The Signal & The Noise · Vol. 04
Since 2 August, machine involvement in a piece of work can be demonstrated. Human involvement still cannot. And the retention policy you were right to write is widening the gap between the two.
I write almost everything by speaking. A dictation tool turns it into text and I edit from there. I chose that tool partly because it keeps nothing. The audio is processed and discarded, no recording, no transcript sitting on anyone's server. That was the responsible choice and I would make it again.
Ten days ago the other half of my working life changed. On 2 August Anthropic began embedding an invisible watermark in text generated by its newer models, woven into the words themselves, travelling with the text when it is copied and pasted and persisting through some amount of editing afterwards. The trigger was European regulation, because Article 50 of the EU AI Act came into force on the same day and requires exactly this. The marking itself sits in the models rather than in a regional setting, which is why it reaches work like mine.
So the machine now leaves a permanent mark on everything it touches, and I leave none at all.
If someone accused me tomorrow of not having written this, I am not certain what I would produce.
That asymmetry is what I cannot stop turning over, and it is not a personal problem. It is arriving in your organisation on exactly the same terms, and rather sooner than you would like.
Read what the watermark actually claims, because it is narrower than the headlines suggest. Anthropic is careful about this, and the care is the interesting part. The mark shows that a model was involved. It does not show who was responsible, what was changed afterwards, or how much of the result was anyone's own thinking. It weakens on short text and heavy editing. And it says nothing at all about text that no model ever touched.
Watermark is a misleading word for it, and the misdirection matters. A watermark on a banknote is something you hold up to the light and see for yourself. This one is invisible by design. It lives in the word choices themselves: at each step the model is nudged towards one half of a secret list, and over enough text that pattern becomes too consistent to be explained by chance. You cannot see it and you cannot check it. Only the company that made the mark can read it, which is a curious thing to call transparency.
The rule behind it was written in Brussels. Article 50 binds anyone placing these systems on the European market, and because it is far cheaper to comply everywhere than to run one model for Europe and another for everyone else, the marking is simply built into the model. Anu Bradford named this the Brussels Effect in 2012. What it means in practice is that the text I dictate in Dubai now carries a European compliance decision that nobody here was asked about.
It only points in one direction. We have built something that can demonstrate machine involvement to a reasonable standard. We have built nothing that can demonstrate human involvement to any standard at all.
I have started calling this one-way provenance, because it needs a name and I have not found a better one. It has three properties, and you can test your own organisation against them this afternoon. Machine involvement is now markable, automatically, by the provider, without anyone asking your permission. Human involvement is not markable at all, and nobody is building that. And your own retention policy, the one you were right to write, widens the distance between the two every quarter it runs.
Meanwhile the conversation has become an arms race about detection. Can the watermark be stripped, how reliable are the detectors, which tool catches which model, what happens when you paraphrase.
Those are real engineering questions and I follow them with interest. They also assume that the question being asked is whether a machine was involved.
For almost everyone reading this, that is not the question you will be asked. You will be asked whether the work was yours, whether a person genuinely decided, and whether you can show it. No detector answers that. A detector can only ever tell you what a machine did, and your problem is proving what a human did.
Here is where it becomes uncomfortable, and it is uncomfortable because the policy that removed your evidence is one you wrote deliberately and were praised for.
Data minimisation. Retention limits. Do not log what you do not need. Delete after ninety days. Anonymise wherever you can. Every one of those is good practice, several are legal obligations, and I have recommended all of them to clients in the past two years without hesitating.
Every one of them also destroys the record you would need to show how a decision was reached, or that a person was meaningfully involved in reaching it.
We spent a decade teaching organisations that keeping less is safer. That was true while the risk was a breach. It stops being true the moment the risk becomes an accusation, and that is the shift that happened while we were all looking at model capability.
I have put some version of this question to close to fifty people this year, at conferences, over dinners, across boardroom tables in this region and outside it. I am still waiting for an answer that was not a description of a policy.
The regulatory answer taking shape in this region has gone in a noticeably different direction, and it is worth understanding even if you never intend to do business here.
DIFC Regulation 10 does not ask anyone for a label. It asks for registers of processing activities, for evidence of audit and certification compliance, and for mechanisms capable of triggering human intervention where there is unfair impact, discriminatory bias or unlawful processing. It has been on the books since late 2023 and moved into enforcement this January. In April the DIFC announced its intention to become the first AI-native financial centre in the world, and this is the same jurisdiction that appointed the world's first minister for artificial intelligence, in 2017, when most governments were still deciding whether the subject warranted a working group.
Marking the machine can be satisfied with a technical standard and a deadline. Being able to evidence the human has to be designed into the way information moves through an organisation, which takes years, costs money in places that never appear in an announcement, and photographs badly. It is also the only one of the two that answers the question you will actually be asked.
And it is the answer nobody exports. Europe's arrived here inside a model update that nobody consulted anyone about. This one stops at the border of the jurisdiction that wrote it.
Once you can no longer read the work and tell, judgement moves to whatever record was kept while the work was being made. That record is either structured, connected and traceable, or it does not exist. There is no version of this where you assemble it afterwards.
In May a short story won a regional Commonwealth prize and its author then spent a month proving that he had written it. The investigation never examined the story. It examined his working drafts, his time-stamped documents and his notes, and he was cleared because he happened to have kept them. The reason his process looked suspicious in the first place is that he dictates on a phone, because chronic illness makes typing at a desk impossible for him.
I dictate too, which is why I have taken that one personally. He had a trail. On the evidence of the last ten days, I do not, and neither does the decision your organisation made last quarter.
If someone put it to your organisation this week that a decision you made last quarter had actually been made by a system, and that the person who signed it had done so as a formality, what would you produce?
Not to prove the outcome was right. That is the easy question and it is not the one you would be asked. To prove who decided, on what basis, and that a human being could have reached a different conclusion and would have been free to.
Most organisations meet that gap for the first time under pressure, with a supervisor in the room and counsel on the phone. It is a considerably cheaper thing to meet on an ordinary Wednesday, on your own terms, with nobody watching you find out.
I am aware that this cuts against a decade of my own advice, and I have not fully resolved it. Keep less remains right for privacy. Keep enough to prove what happened is right for accountability. Those two are now in direct tension, in every architecture I work on, and anybody who tells you there is a clean answer is selling something.
What I am fairly sure of is that the tension is real, that almost nobody has named it yet, and that the organisations which work it out deliberately will be in a much better position than the ones that discover it during an investigation.
So I would rather ask you something than tell you something.
When did your organisation last have to prove how a decision was reached, rather than that it was correct? I am genuinely interested in the answers, including the ones where it has not come up at all, because I suspect that is most of them and I would like to know whether I am right.
Could your own foundation answer that question? An honest look at whether the route to a decision survives scrutiny, across the eight domains where a foundation either holds or quietly gives way.
Take the Capability IndexAnthropic states the mark is not conclusive: it indicates that a model was involved, not who was responsible or what changed afterwards.
The Signal & The Noise
A fortnightly read on what is actually changing in AI across the UAE and the Gulf, written personally. No content calendar, no generated filler.