By: David S. Levine and Ryan M. Hubbard
Artificial intelligence companies have recently announced plans to introduce invisible watermarks into their outputs so that third parties can assess whether an AI tool contributed to the work product. How will these watermarks work? And what does this mean for in-house counsel and other professionals using AI tools in connection with their legal work? The article below discusses these issues and more.

Which AI Companies Apply Watermarks?
The short answer: the outputs of common AI tools such as Claude and Gemini will likely soon have watermarks if they do not already. For users of AI tools who prefer not to engage with the technical details of their preferred models, the conservative approach is to assume that an output is watermarked unless they receive contrary information from their IT departments or similar professionals.
As additional context, Anthropic and Google have indicated that their popular AI tools—Claude and Gemini, respectively—either already do or will soon contain watermarks. Although OpenAI has the capability to watermark its text, the company has not announced plans to do so at the time of this writing. Popular legal-industry tools such as Microsoft Copilot, Harvey, Legora, Westlaw, and Lexis typically leverage an existing model (such as Claude, Gemini, or OpenAI) to generate their outputs, so the watermark analysis for those legal-specific tools will likely depend on various factors (such as which underlying model performed the task and how the tool was configured).
An additional question is whether, for tools such as Claude that are adding watermarks, the watermark will apply to the outputs of the enterprise versions (often used by companies and law firms) or only the consumer versions. At the time of this writing, Anthropic has indicated that the watermark will apply to all new models (including consumer and enterprise versions), but the answer is less clear for Gemini.
How Do The Watermarks Work?
Unlike a watermark that embeds an actual symbol into the text, Anthropic and Google use a system that marks the text through word choice. As Anthropic explains: “Take the sentence ‘The weather today was cold and…’ The next word is very unlikely to be ‘sugary.’ But it is quite likely to be ‘overcast’ or ‘grey.’ Watermarking uses low-stakes choices like these—which occur many times over a piece of generated text—to leave a pattern in Claude’s responses.”
This pattern allows Anthropic and Google—and third parties using detection tools the companies may provide—to assess whether an AI tool likely influenced the work product. Even the AI companies agree that this is a probabilistic assessment and that these tools will not be able to conclusively determine whether an AI tool processed the output. Anthropic explains, for example, that there may be reduced watermarking when Claude has fewer opportunities to generate text, such as when proofreading.
How Might These Watermarks Bear On Common Legal Issues?
It is still early days, but below are some substantive legal issues in which a watermark might matter.
- Copyright Protection. In the United States, copyright protection requires human authorship, and the Copyright Office requires applicants to disclaim that an AI tool generated the work at issue. Accordingly, a watermark suggesting AI influence could be used by a third party to challenge a work’s protectability, particularly given Anthropic’s explanation that watermarking may not be detectable for shorter, lightly proofread works. Going forward, we recommend that creators document their own contributions (such as by saving drafts not processed by AI).
- Patent Protection. Patent law raises related but distinct questions. Under U.S. patent law, a human must have contributed to the conception of each claimed invention of the patent. A patent application bearing an AI watermark may again raise questions about what the human inventor’s contribution was, and if they actually contributed to each claim. Inventors should consider documenting their contributions contemporaneously with each stage of the inventive process, including the initial concepts, any modifications or improvements made along the way, and any prompts to AI tools as well as any human changes to, or rejections of, AI outputs. Documenting these contributions through methods that are not themselves AI watermarked could further help defensibility.
- Employment Policies. Companies increasingly have policies governing their employees’ use of AI tools (a practice that we recommend). Employers may use watermark detection tools to assess whether an employee violated an AI-use, confidentiality, or work-product policy. Because the detection tools will not provide conclusive evidence of AI use, however, employers should not wholly rely on such tools in analyzing whether a particular employee violated the company’s AI policy.
- Contract Representations and Warranties. We sometimes see commercial agreements with representations and warranties regarding the use (or non-use) of AI. If a company or individual agrees to such a representation or warranty and then has the watermark detected in their work product, they may need to explain the discrepancy. Companies and individuals should review their templates with this risk in mind.
- Litigation Orders. Many judges have standing orders regarding attorneys’ use of AI tools (for example, by requiring disclosure of AI use in preparing court filings). Some parties in sophisticated litigation also now insist on protective orders prohibiting the other side from processing their confidential material with an AI tool. Watermark detection tools may result in increasing enforcement of such orders by courts.
Takeaways
As noted, this area is developing rapidly. Especially as watermarking and associated AI detection evolve, companies and their counsel should stay abreast of developments and be prudent in their use of AI tools. Because the implications of AI use may depend on the substantive area of law at issue, companies should take a tailored approach and ensure that their deployment of AI tools does not create unnecessary legal exposure.
Fox Swibel is monitoring these issues closely and can be reached at any time. Please contact David S. Levine, Ryan M. Hubbard, or the Fox Swibel attorney with whom you regularly work to discuss these issues.
David S. Levine

David Levine is a partner in the Firm’s Employment Law and Litigation Groups. David’s practice focuses on representing clients in a wide range of labor and employment matters, as well as other business disputes. As part of his litigation practice, David regularly defends employers in class, collective, and individual actions involving claims under the FLSA, Title VII, ADA, and other federal and state statutes. David also often litigates individual and class actions involving data privacy issues, in particular cases under the Illinois Biometric Information Privacy Act (BIPA). He practices in state and federal courts and before administrative agencies such as the EEOC, DOL, and DOJ.
Ryan M. Hubbard

Ryan Hubbard is a partner in the Litigation and Intellectual Property groups. He concentrates on complex patent and intellectual property litigation in federal court around the country and counselling clients on intellectual property portfolio management, new product development and clearance, and due diligence. He has advised clients regarding cyber-security, privacy, and data breach issues. He represents clients of all sizes, from startups to multinational corporations, and leverages his curiosity and a deep understanding of client needs to deliver practical advice and long-term solutions.
This article contains material of general interest and should not be construed as legal advice or a legal opinion on any specific facts or circumstances. Under applicable rules of professional conduct, this content may be regarded as attorney advertising.