 취소했다는 보도에 대해, 워터마크 발표 이후 취소 건수가 늘어나는 추세는 없었다고 밝혔습니다.
두 얘기는 동시에 참일 수 있습니다. 수십 명이 취소했다고 엑스에 쓴 것과 전체 취소가 늘지 않은 것은 서로 다른 지표입니다.
그러니 이걸 '클로드 구독자가 빠져나가고 있다'로 읽으면 지금 근거로는 과합니다. 확인된 것은 목소리를 낸 사용자가 있었다는 데까지입니다.
■ 볼펜을 저자로 적나
기술 전문가들의 비판은 이어지고 있습니다.
IT 분석가 벤 톰슨은 교정이나 편집 목적으로 AI를 쓴 경우까지 AI 작성물로 분류될 위험을 만드는 규제와 앤트로픽의 방식이 도구의 본질을 벗어났다고 지적했습니다.
“볼펜으로 글을 썼다고 해서 볼펜을 저자로 표시해야 한다고 주장하는 것과 다름없는 터무니없는 발상” — 벤 톰슨
표식 자체보다 그 표식이 어떻게 읽힐지가 문제라는 얘기입니다. 도구를 썼다는 흔적이 '내 글이 아니다'로 번역되는 순간, 편집기로 쓰던 사람까지 손해를 봅니다.
그런데 정말 그렇게 읽히게 될까요? 앤트로픽은 그렇게 읽지 말라고 했고, 유럽 규제는 표시를 요구했으며, 시장에는 벌써 표식을 다루는 도구가 나왔습니다.
표식을 붙이는 일보다 어려운 것은 그 표식의 뜻을 정하는 일입니다. 그 일은 아직 아무도 끝내지 못했습니다.
Invisible marks began appearing in text written by Claude. Six days later, an open-source tool for finding and handling those marks appeared.
In between, some people cancelled their subscriptions. Anthropic said it had seen no rise in cancellations.
The side attaching the marks and the side working on them moved in the same week.
The people who cancelled
According to Business Insider, dozens of people posted on X that they had cancelled their Claude subscriptions after Anthropic disclosed the watermark on the 10th.
Arturo Villaroya, who works in US public policy, dropped Claude Max for Cursor and Grok, worried that even a spell check or a citation fix would carry a watermark.
Richard Echols, an AI consultant in Georgia, cancelled Claude Max on the 12th. He writes corporate documents, drafting the base material himself and using the chatbot only to edit — and still worried a mark would remain.
Their worry is the same: what happens when text you wrote carries an AI mark? But another group reacted harder.
For developers, the worry was authorship of the code
Vladislav Reitmeier, a freelance developer in the Czech Republic, and Stevan Bogosavljevic, a software engineer in Montenegro, also cancelled.
They saw a risk that an AI label detected in final code delivered to a client could raise questions of authorship or cause contractual trouble.
For documents and code shipped professionally, copyright and compliance are at stake. This is not a matter of taste.
Neither a special character nor a hidden one
On the 14th Anthropic explained how the watermark works. It is built on SynthID-Text, published by Google DeepMind in 2024.
It does not insert hidden characters or extra code into sentences. When the model picks the next word, it uses a secret key and the preceding words to choose among several equally natural options according to a fixed rule.
The result reads naturally, but across a long passage a statistical pattern forms. A detector analyses that pattern to judge whether Claude was involved.
Because no characters or tokens are added, the company says token usage and cost are unaffected, and the watermark carries no data identifying a user, an employer or a particular conversation.
So what about the code the developers were worried about? Where the answer is fixed, there is almost no room to choose a different word. '2+2=4' is one case; programming code is another, since changing a command or the syntax can break the program, which limits how much watermark can be applied.
Editing is similar. When existing sentences are revised, only the few changed words are affected, which can make detection difficult.
Anthropic also said it would release a free detection API so users and third parties can check for the watermark themselves. It applied the change worldwide at once because there is no reliable way yet to scope it by region.
Anthropic said a detection result alone cannot establish authorship, ownership or intent, and cannot serve as evidence of misconduct.
An open-source project, six days on
On the morning of the 16th, Cardano founder Charles Hoskinson announced an open-source project called 'anthropies' on X. Odaily reported it.
The project targets three things: the statistical watermark in text, the C2PA content credentials attached to images, and the 'Co-Authored-By: Claude' signature left in Git commits.
The first two are the marks Anthropic has just introduced; the last is closer to metadata recording that Claude took part in writing the code.
So can the marks actually be removed? The project wrote down its own limits. Its README states that it does not guarantee it can fully evade detection systems Anthropic has not disclosed.
In other words, handling the marks does not mean the undisclosed detection methods are removed or bypassed.
The same week, Google moved the other way
Behind all of this is Article 50 of the EU AI Act, in force since the 2nd, which requires machine-readable marking of AI-generated content.
Not everyone is moving in the same direction. On the 14th Google let users choose whether visible watermarks appear on generated images, video and music — its image model 'Nano Banana', video model 'Omni' and music model 'Lyria'.
Visible marking becomes opt-in, but SynthID, which embeds a signal inside the content, and C2PA metadata, which carries provenance, both stay. Google also released an open-source library, 'Credentio', so developers can build verification into their apps.
ZDNet Korea reported that Grok is not taking part in marking generated text.
Fewer visible marks, machine-readable signals kept. That is where the US tech companies are converging.
The numbers say different things
So how many actually left? Responding to reports that some users had cancelled, Anthropic said cancellations had shown no upward trend since the watermark announcement.
Both things can be true at once. Dozens of people posting on X that they cancelled and total cancellations not rising are different measures.
So reading this as 'Claude is losing subscribers' goes beyond the evidence. What is established is that some users spoke up.
You don't credit the ballpoint pen
Criticism from technologists has continued.
The analyst Ben Thompson argued that regulation which risks classifying even proofreading and editing as AI-written work — and Anthropic's approach to it — misses what a tool is.
“It is as absurd as insisting that writing with a ballpoint pen means the pen must be credited as the author” — Ben Thompson
The problem is less the mark than how it will be read. The moment a trace of using a tool is translated into 'this isn't mine', people who used it as an editor lose out too.
But will it really be read that way? Anthropic said not to read it that way, European regulation demanded the marking, and a tool for handling the marks is already out.
Harder than attaching the mark is deciding what it means. Nobody has finished that part.
Sources · AI Times · TokenPost · Daily Secu · ZDNet Korea