The watermark is a product philosophy, not just a feature
Anthropic is adding invisible watermarks to text generated by new Claude models and signed provenance metadata to supported files. The change is connected to the EU AI Act’s transparency rules, which require providers to make AI-generated text, images, audio, and video technically detectable. Anthropic says the marks apply worldwide, not only in Europe. It also warns that the signal is not conclusive proof of authorship and can disappear after heavy editing, paraphrasing, translation, or metadata stripping.
The rationale is understandable. AI-generated work can be passed off as human-made, and machine-readable provenance could help with fraud and misinformation. But a small technical marker also shows a larger direction: the provider is deciding how every output should travel after it leaves the chat window.

The illustration shows provenance as a signal that follows an AI-generated document.
A paid subscription does not mean an open developer surface
The same feeling appears in Anthropic’s account boundaries. Anthropic’s official documentation says that a Claude Pro subscription does not include API usage through the Claude Console. A developer who wants to build an application or integration needs separate Console access and API billing. Anthropic also says that third-party tools should use API-key authentication, while attempts to disguise third-party traffic or route it through subscription limits can be enforced against.
It would be inaccurate to say that Anthropic blocks every external use. The official API is a real developer path. Still, the boundary is clear: paying for the consumer experience does not give a user the same freedom to connect Claude to any external workflow. For someone who expects a subscription to be a general-purpose capability, the separation feels restrictive.
I have had this impression of Anthropic for a while. I cannot claim to know the company’s internal DNA, but its policies often make the developer ecosystem feel like a list of approved doors. A new connection, a new automation, or a new way to use an account is first interpreted through permission, identity, and enforcement. Safety and abuse prevention are legitimate concerns. The question is what happens when the controls become more visible than the possibilities.
Why Codex feels different
This is where Codex creates a sharp contrast. To be precise, OpenAI has not open-sourced every Codex product or model. But Codex CLI is an open-source command-line tool, and OpenAI describes the agent implementation behind it as open source. Developers can inspect how the local agent reads files, calls tools, applies approvals, and runs inside a sandbox.
That distinction matters more than the slogan. An open implementation does not make the model automatically safe, nor does it remove usage policies or account requirements. It does move part of the control surface closer to the developer. Instead of asking only whether the provider will permit a workflow, a developer can inspect the tool, change parts of it, or build an integration around a visible execution layer.
For me, this is the difference between a controlled service and a composable tool. Anthropic’s approach says: use the model through the boundaries we define, and let the provider verify how the result was made. Codex’s open CLI says at least one important layer can be examined and adapted by the people building with it. That is not complete freedom, but it is a different relationship with the developer ecosystem.
Open source is not the same as no rules
There is a danger in turning this into a simple good-company versus bad-company comparison. Provenance marks can serve a real public interest, and a closed service can sometimes provide stronger operational safety. Open source can still contain security flaws, and a visible agent loop does not make its model transparent.
The better question is who controls the boundary. Can users understand the restriction? Can developers choose a different integration path? Can the relevant layer be inspected, forked, or replaced? Are the reasons for enforcement proportional to the risk?
Anthropic’s watermarking makes AI output more governable. Codex CLI’s open-source implementation makes part of the agent more inspectable. These are two directions the AI ecosystem may increasingly divide between: managed assistants with strong provider-defined rules, and developer tools that leave more room for local judgment.
Freedom does not mean having no limits. It means knowing where the limits are, why they exist, and whether you have another way to build. That is why the difference between Anthropic and Codex feels larger than one watermark announcement.



