№ xlii The Almanac of GST · EN IT

Enrico·rubbo.li

Tech · Longevity · Markets · Opinions Enrico Rubboli, propr. Dubai, UAE
essay August 12, 2026 18 min

The Badge Is Not the Ethics

On the second of August 2026, a large part of Europe’s artificial intelligence law stopped being a calendar item and became a compliance project. Chatbots were told to introduce themselves. Deepfakes were told to wear labels. Providers of generative systems signed up to machine-readable marks. Newsrooms wrote the same sentence in fifty languages: the EU is making AI transparent.

Somewhere in that same week, a frontier lab that sells itself as the careful one published the practical form of that transparency. New Claude models would weave an imperceptible watermark into all generated text, apply provenance metadata to supported files, and do it worldwide, not only in a Brussels-facing skin. The company’s own documentation is unusually honest about what that signal means. A detected mark means the content may have been processed by Claude. It does not mean Claude was the author. Proofreading, translation, summarization, and file conversion can all leave a mark on material that began as human writing.[1]

That is not a gotcha about one company. It is the AI Act in miniature. Europe built a machine for visible rituals of trust and for real constraints on named organizations. The public is being sold the first as if it were the second. Ethical AI needs the opposite ordering: enforce power where it hurts people, and stop confusing steganography with morality.

What the Act is actually for

The EU Artificial Intelligence Act is a product and market law, not a theory of machine goals.[2] Its official goods are familiar if you have lived through GDPR: fundamental rights, health and safety in high-stakes systems, a single rulebook for the internal market, and a political brand of “trustworthy AI.”

It sorts systems by risk. A short list of practices is prohibited. A longer list of high-risk uses, hiring, credit, safety components, certain public services, carries heavy process: risk management, data governance, logging, documentation, human oversight, conformity. General-purpose models get documentation and, for the most capable, systemic-risk duties. Transparency rules require disclosure when you interact with AI and markings for much synthetic media.[3]

Fines are real on paper: up to 7% of global turnover for prohibited practices, lower tiers for other breaches.[4] Enforcement is split between national market surveillance and the EU AI Office for general-purpose models. The law reaches providers who place systems on the Union market and deployers who use them professionally, including many firms established outside Europe when the output is used inside it.[2]

None of that is “alignment” in the sense used in the last part of my ethical AI series. Alignment is about whether a system’s objectives stay pointed at what you meant. The Act is about whether a named actor may market or operate a classified system under EU rules. Confusing the two is how you get overconfidence in labels and underinvestment in control research, industrial capacity, and ordinary security.

Cookie consent taught a generation the wrong lesson about digital rights. The banner was supposed to restore choice. Under commercial pressure it became a ritual: accept all, or suffer. Users learned to click through. Companies learned to prove they asked. The harm, tracking and profiling, continued upstream of the modal.

Commercial AI transparency is walking the same path.

“You are talking to an AI.” Useful once, against pure impersonation. After the hundredth support widget greets you with a soft disclosure and still refuses a human, the sentence carries no power. There is usually no meaningful refusal. The data still flows. The scoring, if any, still runs. The company can point to the line in the UI.

Visible deepfake badges on cooperative platforms. Fine for good-faith publishers. Trivial for anyone who re-encodes, crops, generates offline, or never intended to comply.

Compliance documentation without outcomes. A risk file can be perfect and the hiring model still discriminatory. Process without audit and liability is ISO cosplay.

The cookie-banner test is simple. Can the user refuse and still get the service? Does disclosure change retention, scoring, or escalation? Does a determined adversary still achieve the harm? After a hundred exposures, does anyone still read the notice? If the answers are no, no, yes, and no, you are not looking at ethics. You are looking at a liability receipt.

That does not make every transparency rule worthless. It means transparency is the weakest layer of the Act, and the layer citizens will see first, so it will define the law’s reputation while the harder duties either grow teeth or rot quietly in annexes.

The watermark that cannot tell the truth

Machine-readable marking of generative output is the purest form of this problem, because it sounds like science.

Anthropic’s implementation, framed as commitments under the Article 50 transparency practice, marks generated text at the model level across products and regions.[1] The watermark is meant to travel with copy-paste and survive some editing. File outputs can carry signed provenance metadata in the C2PA style. Detection tools will, in principle, let third parties ask whether a Claude mark is present.

Hold that against what ethical discourse pretends watermarks do. People hear “AI watermark” and imagine a stamp that says: this was written by a machine, not by a person. What the system actually delivers is closer to: this string was emitted by a model that was legally incentivized to stain its emissions.

Anthropic’s own limitations section says the quiet part. A mark is not fully conclusive provenance. Claude may not be the original author. People use models to proofread, translate, summarize, and convert. Marked content can be edited, excerpted, or mixed. Absence of a mark does not mean the content was human: older models, heavy paraphrase, short passages, stripped metadata, unsupported paths.[1]

So the regime produces two systematic errors.

False positives on hybrid work. A human writes the argument. The model fixes grammar, tightens a paragraph, translates a section. The output is watermarked as processed by AI. In a culture already armed with AI detectors and purity tests, that becomes a scarlet letter for using a tool, not a detection of deception. Journalism, academia, law, and technical writing are hybrid by nature. Staining every assisted paragraph is not honesty. It is pipeline forensics mistaken for authorship.

False negatives on real harm. Fraud, influence operations, and abuse do not need a watermarked commercial API. Open weights, local inference, paraphrase loops, and multi-model laundering exist specifically to break brittle provenance. The actors who most need to be identified are the least likely to use the stack that cooperates with Brussels.

There is also a market response waiting in the wings: humanizer tools, rewrite services, “remove AI watermark” products. Law that creates a laundering economy is not regulating speech. It is subsidizing an arms race.

None of this requires accusing compliant labs of bad faith. They are rational. The Code asked for marks on AI-generated content. The operational definition of “generated” at a model boundary is “whatever we emit.” So everything gets marked, including your essay after a copy-edit. That is the predictable endpoint of a transparency rule that confuses tool traces with truth.

I have already argued, in the piece on manipulation and truth, that the information environment fails when signals stop correlating with reality. Universal watermarking of hybrid prose is how you break that correlation on purpose, then call it trust.

Substance: what is actually good

If you strip the theater, the Act still contains things worth wanting, provided someone enforces them.

Prohibitions. A short list of unacceptable practices, including social-scoring-style systems and certain exploitative and biometric uses as defined, is not a disclaimer. It is a market ban.[3] Voluntary ethics codes do not retire profitable products. Law can. This is the right kind of instrument for rights-hostile product categories inside the Union.

High-risk duties for high-stakes decisions. When AI is used in hiring, credit, safety-critical products, and certain public services, demanding an inspectable system, data discipline, logs, and a human review path is continuous with older product-safety and anti-discrimination instincts. Most everyday AI harm is not a scheming superintelligence. It is an institution with a model and no accountability. I covered the power side of that map in power, labor, and governance. Process law is a blunt tool, but it is a tool aimed at the right altitude: named deployers and providers, not vibes.

Market leverage on firms that want EU revenue. Extraterritorial reach is not magic, but it is real for companies that need European customers, cloud regions, and enterprise contracts. That is how GDPR moved defaults. The same pressure can force documentation, drop obviously illegal modes, and make “we simply do not offer that feature in the EU” a business fact rather than a blog post.

Incident reporting and supervisory capacity, if they become more than forms, give regulators something to open when a systemic model fails loudly. Institutions mature slowly. Early GDPR looked like paper too. The honest position is conditional: capacity is not yet the same as a proven hammer.

What these pieces share is simple. They constrain organizations with letterhead, invoices, and something to lose. That is not a bug. It is the only population product regulation reliably reaches.

Is it helping? Are bad actors affected?

Helping whom, and against what.

The compliant commercial middle. Banks, HR platforms, hospitals, large SaaS, public bodies with lawyers: yes, over time, if cases and audits arrive. These actors cause a large share of automated injustice without being cartoon villains. Raising the cost of shipping a scoring toy into production is a real good.

Technical alignment and containment. No, not in any serious sense. Documentation is not interpretability. Systemic-risk paperwork is not a proof about goals. The control problem does not care whether your CE file is complete.

Criminal and covert actors. Almost no more than they already ignore fraud and computer-misuse statutes. They do not file conformity assessments. They use open models, rented GPUs, and infrastructure that does not read the Official Journal.

Foreign authoritarian systems at home. Outside the Act’s center of gravity. Military and national security uses are carved away. Domestic social scoring in another capital is not a product on the EU market.

Open-weight local misuse. Hard to attribute a “provider,” easy to run without a European subsidiary, weakly covered by personal-use and research edges depending on facts.

So the slogan “this stops bad actors” needs a defendant. Split the category or the argument collapses.

ActorHit by the Act?
Aggressive firm with EU revenueYes
Negligent enterprise deployerYes when enforced
Big lab selling into the EUYes on paper, as cost of market access
Scam and fraud ringsAlmost no
Influence ops on open toolsBarely
Hostile state domestic AINo

Affected is not stopped. Firms can pay for theater, reclassify products, exit the EU market, or host the harm elsewhere. Criminals were never in the set. Selling the Act as a solution to adversaries is how you get overconfidence in Brussels and underinvestment in actual defense: platform abuse response, media forensics, security engineering, and the unglamorous work of not handing high-stakes decisions to unaccountable systems.

US and China: the comparison that is half true

The popular frame is lazy and directionally useful: America innovates, China accelerates, Europe regulates.

The United States in this cycle has leaned into a minimally burdensome national posture, fought a patchwork of state rules from the center, and preferred voluntary arrangements around frontier models and security rather than a licensing regime for training runs.[5] Private capital and model labs still concentrate there on a scale Europe does not match.[6]

China is not the free-market alternative in the cartoon. It regulates generative services, algorithms, deep synthesis, and AI-generated content labels, often more tightly on the speech layer than Brussels does.[7] The difference is subordination: regulation sits next to industrial policy, compute build-out, and state-directed capital. Control the content layer; still try to win the stack.

Europe’s failure mode is not “having rules.” It is rules as a substitute for production. The Draghi-era competitiveness diagnosis said the quiet part about regulatory density and investment.[8] You can be the jurisdiction the world trusts to write AI law and still import the models that matter. That is not sovereignty. That is a lifestyle brand with annexes.

The serious case for the Act is still real, and it deserves a clean paragraph before the knife returns.

Everyday automated injustice is often done by named firms, not anonymous gangs. Bans on social-scoring-style systems are rights wins even if scammers still deepfake. GDPR was painful and also forced global privacy defaults. Trust can be a market input: people and enterprises may adopt tools faster if they believe someone is watching the vendors. China shows that heavy control and industrial ambition can coexist; the European mistake is to treat the first as a full strategy.

The answer to that case is narrower and harder. Rights process without industrial power becomes dependency with paperwork. Labels without refusal rights become banners. Watermarks without a coherent theory of authorship become stigma machines. A continent that cannot train competitive models will not regulate its way into cognitive autonomy, no matter how elegant the risk taxonomy.

What actually needs law

Not everything that sounds ethical needs a statute, and not every statute that sounds ethical deserves defense.

Enforce hard. Prohibited practices with real withdrawals and fines. High-stakes automated decisions in hiring, credit, essential services: evidence, contestation, human review that is not theater. Public bodies included, or the law protects citizens from companies and not from the state. Platform-scale political deepfakes where the chokepoint is a professional deployer with EU presence, not a hobbyist with a GPU.

Do not confuse with primary protection. Universal “I’m an AI” on every commercial chat. Watermark-all-text as an oracle of authorship. Mountains of process on low-stakes features. These can exist as weak duties; they should not be sold as the ethical core.

Cannot be solved by this law, stop pretending. Technical alignment of highly capable systems. Criminal open-model misuse. Foreign domestic authoritarianism. Certifying that a blog post is “AI-free.”

A useful European path would narrow the hard rules to clear rights harms, lean more on liability and audit for the middle, and treat industrial policy, energy, chips, compute, procurement, as the actual sovereignty program. Sandboxes for builders, not sandboxes as brochure. Measure success by systems that do not crush people and by models and firms that exist here, not by guidelines published.

I am not arguing for a void. I am arguing against a category error that has captured the conversation since August’s transparency wave. Ethical AI, as I have been mapping it, is about bias and consent, truth and manipulation, labor and power, control and containment. The Act touches a slice of that map, mostly the institutional slice, and then covers the rest in badges.

The invoice and the GPU

Here is the whole piece in one distinction.

The AI Act can discipline organizations with a name and a European invoice. It cannot discipline people with a GPU and no letterhead, and it cannot make a watermark mean what the press release needs it to mean.

Europe wrote rules for a technology whose frontier is still largely manufactured elsewhere. Some of those rules will civilize the commercial middle, and that is worth doing without apology. Some of them will train a generation to equate ethics with disclaimers, and that will make the next real failure harder to see.

The badge is not the ethics. Enforce the power. Leave the rituals to the cookie banner industry that already perfected them.


  1. Anthropic, How Claude marks AI-generated content, Claude Help Center (updated August 2026). Notes on hybrid use, non-conclusive provenance, and false negatives are from the Limitations section of that article.
  2. Regulation (EU) 2024/1689 of the European Parliament and of the Council laying down harmonised rules on artificial intelligence (AI Act). See Articles 1–3 on subject matter, scope, and definitions of provider and deployer.
  3. European Commission, AI Act overview: risk tiers, prohibited practices, high-risk obligations, GPAI rules, and Article 50 transparency duties, including the August 2026 transparency wave.
  4. AI Act, Article 99 (penalties): up to €35 million or 7% of worldwide annual turnover for prohibited practices; lower tiers for other infringements.
  5. White House, Executive Order on a national AI policy framework (December 2025) and Executive Order Promoting Advanced Artificial Intelligence Innovation and Security (June 2, 2026), emphasizing a minimally burdensome posture and voluntary frontier-model engagement rather than mandatory pre-clearance.
  6. Stanford HAI, AI Index Report 2026: U.S. private AI investment and model production remain concentrated relative to Europe; the U.S.–China capability gap has narrowed.
  7. China’s generative AI, deep synthesis, algorithm filing, and AI-generated content labelling measures (CAC and related authorities, 2023–2025), including labelling rules phased in from 2025. Summary trackers: e.g. Mind Foundry, AI Regulations around the World (2026).
  8. Mario Draghi, The future of European competitiveness (2024), on regulatory density and the investment gap; subsequent EU debates on AI Act implementation and simplification.