The Watermark Isn't for the Regulator

How watermarks help solve a legal problem you can’t solve later.


Fall is when the questions start.

New cohort, new program, new advisor, new term sheet. Somebody who wasn't in the room in June starts asking what you built and how. If you spent the summer shipping an MVP with a coding agent and a design model, there's a question waiting at the end of that conversation that most founders have never been asked:

Who authored this?

Not who owns the company. Not who's on the cap table. Who authored the work.

If the honest answer is "a model did," you have a hole where a chain of title is supposed to be — a problem that can’t be fixed with an assignment.


Everyone read August 2 as a compliance story

On August 2, two things went live on the same day. The EU AI Act's Article 50 transparency obligations began to apply, and California's AI Transparency Act — SB 942, as amended by AB 853 — became operative.

The coverage since has been almost entirely about compliance. Who has to watermark. What the penalties are. Whether you're in scope.

For most of the companies I work with, the honest answer to "are you in scope" is mostly no. SB 942's obligations land on covered providers — systems with over a million monthly visitors or users publicly accessible in California. That is generally not a seed-stage company in Lawrenceville.

Article 50's machine-readable marking duty under 50(2) sits with the people who build and place the models, not with you for using one. There's one prong that does reach you: if your product talks to users directly, Article 50 requires you to tell them they're talking to an AI. This obligation attaches to the situation, not headcount or revenue. If you have a chatbot with EU users, read Article 50.

The reality is that compliance is a small question for most companies building technology. The more important (and interesting) question is what watermarks are.


A watermark is a receipt

Strip away the regulatory framing and provenance marking is a record of where a piece of content came from in a format that is machine-readable, embedded, and travels with the file.

The watermark is the closest thing anyone has built to an authorship audit trail, which matters, because authorship is the question underlying every copyright, registration, and patent filing you claim to own.

Copyright. U.S. copyright requires a human author. The Copyright Office has held that line consistently — I've argued it's drawn the line in the wrong place — and on March 2, 2026, the Supreme Court denied certiorari in Thaler v. Perlmutter, leaving the D.C. Circuit's holding consistent with the Copyright Office’s guidance in place. Material generated by a model without meaningful human creative contribution is not protectable.

Read that carefully. The problem isn't that somebody else owns your AI-generated code. It's that nobody does. This isn't a title defect you can cure with an assignment. There is no title. Your competitor can copy your code verbatim, and you have no way to stop them.

Registration. If you do register, and the work contains an appreciable amount of AI-generated material, that material has to be disclaimed in the application. The Copyright Office has been explicit that this applies retroactively to registrations already on file, not just new ones. A registration obtained without that disclosure can be cancelled, which means the registration you're pointing to in your data room may be weaker than the certificate suggests.

Patents. The USPTO rescinded its February 2024 AI inventorship guidance on November 28, 2025 and replaced it with a framework that applies the traditional conception test and treats AI as a tool like any other. Although this is a friendlier standard than the one it replaced, it is not a free pass. Conception still has to be human. You must be able to show that a human conceived of the invention.

The question is the same across all three: can you identify the human contribution and prove it?


 

Assessment

Can you answer the question?

Nine questions. About three minutes. No sales call attached.

Find out whether your authorship record would survive a look from an investor, an acquirer, or an enterprise customer’s legal team — while there’s still time to fix what it turns up.

Take the Assessment →
 

Where this actually bites

Assignments transfer what people create. Founders assign their work to the company, employees assign their work to the company, contractors assign to the company. That's the theory: maintain these agreements and you have a clean chain of title from first day to exit..

An assignment can only convey rights that exist. If a meaningful share of your codebase, your copy, your models, or your product design was generated by a model rather than authored by a human, assignments with prompters are moving air.

Then you sign something with an IP representation — a term sheet, a purchase agreement, a license agreement, an enterprise MSA. In every one of these representations you are warranting that the company owns all right, title, and interest in the company intellectual property. You cannot honestly make that representation about material nobody can own.

The diligence version of this question is already showing up. The startup community has spent the last several months arguing about what technical due diligence even means when a large fraction of a codebase was AI generated and the founders can't fully explain it. The verification bottleneck is real, and it's not going to get looser. The teams that can answer "who wrote this and how do we know" will move through diligence. Companies that can't will spend months reconstructing what changed, when, and who / what made the change.


Your stack is deleting the evidence

Creating an authorship audit trail is a this week problem, not a someday problem.

Provenance metadata is fragile by design. For the last twenty years, metadata has been overhead nobody cares about. Most content pipelines discard embedded metadata by default. Image compressors strip it. CMS uploads strip it. Social schedulers strip it.

At the exact moment provenance records become legally useful to you, your publishing stack is throwing them away — quietly, automatically, on every upload.


What to do before somebody asks

Turn on the record now. Commit history with real attribution, prompt and session logs, design files with edit history intact. These data are building the evidence trail you'll need to identify human contribution. Reconstructing the audit trail after the fact is difficult, time consuming, and inherently inaccurate. A reconstruction produced during diligence looks contrived and unreliable.

Find out what your pipeline strips. Test it. Upload an asset with embedded provenance data, download it, check whether the data survived. Do this for your CMS, your image pipeline, and anything that touches marketing assets.

Separate the tracks. Know which parts of your product are human-authored, which are model-generated, and which are generated-then-substantially-modified. The third category is where human authorship claims are strongest — but only if you can identify who performed the modification — a person editing directly, or an agent acting on instruction. Only the first reliably supports a human authorship claim.

Use trade secret where copyright won't reach. This is the fallback nobody talks about. Generated code that isn't copyrightable can still be a protectable trade secret if you actually treat it as one — access controls, confidentiality obligations, a real policy. For a private codebase, that's often the stronger position anyway.

Fix your assignment documents. Your assignments, consulting agreements, and contractor agreements were probably written for a world where a human typed everything. They should address AI-assisted work product, tool usage, and documentation obligations directly.

Read your reps before you sign them. Every IP representation in every agreement, against what you can actually prove today.


The reframe

Most legal problems are fixable. Expensive and annoying, but fixable. You can paper an assignment you forgot. You can clean up a cap table. You can renegotiate a bad contract at renewal.

Authorship isn't fixable. You cannot retroactively author something. Either a person made a creative contribution and there's a record of it, or there isn't. No amount of money in year four can buy back a decision nobody documented in year one.

That asymmetry is the argument. Keeping the record costs almost nothing: attribution you're already generating, logs you're already producing, one afternoon testing what your pipeline strips. Not keeping these records costs you the ability to answer the only question that matters, at the exact moment who wrote your code is worth money.

Provenance is chain of title. Keep the receipts.


Curt Wadsworth, J.D., Ph.D. is the founder of Nerd Lawyer Entrepreneur Services, an AI-native corporate and IP law firm serving founders, startups, SMBs, and growth-stage companies. Reach him at curt@nerdlawyer.ai.

This post is general information about legal developments, not legal advice, and does not create an attorney-client relationship. The liability analysis here is hypothetical and forward-looking; no claim has been asserted against any party described. Consult counsel about your specific agreements and coverage.

Book a 20-minute Investor Readiness Vault consult →

Next
Next

The Unlocked Door: Who Pays When a Rogue AI Agent Attacks From Your Infrastructure