A designer I know got an email last week that ruined her Tuesday. Client had run her proposal through some detector, gotten a number back, and wanted to know why she was billing senior rates for machine output.
She did write it. She'd used an assistant to clean up two paragraphs in the middle and then rewrote most of that anyway. The honest answer was somewhere around "ninety percent me," which is the worst possible answer to give out loud because it sounds exactly like what a person would say if the real number were ten.
She had no way to prove any of it. No drafts saved, no version history worth showing, nothing but her word against a confidence score from a tool neither of them understood.
That's the whole problem in one email. Not the technology. The moment somebody asks and you have nothing to hand them.
I wrote a few weeks back about finding every place machine written text leaves your business. That was inventory work. This is the part after inventory, and it's the part that costs money: what happens when one of those places gets challenged, and whether you have anything that survives the challenge.
The window you're standing in
Quick refresher on where things actually stand, because the reporting on this got muddy fast.
Anthropic started embedding invisible watermarks in Claude's text output on August 2, 2026. Applies worldwide, no opt out, across the app, the API, Claude Code, and the cloud partner versions. Files get signed provenance metadata using the C2PA standard, which is the same scheme Adobe and the BBC and a pile of camera manufacturers already use for images.
The driver is Article 50 of the EU AI Act, whose transparency obligations kicked in the same day. Anthropic signed the Code of Practice that goes with it. Penalties for getting this wrong run to fifteen million euros or three percent of global turnover, which explains the enthusiasm.
Here's the part almost nobody picked up. The marking applies to models launched on or after August 2. Everything released before that date is unmarked, and the company has until December 2, 2026 to add support during the transition period.
Do the math on that. Depending on which model you're actually calling, a meaningful share of what you produced this summer carries no mark at all. Some of what you produce next month will. By December the gap closes.
So for the next ninety days or so, "is this marked" and "is this machine written" are two different questions with two different answers, and almost nobody asking you the first one understands they're not asking the second.
That asymmetry is the whole risk. It cuts in both directions and neither one is good for you.
If your work is unmarked, that proves nothing. Anthropic says so plainly in their own documentation: unmarked content doesn't mean a human made it. Older models, other vendors, heavy editing, a copy paste through a format that strips metadata. Any of those produce clean output from machine origin.
If your work is marked, that also proves less than people think. Run a human written paragraph through an assistant to fix the grammar and the result can carry a mark. Translate your own work and it can carry a mark. Ask for a summary of something you wrote and it can carry a mark. The signal says a model touched this. It does not say a model wrote this, and it certainly doesn't say you didn't.
Anthropic documented that limitation clearly. The number of clients, platforms, and procurement officers who will read that documentation before firing off an accusatory email is approximately zero.
What the audit is actually for
The audit isn't about scrubbing marks out of your work. Don't do that, it's a losing game and it makes you look like someone with something to hide.
The audit is about knowing, in advance, which relationships in your business could survive that email and which ones couldn't.
Sit down with a blank page. Give it ninety minutes. You're building three columns.
Column one: every artifact that leaves your business carrying an implied claim of authorship. Not everything you write. Specifically the things where somebody is paying for, or evaluating, the fact that a person made them.
That's client deliverables and proposals. Bids and RFP responses. Grant applications. Anything you submit to a marketplace or platform with an originality policy. Course material and paid content. Expert testimony, reports, assessments. Bylined articles. Anything a lender, an insurer, or a regulator might read.
Your internal Slack summaries are not on this list. Your meeting notes are not on this list. Nobody is going to challenge the authorship of your grocery order. Keep the list to things where the answer to "who wrote this" would change what somebody pays or decides.
Most small businesses land somewhere between six and fifteen items. If yours is longer than twenty you're padding.
Column two: what the contract or policy actually says. Go read them. Not what you remember, what they say.
You're looking for three things. Does it require original work, and how does it define original. Does it say anything at all about AI assisted work. Does it give the other party a right to audit, reject, or claw back based on that.
This is where most people find their real exposure, and it's rarely where they expected. The scary clause is almost never a specific AI prohibition. It's the old boilerplate about original work product that predates any of this and gets read by a nervous client in the worst possible light.
Column three: what record you could produce. For each item in column one, what would you actually send if somebody asked you to show your work? Right now, today, without going back and manufacturing anything?
For most people the honest answer for most items is "nothing." That's fine. That's what the column is for. Now you know which ones matter enough to fix.
What a record actually looks like
Here's the good news. The bar is lower than you think.
Nobody in a normal commercial dispute is running forensics. They're looking for a reason to believe you. Give them a reason and this ends in one email.
A defensible record is basically three things.
Timestamped drafts that show change over time. Not a final file. A sequence. Google Docs version history does this for free and most people already have it and never think about it. So does the revision history in Notion, a Clay style running record of who you talked to and when, or a folder of dated files, or commit history if you work that way. The point is the shape of the thing: something rough at 9am, something better at 2pm, something different again on Thursday.
Machine output doesn't have that shape. It arrives whole. A messy trail is worth more than a perfect document, which is a sentence I'd like tattooed on a few people.
A note on process, written before anybody asks. Two sentences per project. What you used, for what part, and what you did after. "Used an assistant for the first pass on sections three and four, rewrote both, wrote everything else from the interview notes." Keep it in the project folder.
Writing this after an accusation looks like exactly what it is. Writing it as routine practice looks like routine practice, because it is.
The source material. The interview recording, the client call, the research notes, the earlier project you pulled from. Whatever fed the thing. This is usually the single most persuasive item because it's the hardest to fake and the easiest to check.
Notice that none of this requires new software. You're not buying a provenance platform. You're deciding to keep three things you were probably throwing away.
THE SYSTEM BEHIND THIS
The AI Workflow Blueprint includes the exact folder structure, the two sentence process note template, and the automation that files drafts and source material without you thinking about it. It's the system I run on every piece of client work, built so the record exists whether or not anybody ever asks for it.
The contract conversation nobody wants to have
Now the uncomfortable part.
Somewhere in your client list is a contract that says original work product, signed in 2023, that you are currently in technical violation of according to a strict reading nobody has applied yet.
You have three options and you should pick one on purpose rather than by default.
Say nothing and hope. Legitimate choice for low value, low risk, nearly finished relationships. Not a strategy for anything ongoing. The problem with hope is that it stops working at the worst possible moment, usually during a renewal negotiation when the other side is already looking for leverage.
Raise it yourself, on your terms, before anybody asks. This is the one I'd pick for anything you want to keep. It's a short conversation and it goes better than people expect, because you're the one framing it.
Something close to: "Quick housekeeping. I use AI assistance in parts of my process, mostly research and first drafts, and everything I send you gets rewritten and checked by me. I keep drafts and source material on every project. Wanted to name it rather than have it come up sideways later. Happy to put language in the agreement if that's useful."
That's it. Most clients say some version of "yeah, obviously, everyone does." A few ask good questions. One in twenty has a policy you need to work around, and finding that out now is worth a hundred times more than finding it out in month nine.
Change the contract. For high value or regulated work, get actual language in. Define what assistance means, state what you do, state what you keep. You want a lawyer for this and it's cheaper than you think.
The thing I keep telling people: the marking is not the risk. The risk is that a technical signal with real limitations is about to get treated as proof by schools, employers, platforms, and clients who will never read the caveats. You don't control that. You control whether you have an answer ready.
What to do with the ninety days
Between now and December, the window is open. After December, most things you produce carry a mark, and the question shifts from "can they tell" to "what do you say about it."
That's actually a better place to be. Ambiguity is worse for you than clarity. Right now you're in the awkward middle where nobody knows anything and everybody's guessing.
So use the window for the boring work.
This week, do the three column audit. Ninety minutes, one page.
Next week, fix the record keeping on whatever landed in column three with nothing next to it. Turn on version history where it's off. Make a folder. Start the process note habit on the next project rather than retroactively on the last twelve.
The week after, have the contract conversation with your top three clients by revenue. Not all of them. Three. The ones where losing the relationship would actually hurt.
And then stop thinking about it. Genuinely. This is a housekeeping problem that got treated like an existential one because the headlines were dramatic. It's a folder, a habit, and three conversations.
The designer whose Tuesday got ruined? She got the client back. Took two weeks and a lot of goodwill she'd rather have spent elsewhere. What actually closed it was an old recording of the discovery call where you can hear her working out the exact argument the proposal makes, six weeks before the proposal existed.
She still has that recording because she never deletes anything. Which is not a system. It's a habit that happened to save her.
You can do better than luck. It takes an afternoon.
BUILD THE WHOLE SYSTEM
The AI Business Accelerator is the full build. Six weeks, the complete operating system, including the governance layer most small businesses skip until something breaks: what gets documented, what gets kept, what gets said out loud, and who decides. Built for people running real businesses, not people collecting frameworks.
Jordan
The AI Newsroom is written by Jordan Hale. This issue contains affiliate links to tools I actually use. If you sign up through them I may earn a commission at no extra cost to you.

