EU AI Act · In force since August 2, 2026

Retyping won't save you. AI cheating is about to become impossible.

The EU AI Act's transparency rules are now live. Anyone offering generative AI in the EU has to mark its output as AI-generated in a machine-readable way. Anthropic just showed what that looks like. Claude models launched from August 2, 2026 weave an invisible watermark into the text they generate, worldwide, and older models are being retrofitted. Google, Meta, Microsoft and OpenAI committed to the same code. Here is how the technology works, why typing it out by hand changes nothing, and where it still falls short.

Published August 11, 2026. Sources linked at the bottom of the page.

What just happened

Three dates that end the free ride

AUGUST 2, 2026

The law kicks in

Article 50 of the EU AI Act now applies. Providers of generative AI must mark their output as AI-generated in a machine-readable way, and it must be technically detectable. Not a guideline. Law.

AUGUST 11, 2026

One of the first labs shows its hand

Anthropic becomes one of the first big labs to spell out its compliance, signing the EU's Code of Practice on Transparency of AI-Generated Content and announcing invisible watermarks in Claude's text output. And not just in Europe. The marking applies everywhere Claude runs, including the API, AWS, Google Cloud and Microsoft Foundry. The rest of the industry committed to the same code and now has a template to follow.

DECEMBER 2, 2026

No more excuses

Extended deadline for generative AI systems that were already on the market before August 2. This date does not come from the original AI Act text. It was added by the 2026 AI Omnibus, which gives existing systems until December 2 to meet the machine-readable marking requirement in Article 50(2). The same Omnibus pushed several high-risk deadlines into 2027 and 2028, but it left Article 50 where it was. After December 2026, unmarked output from a major AI platform becomes the exception, not the rule.

The stakes are real. Under Article 99 of the AI Act, providers that ignore the transparency rules face fines of up to €15 million or 3 percent of global annual revenue, whichever is higher (for small and medium-sized companies, whichever is lower). Which is why this is much bigger than one company. Anthropic, OpenAI, Google, Meta, Microsoft, Black Forest Labs and Synthesia have all committed to the EU's transparency code, and because providers generally don't maintain separate EU and non-EU models, the marking goes global by default.

The technology

A fingerprint made of words

Watermarks inside the text itself

When a model writes, it constantly chooses between words that mean the same thing. A text watermark gently biases those choices so that, across a passage, they form a statistical pattern. A detector can read that pattern. You can't. Anthropic describes its version as a watermark woven directly into the text that does not change meaning, quality or readability. Anthropic is among the first labs to spell out EU compliance, but it is not the first to ship the technique. Google's SynthID-Text has run in Gemini since 2024 and was open-sourced in October 2024, so the method is public and anyone can read it. Every signatory of the EU code needs an equivalent.

Because the watermark is the text, it survives copy and paste. Anthropic states that the mark is woven into the text itself and travels with it when the text is copied elsewhere, which rules out metadata and hidden characters. One caveat we owe you: Anthropic has not yet published its exact method, so the description above follows the openly documented SynthID approach and the academic work behind it. We will update this page when the technical documentation lands.

Signed metadata for files

For generated files like images, the industry is converging on cryptographically signed provenance data using the open C2PA standard, the same approach camera makers and news agencies use. Think of it as a tamper-evident seal that records where the content came from and shows if someone altered it.

Two layers, one goal: content that carries its own origin story, designed to be readable by platforms, universities and plagiarism checkers once they build support for it.

Why retyping is pointless

The classic trick was simple. Generate the essay, then retype it into a fresh document so no copy-paste trace exists. That trick assumed detection lived in metadata, edit history or clipboard artifacts. Statistical watermarks break the assumption completely.

The signal lives in the word choices. Retype the same sentences by hand, on another computer, in another program, even from a printout, and you have faithfully reproduced the exact pattern the detector looks for. Retyping is just copying with extra steps. To weaken the mark you would have to rewrite the text so deeply that you might as well have written it yourself. Which is exactly the point of the law.

There is one thing we will not oversell. Retyping was never the strong evasion. Pushing the text through a second model to paraphrase it is, and today that still works, which is covered honestly two sections down. What died on August 2 is the older and more comfortable assumption that detection lives in your file, your clipboard or your edit history. It does not anymore.

The objection

But what if I accidentally write the same words?

It is the most common and the best objection to watermarking. Humans write sentences an AI would write, all the time. True. A single sentence can match the pattern by pure chance. Which is exactly why detection never works at the sentence level.

Simplified, the watermark works like this. At every word the model has several equally good options, and the watermark nudges it toward a marked half of them, call it green. A human word lands on green about half the time by accident, like a coin flip. One hit means nothing. What matters is the running total.

Hitting 60% green across a 20-word sentence by chance ≈ 1 in 4
Keeping that rate up across a 500-word essay ≈ 1 in 200,000
Keeping it up across 1,000 words ≈ 1 in 7 billion

That is the core of it. Every additional word multiplies the improbability. A sentence-level coincidence is expected and gets ignored. An essay-level coincidence would be dozens of times less likely than hitting the lottery jackpot. It works like a DNA match, where a single base pair proves nothing and the full profile decides.

Two caveats, because these numbers get quoted badly. First, this is a teaching model, not a lab result. It treats every word as an independent coin flip, and real language is not independent, real detectors score tokens rather than words, and labs do not publish their parameters. Second, deployed detectors are not actually run at one-in-a-billion. They are tuned to a fixed false-alarm rate that balances catching cheats against falsely flagging the innocent, and the exact level is a design choice no lab has published for a deployed text detector. The shape of the argument survives both caveats. Length is what makes a flag mean anything, and pure coincidence is not how an innocent student gets flagged. There is a way that can happen, and it is in the next section.

The honest part

What it can and can't catch today

No serious engineer claims this is bulletproof yet. Anthropic itself says a detected mark is a signal, not proof. Heavy paraphrasing, translation and very short passages can weaken detection, and older models are still being retrofitted.

There is a second limit that matters more to honest students than any of that. Anthropic is explicit that a detected mark means the text may have been processed by Claude, not that Claude wrote it. Claude edits, translates and rewrites text people bring with them, and the output gets marked either way. Paste your own paragraph in for a grammar fix, copy the cleaned-up version back into your essay, and that passage carries a watermark even though every idea in it was yours. Nobody has explained yet how universities are supposed to tell those two cases apart, which is the strongest argument against treating a mark as a verdict.

And there is nothing to check with yet. Anthropic says verification tools are forthcoming; no public detector has shipped, and no plagiarism checker has announced an integration. Every consequence described on this page is currently a consequence in waiting.

But look at the direction, not the snapshot. Detection tools improve every year, your submitted work is archived and can be rechecked later with better tools than exist today, and Article 50 does not ask for a fixed bar. It requires marking that is effective, interoperable, robust and reliable as far as technically feasible, which ratchets upward as the technology improves. Betting your degree on a loophole that shrinks every semester is a terrible trade.

The current state, honestly:

For students

Two ways to use AI. One of them just died.

The dead end: submitting AI work as yours

Generate the essay, hand it in, hope for the best. That essay now carries a fingerprint that sits in your university's archive for years, and the archive does not change while detection keeps improving. To be precise about today: Anthropic says verification tools are forthcoming, and no plagiarism checker has announced an integration yet. The mark is already in the text either way.

And even a perfect paraphrase can't save you from the oral follow-up question about a text you never understood.

The smart lane: AI as your study engine

Watermarks are completely irrelevant for material you never submit. Turn your lecture recordings and PDFs into structured notes, summaries and Anki flashcards, then learn from them and walk into the exam actually knowing the material.

That is exactly what Heyblocks is built for: your sources in, structured study tabs out. Nothing to hand in, everything to learn from.

FAQ

Questions about AI watermarks

No. The watermark is embedded in the statistical pattern of the word choices, not in the file or its metadata. Retyping the same words reproduces the same pattern, so the mark travels with the text. Anthropic has not published its exact method, but it does confirm the mark lives in the text itself and survives being copied elsewhere, which is what makes retyping pointless.

Heavy rewriting or translation can weaken detection today. But detection improves continuously, submitted work is archived and can be rechecked years later, and a paraphrased text you don't understand still fails the follow-up question.

Anthropic ships invisible text watermarks in Claude models launched on or after August 2, 2026, is retrofitting older ones, and adds signed C2PA metadata to generated files. Google has run SynthID-Text in Gemini since 2024. Google, Meta, Microsoft, OpenAI, Black Forest Labs and Synthesia have all committed to the same EU transparency code. Systems already on the market have until December 2, 2026.

Yes. The rules bind anyone offering generative AI in the EU, and providers generally do not build separate EU and non-EU models. Anthropic, for example, applies its watermark everywhere Claude is offered. EU rules quietly become the worldwide default, the same way GDPR reshaped cookie banners globally.

No. Turning lectures into notes, summaries and flashcards for yourself is learning, and material you never hand in sits outside all of this. There is one catch worth knowing about. The mark goes on anything Claude outputs, including your own text that you pasted in for a grammar fix or a translation. Copy a Claude-polished sentence into something you submit and it carries a mark, even though the thinking was yours. Write the submitted version in your own words, and always check your university's AI policy.

A single sentence can absolutely match by chance, and detectors expect that. One sentence is statistically meaningless. Flags only fire when the pattern holds across a whole document, and the odds of that happening by accident collapse exponentially with length, from roughly 1 in 4 for a sentence to vanishingly small across a long essay. Those figures are a simplified illustration and real detectors run at a fixed false-alarm rate rather than wide open, but the principle holds. Length is what makes a flag mean anything. The realistic risk is not coincidence, it is running your own writing through an AI for editing or translation, which marks the output.

Study workflows

Use AI the way it was meant to be used

Turn your own lectures, videos and PDFs into material you learn from, not material you hand in.

Lecture recording to study notes PDF to Anki flashcards Video to study notes Research notes from sources

Use AI to learn it, not to fake it

The era of submitting AI essays is closing fast. The era of AI-powered studying is wide open. Turn your lectures into notes and flashcards you actually learn from.

Start for free