Say you want to build a coding agent. You are confident and somewhat full of yourself, and you think you can do it better than everyone else. When Silicon Valley talks about the next billion-dollar one-man unicorn built on AI, you assume they are talking about you. So: no team of humans. It will be you and the AIs.
You are also a creature of habit. You jumped on the coding-agent hype the moment it was out, and you now do essentially everything inside one. You plan romantic dates and write angry blog posts there. You even built your own tool that runs different coding agents against each other, so one can supervise the other.
So naturally, you go to a coding agent and start writing a design doc. This time it happens to be Claude Code — the most popular one. It has some design problems, and it is fantastically loop-engineered, but you are used to its quirks and at this point see all of them as spice for the relationship.
You are diligent, so you do the diligent thing before building a project on someone else’s platform. You read the terms.
The terms say you own the outputs. Good. They also say you may not use the service, or its outputs, to train a competing AI model without permission. Less good, but fair enough. It is understandable that Anthropic wants to protect the hard work that went into making these models. Right?
But something indeed feels not right about the terms. The terms say you may not launder the outputs of this system into yours.
You recognize this argument. It is eerily similar to the argument every author, journalist, and researcher makes about the training data that went into all AIs. So you start remembering things.
Here is what you remember. Starting in 2021, Anthropic co-founder Ben Mann downloaded 196,640 books from Books3, then at least five million from Library Genesis, then at least two million from the Pirate Library Mirror. These were pirated copies. Then the book authors, failing to appreciate that Anthropic was busy curing cancer and did not have time for this, sued. One of the lawsuits landed in front of Judge William Alsup, whose June 2025 order in Bartz v. Anthropic even records CEO Dario Amodei describing a desire to avoid “legal/practice/business slog.”
By 2024 the company had become less willing to train on pirated books for legal reasons, so it hired Tom Turvey, who had led partnerships for Google Books, to acquire “all the books in the world.” Anthropic then bought millions of print books, sliced off their bindings, scanned the pages, and threw the paper away. The digital copies it kept.
Today, book acquisition has become something of a tradition in the AI industry. In August 2026, 404 Media put a tracker inside a rare book in a bulk shipment and followed it to an Amazon AI-training facility in Las Vegas. Employees there said they received massive shipments of books, cut off the bindings to scan them, and destroyed the printed copies in the process.
The good judge sorted this into distinct uses. Training language models on books was “quintessentially transformative” and fair use. Scanning a print book you’d lawfully bought was kosher too: one internal digital copy for one physical one. But the general-purpose library assembled from pirate sites was “inherently, irredeemably infringing,” because the books were not paid for. Luckily for the authors, the order did not foreclose claims built on different facts: Alsup wrote that they remained free to sue if infringing outputs emerged. His thought process and the defense arguments were nonetheless noteworthy. According to the judge, the AI models were like schoolchildren reading books, so as long as you pay for the book, you can read and educate yourself as much as you want.
The piracy claims never went to trial. In July 2026, a different judge gave final approval to a $1.5 billion class settlement covering the LibGen and PiLiMi works. The settlement resolved those claims without touching Alsup’s ruling on training. It released only the input side: the downloading, the copying, the training runs, everything up to the point of model output—and only through August 25, 2025. It expressly left every claim based on model outputs alive.
Two days after Alsup’s order, in the same district, Judge Vince Chhabria granted Meta summary judgment against thirteen authors in Kadrey v. Meta. Yet he took apart Alsup’s schoolchildren analogy on the way there. The analogy asked you to see the models as the children of humanity, with the lab as a responsible parent paying for their education. Chhabria instead saw a product. Teaching children to write, he wrote, “is not remotely like using books to create a product that a single individual could employ to generate countless competing works with a miniscule fraction of the time and creativity it would otherwise take.” According to Chhabria, the plaintiffs simply failed to build the stronger case: that models trained on copyrighted expression could flood the market with competing work. His order said explicitly that it did not establish that Meta’s training was generally lawful, and predicted that plaintiffs with a better evidentiary record could win.
The next cases are building that record. In July 2026, Hachette, Cengage, Elsevier, and Scott Turow filed a class complaint against Google, alleging that Google used books supplied for limited purposes, material from web scrapes and pirate sources, and copies stripped of copyright-management information to train Gemini. Finally, the complaints are starting to join acquisition, removal of source information, training, licensing markets, and competition from generated outputs into a single theory of harm.
There is also the U.S. Copyright Office, which reads the same landscape in a 2025 report and declines to give a categorical answer, treating fair use as dependent on the model’s purpose, the works copied, the source and amount of copying, the behavior of outputs, and market effects. It recommends letting voluntary licensing markets develop for now.
So the legal path does not end at “training is fair use.” There are at least three separate questions that can feed into any case: how the work was acquired, what copies were made to train a model, and what the resulting system does to the market and the ecology that produced the work.
But when Alsup reached market harm, the schoolchildren analogy did a lot of work. Take it at face value: if you pay for the book once, you don’t owe the author again every time you read it and learn something new. So why should a model owe one for learning?
A person who reads a book and becomes a writer does not just absorb the text. They enter a system that keeps track of where ideas came from:
Academics cite prior work, building genealogies of arguments.
Journalists name sources, preserving accountability and making correction possible.
Lawyers cite precedent; writers acknowledge influence in criticism, interviews, teaching, and recommendation.
All of these add to an infrastructure that sustains the system. Citations distribute reputation, reputation becomes funding and sales and invitations, and that return path is what lets the next book get written. Attribution is part of the machinery by which intellectual work reproduces itself.
A trained model participates in none of that. The text is converted into statistical relationships spread across parameters and mixed with millions of other voices. That doesn’t mean the model contains a tidy compressed copy of every book. It means the training process benefits from regularities in attributed human expression while the interface ordinarily returns no account of which works or traditions produced those regularities. A human reader is supposed to keep track of these things. And yes, individual readers forget sources all the time. But human knowledge institutions are built to keep provenance recoverable. That’s why there are things like citations, bylines, bibliographies, precedent, acknowledgments, teaching, and recommendation. If you fail to cite a source in a homework essay and get caught, you will likely face some kind of consequence. Models and their owners? The train of consequence has not yet arrived at their town.
Now, to be fair, exact attribution is genuinely difficult with current architectures. Methods exist, but they do not let you inspect the weights after the fact and recover which documents caused a sentence. Ask a model for citations post-hoc, and it may produce plausible invented ones. The usual fix is a secondary retrieval system supplying real sources, but even then the model relies on its knowledge of the unattributed patterns absorbed during training to sift through them.
But “perfect token-level attribution” is not the only standard available. In fact, the way it gets used is actively harmful. Here is the industry’s favorite excuse: ask for an impossible standard, observe that it is impossible, throw your hands in the air, and claim nothing can be done. But do not fall for it this time. Yes, output-level attribution remains an open problem. But input-level provenance is not. A provider cannot tell you which author shaped this sentence. It can tell you which books it bought, which it downloaded, from where, and under what claim of right. Software solved this decades ago: a compiled binary cannot tell you which output byte came from which dependency, so you do not ask it to. You keep a bill of materials and declare the libraries you used when their licenses ask you to. Similarly, the model does not need to say “this paragraph was influenced by this author.” It needs to be able to say “this author’s work was in the corpus, acquired thus, licensed thus.” Perfect attribution vs. none is the industry’s frame. The actual choice is between documenting what went in and choosing not to.
Most major AI companies have so far gone for the second option and kept that corpus-level provenance out of public reach. By late July 2026, ChatGPT was refusing direct requests to imitate well-known authors, including dead ones. Maybe this is respect for authors. It also closes one of the few crude windows authors had into what the machine appears to know about their work. The real ledger remains private.
Hold on to Alsup’s schoolchildren analogy some more. The process of training an AI does involve the word “learning,” but what is taught, the scale, how it is retained, and who gets to control the result are all qualitatively different from normal education. A schoolchild reads books and may later write one or ten. Anthropic turns millions of books into a system that can answer millions of people at once, then declares in that system’s terms of use that a competing model may not learn from them. This scale is a key property of AI learning. It allows building a business around AI, so you cannot dismiss it as an implementation detail as the analogy does.
Every company buys inputs and tries to sell something more valuable. Nothing is new or inherently nefarious about that. AI did not invent the capture of worker know-how into machinery. Industrial management, automation, and software have long tried to detach skill from the worker who possesses it. AI is a bet on the most general version of that ambition yet: that not only a worker’s skill but the cognition through which it is exercised can be detached from the worker, concentrated in infrastructure, and reproduced at inference scale. If the bet pays, capital has not merely made the worker more productive. It has turned the worker’s judgment into an owned capability whose value lies in not having to bring the worker back.
That bet is so attractive to capital because of a price asymmetry. A book priced for a human reader, a labeler’s judgment paid at human wages, and an engineer’s correction already covered by salary are each acquired through a bounded human transaction and then aggregated into what is promised to become a reusable capability.
Call this “capability arbitrage”: acquiring an artifact or judgment under the price and legal terms of a bounded human-scale transaction, then transforming it into machine capability reusable at another scale. Copyright may authorize the copying; a labor contract may authorize the task. Neither necessarily prices that downstream scale or gives the contributor a continuing claim on it.
Take the books. The internet was never a commons in law. Most of the books, journalism, scholarship, photographs, and software available through it remained owned, licensed, and attributed. But it functioned as a pseudo-common in practice: a distributed ecology of publicly reachable work circulating under overlapping norms of reading, quotation, indexing, research, criticism, teaching, and fair use. Those norms assumed human scale and human memory: the author’s name traveled with the work, and reputation became future sales, employment, funding, and the ability to produce more work.
AI companies found a price difference between that ecology and another system. Upstream, knowledge was dispersed, inconsistently protected, and cheap to acquire at scale. Downstream, the capability built from it could be sold through proprietary models and paid APIs. AI is a technologically roundabout way of pursuing that arbitrage. The route is genuinely complex and expensive: architectures, training systems, safety systems, and compute. That complexity is highly desirable to capital: it makes the familiar economic move underneath harder to see, while the expense narrows who can place the bet. The infrastructure does not turn the knowledge stock into the company’s property, but it gives the company control over access to the transformed stock. The difficulty of building the machine then becomes the story used to claim everything it reaches.
The books are only the first intake valve. Everything so far has been about pretraining, the text a model reads. Human judgment enters after that through several doors. It can tune the model itself, train a safety classifier used with it, decide which version ships, or enter product logs that later become training data. These are different technical operations. Each lets human judgment shape the system people finally use.
Books give the model patterns. People supply judgments that never existed in a published corpus: which answer is useful, which error matters, how a specialist corrects it. This is how the capture moves from the internet into work itself.
Can you argue that the labeler knew perfectly well that the task was meant to improve a model, thus all good? Well, the arbitrage is not about concealed purpose. It is about the mismatch between the unit being bought and the asset being built. The worker is paid in a familiar unit: an hour or a completed judgment. The labor market can quote a price for that task. But that is not a price for the downstream capability: the worker is not selling the aggregate capability, and it does not yet exist in a known form. No one knows how far AI’s capabilities will develop, which work they will replace, what inference will cost, or what market will eventually form around them. The worker is paid task by task. The model company controls the aggregate experiment and retains the option on its result. This is not a mature market repeatedly pricing a known capability. It is a bet over one that does not yet exist.
The AI bet is risky, but its promised payoff is seductive. If reality cooperates, the money is supposed to become effortless: each new sale requires less human labor until eventually every worker disappears. That disappearance is not an unfortunate externality; it is what makes the investment so valuable.
Perhaps when Amodei warned Axios in May 2025 that AI could wipe out half of all entry-level white-collar jobs and that AI companies and government should stop sugar-coating it, he really was concerned about humanity. You cannot know his state of mind. But to an investor, the warning sounded like a pitch: every job the machine can erase is work capital can stop paying for.
If you are dead set on this bet, the workers who will lose their livelihood if the bet pans out need a hedge. A continuing ownership stake gives them such a hedge: a claim on the returns from the system that makes their labor less valuable. Without it, the company can declare the transaction finished even if the workers are still living downwind of it.
If authors and workers had retained bargaining power over that reuse, the company would have to negotiate before it scaled and share the downstream value. It would have to work with the people whose markets it meant to enter. That is slower. Avoiding that negotiation is part of the arbitrage bargain.
And the market price cannot settle whether this bargain is fair. Investors are pricing the returns the rules let them keep. If those rules hand the company the reusable capability and leave the worker with a wage but no real stake, the prospect of replacing the worker can raise the company’s valuation. Capital can be ruthlessly efficient at exploitation, and the market will reward it for being good at it. None of that makes it fair. An allocation can be efficient and still be deeply unfair. Slavery is an extreme example of how little that criterion tells you about justice. Policy decides which bargains the market is allowed to price and to what degree the outcome will be fair. Right now, the bargain on offer is an unfair and risky bet. Pointing to the valuation to prove capital earned the gain would be circular: the valuation exists because the rules let capital claim the gain.
Nor does the money pouring in prove the bet has been priced correctly. Investors can doubt the eventual profits and still expect to sell to a greater fool first. You know things are heated when even the cheerleading IMF is worried. In a 2026 report, it identified a related risk in AI’s circular financing, where developers, chipmakers, and cloud companies invest in and buy from one another.
There is a bit of a footgun here too. One reason things got so heated was the promise that human contributions can keep generating revenue while payments to humans become negligible. A continuing claim would not become negligible as the business scaled. That would have made the bet a bit less lucrative for capital and might have tempered the rush.
Capital not paid upstream stays available downstream. That extra runway helps carry massive losses while inference is kept cheap and the market reorganizes around the service. And in fact, this strategy is not new at all in Silicon Valley. Uber was a prominent example: massively underprice the product to disrupt and capture the market, then extract rent once the competitors are dead or sufficiently subdued. AI companies are attempting something Uber could only dream of: extracting the subsidy from the people the product is meant to displace.
Even while pitching such a massive arbitrage, the AI companies go looking for a geographic discount. Under contracts signed in late 2021, OpenAI paid Sama $12.50 an hour for Kenyan workers to label toxic text. The labels trained an additional toxicity detector built into ChatGPT and also helped filter future training data. According to TIME, the workers took home around $1.32 to $2 an hour. Sama disputed parts of TIME’s wage account and said the client rate also covered infrastructure, benefits, quality assurance, and team leads. A 2026 study of Kenyan data work describes an industry that routinely offshores data work to Africa, South and Southeast Asia, and Latin America, using differences between labor markets to reduce its costs. So the supply chain of cheap human workers, tuned for exploitation already, adds ordinary geographic labor arbitrage on top.
The supply chain does not even need offshore jurisdictions. Business Insider reported in June 2026 that Snorkel AI’s Project Marlin used feedback from about 1,000 software engineers to improve Claude Code. Two contractors said they were paid $280 per task, with each task taking about an hour, though some required more back-and-forth with Snorkel’s approval layer. Anthropic’s Sonnet 4.6 system card confirms the pattern company-wide: labeling services, paid contractors, and platform workers doing preference selection and adversarial testing. That is not the Kenyan wage, but the wage is not the point. The task, once bought, is kept as capability.
When the experts are already on the payroll, the AI companies can turn inward. In April 2026, Meta told its U.S. employees that it would record clicks, keystrokes, and occasional screen snapshots for model training so agents could learn to perform work tasks. Google says it tunes models on engineers’ acceptances, rejections, and corrections, and calls the activity it collects across its internal engineering tools essential to model quality. Meta managed to make the bargain especially visible: more than 1,600 employees signed an internal petition against the monitoring, and the company paused the program after an access-control failure exposed collected data inside the company. The collection landed in the middle of a broader morale crisis over Meta’s AI reorganization; some employees described their new assignments as menial and “soul-crushing.”
This is on top of the roughly 6,500 engineers and product managers WIRED reports Meta moved into an internal unit to write coding problems, tests, and grades for training and evaluating frontier models. Zuckerberg explained the logic in a leaked all-hands: the average intelligence at Meta is “significantly higher than the average set of people that you can get to do tasks” through contractors. Three weeks later, Meta announced layoffs of about ten percent of its workforce.
Your coding agent puts you on both sides of the arbitrage: Claude Code arrives already shaped by other people’s books and judgments; if your wrapper succeeds, your users’ judgments become the next tempting input. The beauty, for Anthropic, is that it does not need to claim copyright in your output. Anthropic owns the model and the infrastructure through which the capability is sold. It hands you the output as if its infrastructure gave it clean title, so you are made a party to its highway robbery. The loot is spread among millions of users, each with a reason to keep the party going. Authors wanting to fight back now have to go through Anthropic’s lawyers, then past pissed-off programmers and copywriters who cannot code or write anymore. Even better, Anthropic can still write the rule that you may not use the service to build a competing product, including a model trained on those outputs. That is owner-like control without ownership of the output.
So no wonder the machine that forgot everyone on the way to riches suddenly remembers its rights on the way out.
Anthropic has announced that supported Claude models will weave an imperceptible watermark into generated text. Models launched in the European Union on or after August 2, 2026 support marking at launch, and Anthropic says it is working to add support to older models over the coming months. The policy will take effect everywhere: the Claude API, Claude, Claude Code, Claude Cowork, and wherever else Claude is offered, worldwide. Text gets an embedded watermark. Supported files get a separate cryptographically signed provenance note in their metadata.
The watermark is designed to be hard to get rid of. Copy the text and the watermark travels with it. Edit it lightly and the mark may survive. You really need to rewrite every word to be sure it is gone. As of September 1, Anthropic says a detection API is now in private preview, available to eligible organizations under EU law and to enterprises with similar compliance duties. It plans to expand access, but has not published the detector’s threshold or error rates, or a process for challenging a match.
The stated reason for all this is the European Union’s AI Act and its accompanying voluntary Code of Practice. Anthropic signed the Code in July 2026 and says it is making this change to comply with the Act. Based on a technical explanation published by Anthropic on August 14, Claude’s text watermark uses a version of Google’s SynthID-Text.
The algorithm does not work by adding something extra like hidden characters to text. Instead, it relies on inherent randomness at the heart of LLMs. In any generation, the model often has several acceptable next words and makes a random choice among them to proceed. This is why the same question can produce a different answer on a different run. The model still makes a random choice, but a secret key and the preceding text control where that randomness comes from. Across a long enough passage, those choices leave a statistical pattern that a detector with the same key can test.
Anthropic is admirably plain about the limitation. Detecting the mark would show only that Claude was probably involved with the text. It would not prove Claude wrote the underlying material. A short passage may contain too few choices to produce a strong signal, and a complete rewrite can remove it. The absence of a mark proves nothing either. For files, format conversion or re-saving can strip the signed metadata note. That does not tell you what happened to a watermark embedded in the text itself.
One worry is whether the invisible mark could point back to the user. Anthropic’s answer, for the mark it has described, is no. The announced design can tell Anthropic that Claude was involved. It cannot tell who prompted it: the key contains no information about the user, organization, or chat.
Still, there is a bit of irony here. It is about what gets remembered. Claude’s outputs now carry a signal marking Anthropic’s hard work. But if you are an author? Good luck. When lineage protects Anthropic, provenance is suddenly tractable. When authors ask where the model’s knowledge came from, poor Anthropic is back to the limits of output attribution.
Never mind that authors do not need a source for every token. They need to know what went into training, where it came from, and under what claim of right. Anthropic answered one such question when the reader was a judge. In the Bartz settlement, it represented to the court that neither LibGen nor PiLiMi, nor any portion of either, was in the training corpus of its commercially released models. But no: let the authors bang their heads against the technical limits of output attribution. Do not tell them there was a choice about which provenance to keep. And remember what the Bartz release left alive for the authors? Every claim based on model outputs. This is the side Anthropic decided to mark with a “Claude was here” signal, without anything about whose work Claude was carrying.
To be fair, AI companies have a reason not to show you the ledger. Data selection, filtering, and mixture weights can materially affect model quality, and even a source list would give competitors useful clues. But a bill of materials is not a training recipe. It need not disclose exact sampling weights, preprocessing, annotations, or the training schedule. Some of that advantage is real technical craft. But if the rest is knowing who to rob, and by how much, is that really intellectual property—or just the arbitrage made proprietary?
Now back to Brussels, because the EU AI Act’s legal obligation is narrower than the announced policy. Article 50(2) requires providers of systems that generate synthetic text, audio, image, or video to make outputs machine-readable and detectable as artificially generated, as far as technically feasible. The same paragraph exempts systems that perform an assistive function for standard editing or do not substantially alter the input or its meaning. The European Commission’s final guidance also places source code, short sequences, machine-to-machine outputs not exposed to people, and certain closed-loop production outputs outside the obligation.
Anthropic’s policy goes further. Marking applies worldwide across supported product surfaces, explicitly including Claude Code, even though the Commission excluded source code from the legal obligation. Brussels required the mark, but not its full reach.
This matters to you concretely because code was your case. One key question is whether code could be watermarked without sacrificing model performance. Would the mark live only in comments, for example? Anthropic says when an exact output is required, the watermark has nothing to act on. Code therefore carries less of the mark than ordinary prose. Where the model has an arbitrary choice, including in comments, the mark can still appear. So the signal will be weaker, but present in generated code too.
Zoom in on “watermark” further. Why would you need it? There are at least four reasons you might want one, and the four reasons do not get along.
Public provenance is the version Brussels is asking for. It lets a reader, platform, or regulator ask whether an AI system was involved in producing a text. For that job you want a detector other people can use, clear semantics, published error rates, and a way to challenge a false match.
Then there is training-data hygiene. A model builder scraping the web may want to know which material came from earlier models before feeding it into the next one. Research published in Nature found that indiscriminate recursive training on generated data can produce model collapse, including loss from the tails of the original distribution. A provider-level mark, meaning one that points to Claude rather than its customer, could help filter or measure synthetic text, but only if dataset builders can detect it. Here the mark protects the next training corpus, not the person reading the output.
With model-theft detection, the beneficiary changes. If a competitor gathers millions of Claude answers to train or distill another model, Anthropic wants Claude’s lineage to survive long enough to build a case. A mark found in the collected corpus could show that Claude outputs entered the pipeline. Research also suggests that, under some conditions, a student model can learn the teacher’s watermark, allowing the original provider to probe for it later. Here secrecy may be more useful than public verifiability.
The fourth use is private enforcement. A mark that points to Claude can help enforce a contract when it is combined with service logs and other evidence. A different watermarking design can go further by assigning different marks to different customers or embedding a short identifier in the output. Give each user or group a different key, and a detector can test which key’s pattern appears in the text. In theory, the mark can then point back to the account assigned that key. Multi-user and multi-bit text watermarks have already been built in the research literature.
These four uses pull in different directions: public provenance wants detection that other people can use and challenge; training-data hygiene needs interoperability; model-theft detection benefits from secrecy; customer tracing needs rules around identity, retention, access, and what happens after a match. Fold them into one invisible, provider-controlled layer and a public compliance mechanism can become a private enforcement primitive.
And the incentives are muddied. The same company owns the model, controls the key and the terms of detection, writes the competition clause, and actively investigates distillation. It presents the mark as public provenance while also having a private contractual interest in preserving Claude’s lineage.
That gives Anthropic plenty of incentive to make the signal more granular later. You can even imagine the privacy-washed version in the Google style, a rerun of Chrome’s FLoC debacle: no one tracks you; the system merely assigns you to a cohort, and the cohort gets its own watermarking key.
OpenAI pushes another version of the same invisible, provider-controlled layer into delegated coordination. GPT-6 Astra is trained to divide work among subagents through the beta multi-agent mode introduced with GPT-5.6. Switch it on and a root agent can create subagents, assign their work and assemble it inside OpenAI’s service, while your application executes some tools in your environment. You see the tree and some streamed subagent text. But delegated tasks and inter-agent messages return encrypted. Compaction runs automatically for each agent. The compacted state is opaque, and reasoning summaries are unavailable. The stream records the outline, without the load-bearing assignments, messages and context transitions needed to account for it.
The encryption of agent reasoning predates multi-agent work. OpenAI and Anthropic already returned encrypted reasoning for customers to carry between calls, including in configurations where the provider stores no conversation state. Now the pattern carries coordination and compacted memory. The customer carries the memory but cannot read it; only the provider can put it back together. OpenAI made the change explicitly in Codex: readable delegation messages became ciphertext in the local history. OpenAI might twist itself into a pretzel trying to call this security, but protecting the record does not explain why you cannot read it. Just like the watermark, one mechanism can serve multiple functions, with some understandable and others infuriating. There is a case to be made that this helps with privacy if you use it for sensitive data. But it also denies competitors those reasoning traces for distillation. The customer cannot hand the encrypted working state to a competing provider and continue from it. Switching means giving up that state and working from the visible records or a reconstructed summary.
Take Astra. Give OpenAI its strongest case. Suppose OpenAI, as is probably the case with Astra, managed to improve its models substantially through reinforcement learning in an environment OpenAI built, with its compute and little direct human supervision. The lab can keep that recipe secret. Copyright does not extend to a process or method of operation; trade-secret law can protect economically valuable secret methods. Fair use supplies no inspection right. But does that settle what the provider may conceal about your job? A process receipt is not a training recipe. Why can’t you know the steps the agent took — steps backed, as you saw, by human judgments and artifacts?
You might say, “But human authors also only owe you the finished book.” A human author is not the right metaphor here; a much better comparison is a contractor. A contractor works inside a house you live in. An agent is a contractor too. It acts inside an environment for which you ultimately answer. Its receipt can name mandates, consequential actions, evidence, tests, handoffs, context loss, and missing parts and reasons. If you are a worker trying to stay relevant and still interested in knowing what is going on in your project, you need to be able to look at that stuff. And no, it is not raw chain of thought. It should be enough to verify the work and inspect the thinking behind it. If you do not get it as a worker, you really are little more than an AI babysitter, and soon, when the baby has grown, you need to find another job. This, too, advances the worker’s disappearance. This time from the other end. The provider has already absorbed the skilled worker who helped build the models; now it cuts out the worker who uses it and wants to understand what it did. The receipt was one last route by which the skill might have permeated back to the person doing the job. Encrypting it blocks that route.
If the AI were actually a contractor doing the work, you would not accept this from him or any other worker: he took your payment, told you the work was done, denied you an account of what happened, and stamped all the paragraphs he touched with his name, even if he had only proofread the text. But here is the point the big labs hope to land. You are not a client hiring a contractor. You are a consumer. Who do you think you are, wanting to know? Soon you should be happy that the agents talk to you at all to pick up your menial task.
Fine. Accept the big labs’ logic. Try to build your coding agent their way.
Suppose you use Claude Code heavily and use it well. And your design is so great and innovative that you win the hearts and minds of programmers around the world and have millions of users. Here is the first problem: If your coding agent counts as a competing product, Anthropic’s terms say you were not allowed to use Claude Code to build it in the first place. But wait! Anthropic says you own the output. So Claude can write code you own for a product you are not allowed to build with Claude?
Suppose you somehow get Anthropic’s approval and keep going. You use Claude as one of the underlying models users get to use. You pay Anthropic for the API and charge your users a flat fee. The commercial terms expressly allow customers to use Claude to power products for their own users. The same terms prohibit building a competing product or reselling the service without Anthropic’s approval. A thin wrapper might be a permitted product. A very good coding harness begins to look like Claude Code’s competitor. Your safest options are to remain unimportant or get a custom contract.
But no! A custom contract might fall apart too. On August 28, 2026, OpenAI said it would wind down the contract supplying its models to Cursor, with a proposed cutoff on November 12, after Cursor was acquired by SpaceX. OpenAI invoked a change-of-control clause and distrust of SpaceX, not simply Cursor’s competition with Codex. For the application company, the result is the same: the model supplier can end access to the current models and withhold the next ones. Hopefully Cursor’s founders got to cash out as part of the deal, but you might not be that lucky.
Perhaps you can fix this with BYOK: bring your own key. You stop selling access to Claude. Every user connects their own Anthropic API key and pays Anthropic directly. You do not allow Pro or Max logins, only API keys governed by Anthropic’s commercial terms, to keep everything aboveboard. No inference subsidy for you. You won’t compete dirty. Then you go to your users and ask permission to learn from what happens inside your agent. Since they love you so much, and since you are sweetening the deal with a discount, they agree.
Surely this works, right? You might even observe here that the user does more than consume. They are working the underlying engine. They bring the repository, the problem and the intention. Claude proposes a patch. The programmer tests it, rejects it, corrects it or replaces it. Your harness records which suggestions survived and what the programmer did when they failed. This is expert labeling inside a real project, and it did not exist before you brought the user, the harness and Claude together.
Anthropic says the user retains their inputs and owns the outputs. Good. You found the owner, asked permission and paid for the contribution. Under the commercial terms, Anthropic itself may not train on Customer Content. Yet BYOK moves the anti-training restriction from your contract into every user’s: Anthropic does not claim the programmer’s correction for itself; it claims the power to stop you from learning from the joint product. Anthropic made one part of that product and was paid for the inference. The user made another and agreed to sell it to you. You built the harness and brought them together. Still, the model supplier keeps leverage over every user.
That leverage is contractual, not a property right that follows the correction. Anthropic can suspend or pursue users who violate its terms. But if you never agreed to those terms, they do not automatically bind you merely because the data once passed through Claude. Anthropic might argue that you deliberately induced the breach; whether it could stop you directly from using material its owner licensed to you is a separate, unsettled question. The model supplier has a practical choke point, not proven ownership of the downstream corpus.
Now defend this arrangement the way Anthropic defended training on books. Anthropic was paid for Claude, by you or by the user, just as Anthropic paid for at least some of the books it trained on. You obtained something better from your users: express permission to use their work. Claude is only one input into a much larger service. You would say your model extracts patterns from millions of interactions rather than reproducing any one of them. You add value through the harness, the tools, the tests and the work of bringing all those users together. By this logic, you are not stealing Claude. You are learning from it.
Anthropic’s answer would be that paying for access to Claude did not buy permission to train a competing model. Now that would be something. The authors suing Anthropic might recognize the argument. They sued under copyright, and Anthropic answered with fair use. Your dispute would arise under a contract Anthropic wrote before letting you use Claude. Control of the infrastructure gave Anthropic the chance to set those terms before you ever see an output, a chance the authors never had.
This is why the watermark was bothering you too. The mark on its own does not create a copyright or patent right. If detectable Claude output were found in your training corpus, however, it could help show that Claude was involved. It would not establish who owned the surrounding code or whether a contract was breached. It could not even tell whether Claude reached the corpus through your API account or a user’s. The contracts, account records and other evidence would have to do the rest. But the mark could tell Anthropic where to start looking.
Anthropic’s competitive interest is not hypothetical. In February 2026 it said that DeepSeek, Moonshot, and MiniMax had generated more than sixteen million exchanges through roughly 24,000 fraudulent accounts to improve their own models, and described the activity as illicit distillation in violation of its terms. That is Anthropic’s account, not evidence that the watermark caught anyone. But it tells you the company is looking. There is no insiders’ club either: in August 2025, Anthropic revoked OpenAI’s API access after concluding that OpenAI staff were using Claude Code, on the grounds that this violated the same no-competing-use terms. So the rule gets enforced even against the company that is, depending on the week, Anthropic’s closest rival or its estranged sibling.
OpenAI had rehearsed the same reversal. In written evidence published by the House of Lords in January 2024, it said it would be “impossible to train today’s leading AI models without using copyrighted materials.” A year later, OpenAI said it was reviewing indications that DeepSeek may have inappropriately distilled its models. On Fox News, David Sacks, Trump’s AI adviser, promptly volunteered as OpenAI’s star witness, claiming “substantial evidence” without disclosing any. It is hard not to chuckle at the logic: impossible to train without everyone else’s work; forbidden to train on ours.
So now things slowly start to dawn on you. Follow Anthropic’s logic, and you become another arbitrage machine, this time fed by Claude and the people correcting it. If human artifacts and judgments allowed Anthropic some sweet arbitrage play, the same logic should allow you one too. You should be able to take Claude’s outputs and the judgments of your users and use them for your own plan. Surely you transformed them enough and worked hard enough to claim ownership over them. But now Anthropic is invoking its ownership of the infrastructure and the surrounding contract to stop you from doing to Claude what Anthropic did to earlier human work. And what did you expect? They invented this. Anthropic is too big to be robbed on the highway. It owns the highway. Who do you think rented you the getaway car?
So what is the way out if you do not want to be like Anthropic and rob anyone? Here is a crazy idea: make the bill of materials from earlier carry legal weight. Computational training would require a license that traveled with the data, and a model could carry no broader rights than that chain gave it.
The rule would run in both directions. Anthropic would negotiate for the books and judgments used to build Claude. If you wanted to train on Claude outputs and your users’ corrections, you would negotiate with both. Claude becoming the input would not suddenly change the rule. That costs more and moves slower, but you might prefer not to move fast and break things.
This rule also has to leave facts and ideas available for thought, criticism, and new creation. The answer to enclosure is not to turn every idea into a permissioned object. Provenance does not solve market power either. A publisher can cite an author while monopolizing access, and a provider can disclose its datasets while imposing exclusionary contracts.
That is not what emerged. What exists today instead is a licensing market between large publishers and technology companies. Wiley reported $23 million from one generative-AI content-rights project in its 2024 fiscal year. Informa reported more than $75 million in 2024 AI partnership revenue for non-exclusive access to Taylor & Francis archives, with author royalties and work on discoverability and automated citations. Cambridge contacted more than 40,000 authors and asked them to opt in before licensing academic books; a majority did.
These bargains are not all the same. A one-time corpus license makes ingestion lawful and may pay royalties, but it leaves the company paying once and selling capability repeatedly, with no route from later answers back to the work. A royalty tied to downstream use would change that price structure. Attribution is a separate question. OpenAI’s agreement with Le Monde and Prisa combines training permission with attributed summaries and links, while Anthropic’s Wiley integration retrieves peer-reviewed material directly into Claude through the Model Context Protocol. In both cases, material shown to the user can still point back to a source.
But the market is learning to pay whoever can sign the license, not necessarily whoever made the knowledge. Publishers distribute royalties and do real editorial work, but they also concentrate bargaining rights over thousands of contributors. A bilateral deal can formalize the enclosure: two large institutions divide the proceeds while the public receives the same anonymous synthesis. These are separate bargains by institutions that already control large collections, not a reciprocal model. On the labor side, meanwhile, the market wage is still supposed to clean it all up automagically.
So now what do you learn from walking through the coding-agent problem? You learn that copyright can catch some bad acquisitions, piracy most obviously. It cannot name the whole machine. Training can be transformative and still perform this arbitrage. The labeler makes that impossible to hide behind the schoolchild: nothing needs to be stolen. A bounded human judgment can be bought, detached from the worker, and capitalized as reusable capability.
That is why the watermark belongs inside the fair-use argument and not as a footnote. It is the point where input forgetting becomes output memory. Public provenance marks the outbound artifact but does nothing for the people upstream. The same provider-level signal can support contract enforcement when marked outputs appear downstream. The technology did not create that contradiction. It makes the contradiction executable.
Anthropic wanted all the books in the world. It is now building the machinery to make sure the world remembers Anthropic, and only Anthropic. And you personally do not mind remembering them despite their occasional hypocrisy or threats to the entire human experience. Your problem is they do not extend the courtesy of remembrance to all the people whose work went into their models. It really does not sit well with you that on the way in, millions of books and the judgments of paid workers disappear from what the user sees; inside, the process survives as memory the customer carries but cannot read; and on the way out, Claude’s contribution becomes a detectable lineage.
So, back to the coding agent you set out to build. Should you build it with Claude Code? Should you build anything with Claude Code?
For something noncommercial — a blog post, a trip plan, a side experiment — sure, go ahead. But you would not build a serious product on it, and you especially would not build one anywhere near a space Anthropic is already in. And for other areas they might move into next, their watermark is going to leave provider-level evidence in the text. So if they move there, you will have some kind of sticky code on your hands.
How do you know what Anthropic will move into next? You don’t. To answer that, you need to consult your crystal ball. Let’s hope it is reliable enough to build a company on.
