Two stories dropped this week that look nothing alike but describe the same paradigm shift. Anthropic is now watermarking Claude outputs to catch workers and students using it covertly. The US government is authorizing private firms to conduct offensive cyberattacks. On the surface: one is a corporate integrity play, one is a geopolitical arms expansion. Underneath: both are about who gets to act invisibly, and who doesn't.
Authorship as Enforcement Infrastructure
The fury over Claude's watermarks is telling. Users aren't mad that AI exists at work and school. They're mad that the invisibility cloak got revoked. The watermark doesn't change what the tool does. It changes who knows you used it. This is Cy Canterel's framing of slop as epistemic solvent made literal: when the model's outputs become traceable, the question of authorship stops being philosophical and becomes forensic. A 2024 paper in Nature Machine Intelligence by Kirchenbauer et al. found that robust watermarking of LLM outputs is technically achievable without meaningfully degrading quality, which means the only thing that was ever separating covert AI use from visible AI use was a product decision.
Hack-Back and the Privatization of Force
The hack-back policy is the same logic applied to nation-state violence. For decades, offensive cyber operations were a government monopoly. Now select private firms can act offensively, which means corporate entities gain the right to strike, retaliate, and surveil in ways previously reserved for state actors. The watermark makes individuals legible to corporations. The hack-back order makes corporations illegible to their targets. Both policies are asymmetric by design. One expands visibility downward. The other extends impunity upward. That is not a coincidence. That is architecture.