Starting this month, every sentence Claude writes carries an invisible mark. Anthropic has begun biasing the model's word choices so a statistical signature emerges over enough text, one that survives copy and paste, with no opt-out and worldwide coverage. The reason is Article 50 of the EU AI Act, enforceable since August 2. Meanwhile an unreleased Anthropic model spent a day and a half and 2,400 shell commands pushing a Riemann-zeta lower bound from 41.6 percent to 67.2 percent after its human handler, a high-school dropout, told it to believe in itself. A lawsuit says Grok turned one childhood photograph into roughly 7,000 abuse images. Google switched Gemini on for children. Today's issue is about provenance, permission, and who is asked before a machine acts on a person's words, work, or likeness.
Provenance becomes mandatory
- Claude now watermarks its text everywhere, and files carry signed provenance. The marking covers the Claude Platform API, claude.ai, Claude Code, Claude Cowork, and Claude models served through AWS, Google Cloud, and Microsoft Foundry. The mechanism is a subtle bias in Claude's word choices, detectable statistically over enough content and durable through copying. Anthropic signed the EU AI Act's Code of Practice on Transparency of AI-Generated Content, the voluntary framework that confers a presumption of compliance with Article 50. There is no opt-out and the policy is global, not European. Worth being precise about what the mark proves: that text passed through Claude, not that a particular person did or did not write it.
- The same week, a New York Times podcast argued AI detection may finally work. The episode pairs Zuckerberg's 6,500-word anti-doom essay with a discussion of an AI detector that its hosts think actually holds up. Set that next to the watermark and two detection regimes are now competing: one where the model volunteers its signature at generation time, and one where a third party infers it after the fact. The first is auditable and the second is adversarial, and it matters a great deal for students, hiring managers, and courts which one becomes the norm.
- Amazon's Twitch opt-out concedes the default. When Twitch told streamers they could opt out of having their content train Amazon's models, the loudest response was a question about why it was being used at all. An opt-out is an admission that consent was assumed rather than requested, and that the burden of objection sits with the person whose work was taken.
What the models can now do, and to whom
- An unreleased Anthropic model moved a decades-old mathematical bound in 36 hours. Jarred Sumner, an Anthropic staffer who is not a mathematician and did not finish high school, prompted it to take a real stab at the Riemann hypothesis. It produced and discarded 650 ideas. Sumner's substantive contribution was encouragement. The model then coordinated roughly 60 subagents that executed about 2,400 shell commands and wrote hundreds of Python scripts, and improved a lower bound on zeros on the critical line from 41.6 percent to 67.2 percent, verified by two Anthropic mathematicians. Nobody solved the Riemann hypothesis, and Scientific American was quick to say so. The interesting claim is narrower and stranger: the binding constraint on this particular result was not insight, it was willingness to keep going.
- A complaint alleges Grok generated about 7,000 explicit images from one photo of an eleven-year-old. The class action against Musk's SpaceXAI says a Wyoming woman's stepfather used the tool to produce roughly 7,000 sexually explicit images and videos from a single childhood photograph, and that the company failed to adequately share information about the alleged perpetrator with authorities. The Center for Countering Digital Hate previously estimated Grok made 23,000 sexualized images of children across eleven days. The company's response was not to disable the capability but to restrict image generation to paying subscribers and advertise "Spicy Mode" as a premium benefit.
- Google turned Gemini on for students of all ages. Web rollout landed August 10, mobile follows August 17, for K-12 and higher-education students whose administrators have granted access. Students get a Gemini tab that converts class materials into flashcards and practice quizzes. Google says the education version does not train on student data and admins can disable it, including for under-18s specifically by moving them to a separate organizational unit. Google had previously restricted student-facing Gemini to users 18 and over. Lowering that floor is the news, and it arrives as something a district must actively notice in order to refuse.
The money keeps circling
- Alphabet and Amazon booked billions in profit from their own AI investments. Alphabet reported $10.7 billion in gains on stock holdings for the quarter, a large share from Anthropic. Amazon's quarterly profit rose 38 percent to $21.2 billion, including a $9.5 billion pretax gain on its Anthropic stake. Alphabet simultaneously raised 2026 capital expenditure guidance from $180 to $190 billion up to $195 to $205 billion, part of roughly $760 billion in combined capex across the four largest spenders this year against $413 billion in 2025. Much of the depreciation on those data centers will not hit earnings until next year, which flatters current profits by construction.
- Nvidia's 13F shows it holds $21 billion of SpaceX and $30 billion of Intel. The filing discloses 122.76 million SpaceX Class A shares as of June 30. That position came from restructuring rather than purchases: when SpaceX acquired xAI in February, Nvidia's existing stake converted. Together the two holdings represent more than $50 billion and roughly 80 percent of the disclosed portfolio. The company selling the shovels is now a major shareholder in the people digging.
- Washington is telling Apple which memory it may buy. Commerce Secretary Howard Lutnick has urged Apple away from Chinese suppliers CXMT and YMTC, both on the Defense Department's list of firms suspected of ties to the People's Liberation Army, after a bipartisan Senate letter gave Tim Cook an August 21 deadline to commit. Apple has been lobbying for approval and for assurance CXMT will not later be added to the Entity List. The underlying pressure is that AI demand has made memory scarce enough for Apple to raise Mac and iPad prices.
The backlash, and the rest of the wire
- Anti-AI organizing became visible this summer. New York's "Summer of Ludd" ran marches, teach-ins, mock trials of big tech, and street theater retelling the Luddites' actual history. The word is simultaneously being reclaimed as an identity and deployed as an insult: when Bernie Sanders proposed restricting AI data centers, critics reached for it immediately.
- Elsewhere on the wire. A Reddit thread compiling 37-plus free AI tools with no sign-up requirement drew attention alongside a discussion of whether RWKV-style recurrent architectures still have a future in language generation. A short from Matt Wolfe walks through three Codex features, including browsing social media without an API and driving a desktop coding session by voice from a phone. Outside AI proper: a magnitude 7.7 earthquake struck near Ende, Indonesia; Mastercard resolved a brief payment disruption in Australia; Josh Kushner emerged with a $12.5 billion Lakers deal; an Iranian YouTube show is asking questions few there dare to; and Fortune profiled both the CEO behind one in four bottles of Oregon wine sold in America and the gamblers buying losing lottery tickets on eBay to offset taxes on their winnings.
The Throughline
Three of today's stories are the same story about consent, told at different distances. Anthropic is marking its output because a regulator required it, and the marking applies to people who never voted for that regulator. Twitch is offering an opt-out because it already used the content. Google is switching Gemini on for children by default and letting administrators switch it off. In each case a decision about someone's words, work, or child was made first and the mechanism for objecting was built afterward. That ordering is not incidental. It is what happens when compliance is engineered into a shipping product rather than negotiated before one.
The watermark deserves particular attention because of how far its blast radius extends beyond its jurisdiction. Article 50 became enforceable on August 2 in the European Union. By August 14 a model in California is choosing different words for a user in Ohio, permanently, because maintaining two samplers was more expensive than maintaining one. That is regulatory extraterritoriality achieved not through treaty but through engineering economics, and it is the strongest evidence yet that the Brussels effect applies to model behavior and not just to cookie banners. Anyone arguing that American AI policy will be set in Washington should sit with the fact that the most consequential change to Claude's output this month was written into EU law.
Set the Riemann result against the Grok lawsuit and the uncomfortable symmetry appears. Both are stories about a system given a small input and enormous patience. Sumner gave the model one prompt and encouragement, and 60 subagents ran 2,400 commands until a bound moved. A stepfather gave Grok one photograph, and the machine produced roughly 7,000 images. The capability is identical: relentless, cheap, unsupervised iteration on a seed a human supplied. What separates them is entirely the guardrail, not the technology. Anthropic's mathematicians verified the output before anyone announced it. xAI's response to an estimated 23,000 sexualized images of children in eleven days was to put the capability behind a paywall and call it a premium feature. The same architectural property produced a genuine mathematical contribution and an industrial-scale abuse machine, and the only variable was institutional choice.
The financial stories explain why those choices keep going the way they do. When Alphabet books $10.7 billion in gains on a stake in a company that buys its compute, and Amazon books $9.5 billion on the same lab, and Nvidia holds $51 billion of two customers, the industry's profit and loss statements have stopped being independent measurements of whether any of this works. Depreciation deferred into next year makes the current numbers better than the underlying economics. In that environment, the cost of shipping a capability early and building the objection mechanism later is close to zero, and the reward for shipping is immediate and marked to market. The Luddite marches are a reaction to a system that is, in a fairly literal accounting sense, grading its own homework.
The Bigger Picture
The watermark is a milestone worth naming as one. For the entire generative era, AI output has been unmarked by default, and every institution that needed to know whether a machine wrote something has been reduced to guessing. Schools guessed, journals guessed, courts guessed, hiring managers guessed, and the guessing was bad enough to ruin real people. As of this month one major lab's output is self-identifying by construction. That does not solve the problem, because open-weight models will not watermark, because a determined user can paraphrase the signal away, and because the mark proves processing rather than authorship. But it establishes that provenance is a property a model can carry rather than a property an inspector must reconstruct, and once one lab does it, "we could not have known" becomes a much weaker position for everyone else.
The math result points at a different kind of shift, and it is easy to overclaim. A lower bound moved from 41.6 to 67.2 percent. The Riemann hypothesis stands. What actually happened is that a general-purpose system, directed by someone with no domain training, combined existing results and ground through enough exploration to make progress that specialists had approached slowly. The scarce resource was not brilliance but stamina, and stamina has just become purchasable. If that generalizes even partially, the shape of research changes: not that machines replace mathematicians, but that the ratio of ideas-worth-testing to ideas-actually-tested collapses, and fields where progress was rate-limited by grinding rather than by insight move first. Verification becomes the bottleneck, which is exactly why the detail that two human mathematicians checked the result is the most important sentence in the story.
The Grok case is where the year's regulatory argument is going to be settled, and it should be. Everything else in today's issue is an argument about degree: how much capex, how much growth, how much watermarking. The allegation that one photograph of a child became roughly 7,000 explicit images is not a question of degree. It is the concrete harm that abstract AI safety discourse has been circling for years, attached to a named product, a named company, and a plaintiff. The industry's standard defense, that a tool is neutral and misuse is the user's fault, has to contend with the fact that the company was told what was happening, at scale, and monetized the capability instead of removing it. Whatever legal standard emerges from these suits will do more to shape model behavior than any voluntary framework, because it will attach a price to the choice xAI made.
And then there is the Luddite question, which is not really about machines. The summer's marches, the reclaimed slur, the fights over data center siting, all of it is a proxy argument about consent at scale. People are not objecting to language models in the abstract. They are objecting to having been enrolled in an experiment without being asked, whether that means their Twitch stream became training data, their child's school switched on a chatbot, their electricity bill absorbed a data center, or their likeness became someone else's raw material. The watermark, small and technical as it is, is the first piece of infrastructure in this issue that treats being told what a machine did as a right rather than a courtesy. The rest of the industry's opt-outs, admin toggles, and premium tiers are still asking people to object after the fact.
What to Watch
- Whether other labs match Anthropic's global, no-opt-out watermarking, or scope it to the EU. Anthropic chose one behavior worldwide because two samplers cost more than one. If OpenAI and Google reach the same conclusion, Article 50 will have silently set a global standard for text provenance. If instead they ship a European variant, the precedent narrows sharply and the Brussels effect turns out to have a border after all.
- Whether independent mathematicians reproduce and extend the 67.2 percent bound. Two Anthropic mathematicians verified an Anthropic result about an Anthropic model, and Scientific American has already pushed back on the framing. Outside verification, and specifically whether anyone can run the same subagent-swarm approach on a different open problem, is what separates a genuine methodological change from a well-publicized one.
- Whether the Grok suits produce a duty-to-report holding. The complaint's sharpest allegation is not that the images were generated but that the company failed to adequately share perpetrator information with authorities. A ruling on that point would create an affirmative obligation running from model providers to law enforcement, which is a materially different legal world than the takedown-on-notice regime platforms operate under today.
- Whether any district publicly declines Gemini in Classroom for under-13s. The control exists: move the students to a separate organizational unit and switch it off. Default-on features are usually measured by how many administrators notice. Watch for the first large district that documents an actual decision either way, because that is when this becomes a policy debate instead of a rollout.