ーWho may detect AI in public recordsー

August 25, 2026

Japan Institute for Crisis Management

Author: Miho Funayama

Independently adapted from the Japanese original (published August 15,  2026) — not a direct translation.

This report reflects information published as of 16 August 2026.


In August 2026, a frontier AI provider began embedding machine-readable watermarks in the text its models generate, and chose to do so everywhere in the world rather than only in the European Union. The obligation that prompted this is European. The marks it produces are not confined to Europe. Neither, therefore, is the question of what those marks mean when they appear in another state’s public records.


Key Findings

1. The marking travels. The right to detect it does not.

The EU Code of Practice on Transparency of AI-Generated Content requires signatory providers to make a detection mechanism available, in principle free of charge, and guarantees free and unrestricted access to regulators, law enforcement, media, fact-checkers, researchers and civil society. That guarantee is anchored in an EU instrument. A government outside the EU has no standing under it. Where a provider applies marking globally — as at least one now does — the mark reaches public records in jurisdictions that have no corresponding claim on the means to read it.

2. There are three dates, and two of them are still ahead.

Article 50 obligations took effect on 2 August 2026. Marking and detection obligations for generative systems already on the market were deferred to 2 December 2026. Interoperability of watermark detection is required by 2 February 2027. Any government wishing to secure detection access has a window defined by those dates, not by its own legislative calendar.

3. Roughly 190 organisations have signed the Code. This is not one company’s decision.

As of 31 July 2026, the European Commission reported approximately 190 signatories. Anthropic, OpenAI, Google, Meta, Microsoft and Mistral are among them. The structure this report describes — marks that only the provider can currently read — is a property of the technique, not of any single firm.

4. The mark is a poor instrument for accusation, and a worse one for exoneration.

Provider documentation is explicit that detection indicates possible processing, not authorship. It is equally explicit that absence of detection proves nothing: watermarking is sparse in factual, formulaic passages, and proofreading a human draft may leave too few provider-chosen words to register at all. Government prose is disproportionately of this kind.

5. Japan is a worked example, not a special case.

Japan’s government-wide AI platform serves approximately 180,000 officials, runs frontier models from a signatory provider, already includes an application for editing official-style documents, and has a Diet-answer drafting application scheduled for development within the fiscal year. Its records-management guidance takes effect on 1 September 2026 and contains no provision addressing machine-readable marks. The same three questions this report puts to Japan can be put to any government.

6. EU member states are better placed, but not exempt.

Member-state authorities have standing to demand detection access. That resolves the second of the two gaps identified here. It does not resolve the first: whether a national regime for public records contemplates marks embedded in official documents. Standing to read a mark is not the same as a rule for what to do when one is found.


Contents

1. What was decided, and by whom

2. The asymmetry: marking travels, the right to detect does not

3. Three questions to ask about AI watermarks in your public records

4. Japan, as a worked example

5. What the mark proves, and what it does not

6. Why EU member states are not exempt

7. Implications

References


1. What was decided, and by whom

Figure 1: AI watermark public records timeline showing three EU deadlines

Figure 1  Three dates, and what each one governs

[Confirmed Fact] On 20 July 2026 the European Commission published its finalised guidelines on the implementation of Article 50 of the AI Act, completing a framework that also includes the Code of Practice on Transparency of AI-Generated Content. The obligations broadly took effect on 2 August 2026. Providers of AI systems that generate synthetic text, audio, image or video must mark outputs in a machine-readable format detectable as AI-generated, using technical solutions that are effective, interoperable, robust and reliable. Penalties reach the greater of EUR 15 million or three per cent of worldwide annual turnover [1].

[Confirmed Fact] Two deferrals matter more than the headline date. Marking and detection obligations for generative systems already on the market were postponed to 2 December 2026. Interoperability of watermark detection mechanisms — so that content can be verified without running each provider’s detector separately — is required by 2 February 2027 [1].

[Confirmed Fact] On 10 August 2026, Anthropic published its approach to marking AI-generated content, confirming that it has signed the Article 50(2) Code as a provider of both models and systems. Models released on or after 2 August 2026 support marking at launch; older models fall under the legal transition period, with support being added. Marking applies across the company’s products and wherever its models are offered, including access through major cloud platforms [2].

[Confirmed Fact] On 14 August 2026, the company published a technical explanation. Its text watermark is a version of the SynthID-Text approach that Google DeepMind described in Nature in 2024, itself descending from a 2022 proposal. Global application was adopted because the company does not yet have a durable method of scoping the watermark by region; other approaches remain under evaluation. A detection API is planned, with implementation details still being worked out. Rollout to older models is described as taking place over the coming months [3].

[Confirmed Fact] As of 31 July 2026, approximately 190 organisations had signed the Code, including Anthropic, OpenAI, Google, Meta, Microsoft and Mistral [1].

[Inference] The significance of the second and third dates is easy to miss. A government reading only the 2 August headline may conclude that whatever was going to happen has happened. It has not. For models already deployed inside government systems — which is to say, most of them — the operative date is 2 December 2026. For the ability to verify marks across providers without bilateral arrangements, it is 2 February 2027. Both are procurement horizons, and both are close.


2. The asymmetry: marking travels, the right to detect does not

[Confirmed Fact] The Code goes beyond the marking obligation in the Act itself. It requires signatory providers to make available a mechanism for detecting AI-generated or manipulated content. That mechanism must in principle be free of charge. Providers below one million monthly users may charge a reasonable fee for high-volume requests where detection imposes substantial cost. But regulators, law enforcement, media organisations, fact-checkers, researchers and civil society must always have free and unrestricted access [1].

[Confirmed Fact] At the time of writing, no general detection capability is publicly available from the provider discussed above. The company states that a detection API is planned and that implementation details are being settled [2][3].

[Inference] Set these two facts beside the decision to mark globally, and an asymmetry appears that no party appears to have designed.

The mark is applied on the basis of a commercial decision about engineering convenience — the absence of a durable way to scope by region. It therefore lands in Tokyo, Ottawa, Canberra, Seoul and Brasília exactly as it lands in Dublin. The right to demand the means of reading it, however, rests on an EU instrument, addressed to EU authorities. A Japanese ministry, a Canadian department or a Korean agency is not a regulator within the meaning of the Code. It has no claim.

This is not a complaint about the Code, which was drafted to govern the European market and does so. It is an observation about what happens when a technical measure designed for one jurisdiction is deployed across all of them. The obligation is European. The mark is global. The entitlement to detect is European again.

[Inference] The practical consequence is narrow but real. If a mark is found in a government document, the finder will in the first instance be someone with detection access — a researcher, a journalist, an EU authority — and not the ministry that produced the document. A government that has not secured its own access will learn about the contents of its own public records from outside.

[Scope Note] Nothing in this section should be read as suggesting that watermarking transmits document content. Provider documentation states that the watermark and its key contain nothing from which information about a user, their organisation or their conversations could be recovered [3]. The technique biases word selection during generation; it does not communicate. The question here is not leakage. It is who can read a mark in the public records that a state’s own law never asked to be created.


3. Three questions to ask about AI watermarks in your public records

[Inference] The following three questions are answerable from public documents in most jurisdictions. They are set out here so that readers can apply them to their own administrations rather than to Japan’s.

Question 1 — Which models sit inside your government’s AI platform, and are they in scope?

Identify the models available to officials on any centrally provided AI platform. For each, establish two things: whether its provider has signed the Code, and whether the specific model version was released before or after 2 August 2026. Models released before that date fall under the transition period; the operative deadline for them is 2 December 2026, not August.

Then ask the question that public documents rarely answer: when is the platform’s model roster next scheduled to change? A single model refresh can move a platform from out of scope to in scope without any policy decision being taken.

Question 2 — Can your government detect the mark independently?

Watermark detection of this kind requires a key. Without it, detection is not merely difficult but unavailable. Establish whether any national body — a records authority, an AI safety institute, a technical agency — holds or has requested detection access from the providers used in government.

If the answer is no, the follow-up question is where that capability would sit if acquired, and whether the forthcoming interoperability requirement of 2 February 2027 offers a route to obtaining it.

Question 3 — Does your law on public records contemplate machine-readable marks?

Most records-management regimes were drafted around questions of authorship, retention, classification and disclosure. Few contemplate a machine-readable signal embedded in the text of a record by a third party under foreign law.

Three sub-questions follow. Is the presence of such a mark itself a fact subject to disclosure on request? If the administration cannot detect the mark, can it discharge a duty to explain what its records contain? And if a third party acquires detection capability first, what is the position when the existence of a mark in an official document is reported from outside government?


4. Japan, as a worked example

[Scope Note] Japan is examined here because its position is documented, current and answerable — not because it is unusual. The Japanese-language edition of this report treats the domestic policy questions in full; this section presents only what is needed to show the three questions producing answers.

Question 1, answered

[Confirmed Fact] Japan’s Digital Agency operates a government-wide generative AI environment developed in-house and in service since May 2025. Published materials list four selectable models: one from Amazon and three from Anthropic. The same materials note that additions and updates to the model roster are planned. The platform is in large-scale trial across all ministries, covering approximately 180,000 officials, with around 100,000 able to use it as of late May 2026 [4][5].

[Confirmed Fact] Three of the four are from a Code signatory. All three were released before 2 August 2026 and therefore fall within the transition period. The fourth is from a provider not reported among the signatories.

[Confirmed Fact] The model list carries a temporal qualifier: it describes the position as of March 2026. Whether the roster has since changed cannot be verified externally.

[Inference] Japan’s answer to Question 1 is therefore: probably not yet in scope, on the basis of five-month-old public information, with no external means of confirming the present position, and with two independent routes by which scope could arrive — a roster update, or the provider’s rollout to existing models. Neither is a Japanese decision.

Question 2, answered

[Confirmed Fact] No Japanese body is publicly identified as holding detection capability for the marks in question. The provider’s detection API has been announced but not released [2][3].

[Confirmed Fact] A route exists. In December 2025 the Prime Minister directed a substantial expansion of Japan’s AI Safety Institute, with a target scale comparable to the United Kingdom’s [4]. An institution capable of holding detection keys is already a stated policy objective.

[Inference] Japan’s answer to Question 2 is: no, and the gap is not closed by the announcement of an API that has not shipped. What the announcement changes is the nature of the ask. The requirement is no longer to induce development; it is to secure access at the point of procurement.

Question 3, answered

[Confirmed Fact] Japan’s Digital Agency adopted version 2.0 of its guideline on the procurement and use of generative AI in government on 12 June 2026, with effect from 1 September 2026. The guideline is normative for government information systems [6].

[Confirmed Fact] It addresses disclosure: procurement requirements specify that where a generative AI system is used by the general public outside the ministry, users must be able to distinguish system output from human-originated information. It addresses records status: documents created by officials using generative AI become administrative documents where held for organisational use. It even addresses foreign law, noting that servers located abroad are subject to local law and to the possibility of censorship or seizure [6].

[Confirmed Fact] On a full reading of the main text and its four annexes, it contains no provision on watermarking, provenance metadata or machine-readable marking. Verifiability, explainability and traceability are treated at length. The prospect of a mark embedded in the output itself is not addressed [6].

[Inference] This is not a drafting failure. On 12 June, the provider announcement of 10 August did not exist. The gap between decision and entry into force is where the technical premise changed. Japan’s answer to Question 3 is: no, and the instrument that would carry such a provision comes into force before the question has been put.

[Confirmed Fact] Two further facts sharpen the case. The platform already includes an application for editing text into official document style, aligned to national guidance on public-sector writing. And a Diet-answer drafting application — described as generating draft answers to parliamentary questions, funded within a supplementary budget line and contracted for the period April 2026 to March 2027 — is scheduled for development within the fiscal year [4].

[Inference] The two timelines converge. The period in which marking is expected to reach the platform and the period in which an answer-drafting application is scheduled to be built are the same fiscal year.


5. What the mark proves, and what it does not

[Confirmed Fact] Provider documentation is unusually direct about the limits of detection. A detected mark indicates that the model may have processed the content; it does not establish authorship. Content may have been altered, excerpted or combined after processing. Conversely, absence of a mark establishes nothing: outputs from models predating marking support, heavily edited or paraphrased text, and passages too short to carry a reliable signal may all escape detection [2].

[Confirmed Fact] The technical explanation published on 14 August adds two refinements that matter for public administration. Where the model proofreads text written by a person, nearly all the returned words are the person’s own, leaving little for the watermark to attach to; depending on length and the extent of editing, the result may not be detectable. Translation is different: every word is model-chosen, and the watermark is carried. And watermarking is sparser in factual passages, where fewer alternative wordings are available [3].

[Confirmed Fact] The Commission’s guidelines reach a compatible conclusion by a different route. Systems performing an assistive function for standard editing, or not substantially altering input data, fall outside the Article 50(2) marking obligation; grammar and spell-checking and format conversion are given as examples. Short outputs are similarly excluded, and the Code exempts text below roughly 200 tokens from the watermarking requirement [1].

Figure 2: AI watermark public records detection versus actual AI use

Figure 2  What a detected mark establishes, and what it does not

[Inference] Read together, these establish a proposition that any government should internalise before detection becomes widespread. Official prose is among the text least likely to carry a detectable mark. It is formulaic, factual, frequently short, and often produced by editing rather than generation. A ministry that treats absence of a mark as evidence of non-use will be wrong routinely.

[Inference] The corollary is the more important half. If the mark is unreliable as proof of use, it is equally unreliable as proof of non-use — and it is therefore useless as an instrument of accusation in either direction. The risk is not that officials will be caught. The risk is that a poorly understood signal becomes a subject of public dispute, and that officials respond by avoiding a permitted and useful tool. Establishing what the mark does not mean, before anyone can read it, is the cheapest available intervention.

[Confirmed Fact] One further element of the Code deserves attention from governments in particular. Article 50(4) requires deployers who publish AI-generated or manipulated text for the purpose of informing the public on matters of public interest to disclose that fact, subject to an exception where the text has undergone human review or editorial control by a responsible person. The Commission construes the public-interest trigger broadly, covering politics, public health, consumer safety, the environment and scientific developments; the editorial exception is set at a high bar, and cursory sign-off does not meet it [1].

[Inference] Government communication is public-interest text almost by definition. Within the EU, a public authority publishing AI-assisted material on such matters is a deployer with a labelling duty, and the provider’s machine-readable mark does not discharge it. Outside the EU, no such duty exists — but the drafting is available as a model, and it is a more precise instrument than any this report’s authors have found in national records law.


6. Why EU member states are not exempt

[Inference] It would be a comfortable conclusion that this is a problem for third countries, and that within the Union the framework closes on itself. It does not.

Member-state authorities do have what others lack: standing to require detection access, free and unrestricted, under the Code. That answers Question 2 in the affirmative. It is a material advantage and non-EU governments should note the terms on which it was obtained.

But Question 3 is a matter of national records law, and Article 50 does not speak to it. The Act regulates providers and deployers of AI systems. It does not amend any member state’s rules on what an official document is, what its attributes are, or what must be disclosed about it on request. A German or French ministry using a marked model produces marked public records under the same national archival regime that existed before, and that regime is no more likely than Japan’s to have contemplated a machine-readable signal embedded in the text.

[Inference] The gap is therefore narrower inside the Union — one of two questions is answered — but it is the same gap. And the sequence matters: member states will acquire the ability to detect marks in their own records before they have decided what the presence of a mark means. That is an unusual order in which to arrive at a policy question, and it argues for settling the second question early rather than discovering it through the first.


7. Implications

Three conclusions follow.

The relevant deadlines are not domestic. A government’s window for securing detection access is bounded by 2 December 2026 and 2 February 2027 — dates set in Brussels for reasons unconnected to any other state’s legislative calendar. Where the necessary instrument is a procurement requirement rather than a statute, as it generally will be, this is achievable. Where a records-law amendment is thought necessary, it is not.

The correct ask is access, not development. A detection API has been announced. Other signatories are subject to the same Code and the same interoperability requirement. The question for procurement is therefore not whether detection will exist, but whether a given government will be positioned to use it — and, if the answer depends on a mechanism drafted to serve EU regulators, what alternative standing can be constructed. Key escrow with a neutral national body is one available answer; contractual undertakings at the point of procurement are another; both are cheaper now than after the fact.

The mark should be demystified before it becomes readable. On the evidence, official documents are among the least likely text to carry a detectable mark, and detection failure will be common. A government that has published nothing on what an AI watermark in public records means will find the interpretation supplied by others. The most consequential act available in the next several months is not technical. It is a short, accurate statement of what a detected mark does and does not establish, issued before anyone is in a position to make the finding.

[Inference] A closing observation on the shape of the problem. The four-layer framework this institute has used in previous reports treats sovereignty over models, weights, compute and power as separable dependencies [7][8]. The present case belongs to none of them cleanly. What is at stake is not who holds the weights, nor who supplies the compute, but who may read the provenance of an artefact after it has been produced. That is a fifth thing, and this report raises it without settling it.


References

[1] European Commission, guidelines on transparency obligations under Article 50 of the AI Act (20 July 2026) and the Code of Practice on Transparency of AI-Generated Content. Summarised in Paul, Weiss, “EU Finalises Transparency Rules for AI-Generated Content,” 4 August 2026 (deferrals to 2 December 2026 and 2 February 2027; detection mechanism and free access for regulators, law enforcement, media, fact-checkers, researchers and civil society; ~190 signatories as of 31 July; carve-outs for assistive editing and short outputs; Article 50(4) labelling and the editorial exception).

https://www.paulweiss.com/insights/client-memos/eu-finalises-transparency-rules-for-ai-generated-content

Primary sources: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems and https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content

[2] Anthropic, “How Claude marks AI-generated content,” Claude Help Center, updated 10 August 2026.

https://support.claude.com/en/articles/16266773-how-claude-marks-ai-generated-content

[3] Anthropic, “How Claude’s text watermark works,” 14 August 2026 (SynthID-Text lineage; global application pending a durable regional scoping method; detection API planned; rollout to older models over the coming months; proofreading and factual passages).

https://www.anthropic.com/news/claude-text-watermark

[4] Digital Agency, Government of Japan, reference materials on the deployment status of the government AI platform, May 2026 (in Japanese). Application list as of 29 May 2026; four selectable models with additions and updates planned; official-document editing application; Diet-answer drafting application scheduled for development within FY2026; supplementary budget line and contract period; December 2025 direction on expansion of the AI Safety Institute.

https://www.digital.go.jp/assets/contents/node/information/field_ref_resources/fc155eba-e83d-4ecf-9c6a-a3c855e2e7b3/d0d53b25/20260528_news_genai_outline_01.pdf

[5] Nikkei xTECH, report on the 180,000-user government generative AI trial, 2 April 2026 (in Japanese).

https://xtech.nikkei.com/atcl/nxt/column/18/00001/11637

[6] Digital Agency, Government of Japan, Digital Society Promotion Standard Guideline DS-920, “Guideline on the Procurement and Use of Generative AI for the Advancement and Innovation of Public Administration,” version 2.0, adopted 12 June 2026, in force 1 September 2026 (main text and annexes 1–4, in Japanese).

https://www.digital.go.jp/assets/contents/node/information/field_ref_resources/decb64eb-f26e-41cb-8d37-f3dd173108b8/59054b35/20260612_resources_standard_guidelines_guideline_01.pdf

[7] Japan Institute for Crisis Management, “Four Layers of AI Sovereignty: What Japan’s Noetra (FRONTia Project) Reveals About National AI Strategies,” English edition, 22 July 2026.

https://inst-ds.org/cyber-security/2065

[8] Japan Institute for Crisis Management, “Struck, Suspended, Converging: The Four Layers of AI Sovereignty Under Stress,” English edition, 4 August 2026.

https://inst-ds.org/cyber-security/2185

[9] Dathathri, S., See, A., Ghaisas, S. et al., “Scalable watermarking for identifying large language model outputs,” Nature 634, 818–823 (2024). doi:10.1038/s41586-024-08025-4

https://www.nature.com/articles/s41586-024-08025-4

[10] Japanese edition of this report: 「行政文書に、見えない印が付くことが決まった――生成AIの電子透かしと政府AI基盤『源内』。残された時間を、日本は測れない」15 August 2026. Domestic policy recommendations and four proposed parliamentary questions are set out there in full.

https://inst-ds.org/ai/2196


Note on the preparation of this report

This report is concerned with transparency about AI use, and its authors judged it consistent with that subject to disclose their own process. Generative AI was used in locating and organising primary sources and in preparing drafts. The selection of questions, the choice and weighting of sources, the separation of established fact from inference, and the conclusions are the author’s. Responsibility for any error is entirely the author’s.

Given the specifications discussed above, this text may itself carry a machine-readable mark. As set out in section 5, such a mark would indicate possible processing and nothing about the origin of the analysis or the identity of the judgement behind it.


Author: Miho Funayama

Miho Funayama is a strategic analyst specializing in international standardization, technology intelligence, intellectual property analysis, and geopolitical and crisis risk management. She holds a degree in International Politics from Sophia University and completed graduate studies in International Political Economy, Philosophy, and Psychology at Aoyama Gakuin University. She previously led patent research and strategic analysis on international standards and emerging technologies at Canon Inc., where she served as Deputy International Secretary of ISO/IEC JTC 1/SC 28 and received the ITSCJ Award for Contribution to International Standardization three times. She is currently a Director and Chief Researcher at the Japan Institute for Crisis Management, a Fellow at the Institute of Middle East–Asia Information Strategy, and a Professional Associate Member of the Foreign Correspondents’ Club of Japan.

Her research focuses on the intersection of cybersecurity, geopolitical risk, and information warfare, examining decision-making structures and psychological operations through an interdisciplinary lens spanning international politics, philosophy, and psychology.


This paper is based on analysis of publicly available information. Citations use only real, verifiable URLs referenced in the text and reference list. Facts not confirmed in primary sources are explicitly flagged as such. Facts and inference are explicitly distinguished throughout.