Claude now watermarks everything it writes — what it catches, what it misses, and what it means if you publish
TL;DR: On 11 August 2026, Anthropic said Claude now embeds an invisible, machine-readable watermark in the text it generates. It is not a hidden character you could find and delete — it is a statistical signal nudged into the model’s token choices during generation, in the same family as Google’s SynthID-Text, detectable only by running a test with a secret key. It covers models released from 2 August 2026 onward, with older models to follow by 2 December, and applies worldwide across the Claude apps, the API, Claude Code, Claude Cowork and Claude Tag, plus cloud partners AWS, Google Cloud and Microsoft Foundry. Files get the C2PA provenance standard. The mark survives copy-paste, retyping and screenshotting; a paraphrase — by you or another model — erases it. The driver is the EU AI Act’s transparency code, which took effect 2 August. The structural point for buyers: this moves AI detection from a claim you make to a signal in the text — and it marks light editing and wholesale generation identically. It does not replace your own disclosure duty, and it does not stop anyone who wants to remove it.
What Anthropic actually announced
On 11 August, Anthropic said that Claude has begun embedding a machine-readable watermark in the text it produces. Three details separate this from the “AI detector” tools that have been unreliable for years.
First, the mechanism. This is not a hidden Unicode character, a zero-width space, or an odd bit of punctuation you could search for and strip. It is a statistical watermark applied during sampling: at each step where the model is choosing among several near-equivalent next tokens, the choice is nudged according to a secret key, so that over a long enough passage the text carries a detectable statistical signature. Nothing about the wording looks unusual to a reader. Recognition requires a detector that holds the key and runs a test, and it returns a probability score rather than a clean yes or no. That places it in the same technical family as Google DeepMind’s SynthID-Text, which has been in production on Gemini output.
Second, the coverage. The watermark applies to models released from 2 August 2026 onward — which currently means Claude Opus 5, Sonnet 5 and Fable 5 as they are updated — with older models to be covered through an extended rollout by 2 December 2026. It applies across every surface: the Claude apps, the API, Claude Code, Claude Cowork and Claude Tag, and it reaches the model wherever it runs, including through cloud partners AWS, Google Cloud and Microsoft Foundry. It is global, not EU-only. For files rather than raw text, Anthropic is using the C2PA open provenance standard, the same content-credentials scheme cameras and image tools have adopted.
Third, the honesty about limits, which Anthropic put in the announcement itself: the absence of a detected mark does not mean content was not made with AI, and extensive editing, paraphrasing, translation or very short passages can make detection fail.
Why now: this is the EU AI Act arriving on schedule
None of this is spontaneous. The driver is the Code of Practice on Transparency of AI-generated Content under Article 50 of the EU AI Act, which became applicable on 2 August and requires providers of generative systems to mark synthetic output in a machine-readable way that other systems can detect. Anthropic is one signatory among many: OpenAI, Google, Meta, Microsoft, Black Forest Labs and Synthesia all committed to the same code. What distinguishes Anthropic’s move is that it went first and loudest on text — the hardest modality to watermark — and chose to apply the mark worldwide rather than geofencing it to the EU.
That timing matters for how to read it. The provider-side marking obligation was the half of Article 50 that this site flagged as mostly free to you — a duty that lands on the vendor, invisible in daily use. What ships on 11 August is exactly that obligation becoming real infrastructure. The other half of Article 50 — the deployer duty to disclose when you publish AI-generated text to inform the public — is untouched by this, and still yours.
What survives, what doesn’t — and why that shape matters
The removability profile is the whole story, so it is worth being precise about it.
Survives: copying and pasting the text elsewhere, retyping it by hand into a CMS, screenshotting it and re-typing, running it through a plain-text editor. Because the signal lives in which words were chosen, not in any invisible characters, none of the usual “cleaning” tricks touch it.
Does not survive: paraphrasing, translation, or feeding the passage to a different model and asking it to rewrite — anything that substantially changes which tokens appear. Very short passages also carry too little signal to score reliably.
Put those together and the mark has a clear character: it catches the honest and the casual, and misses the determined. Someone using Claude openly to draft a blog post leaves the fingerprint. Someone running the output through a second model to launder it does not. That is not a flaw Anthropic can engineer away — it is inherent to statistical text watermarking, and it is why the reaction has been sceptical in places. As Fortune put it, watermarking alone will not clean up the internet, because anyone determined to disguise AI output “has plenty of ways to degrade or erase a statistical text watermark.”
Why this matters
It moves detection from a claim to a signal. For three years, “was this written by AI?” was answered by a probabilistic classifier guessing from style, or by the author’s own disclosure. Both are contestable. A watermark that the generator embeds is a different kind of evidence: not proof a human can eyeball, but a test a platform, university or publisher can run. If you publish AI-assisted text and treat “nobody can prove it” as your safety margin, that margin just narrowed — at least against anyone Anthropic gives a detector to.
It marks light editing and wholesale generation identically — and that is the real problem. The mark signals that Claude processed the text, not that a machine wrote it. A student who used Claude to fix grammar, a journalist who used it to translate a transcript, and a content farm generating a thousand articles can all trip the same detector. TechTimes’ framing is the accurate one: the mark proves processing, not authorship. Any institution that treats a positive detection as “this is AI slop” will punish honest, disclosed, minor use exactly as hard as deceptive mass generation. The tooling is ahead of the policy.
It does not lift your disclosure duty. If you run a publication, the vendor marking its output does nothing for your Article 50(4) obligation to disclose AI-generated text you publish to inform the public. The two obligations are independent. This site, for instance, discloses on every article regardless of any watermark. What the watermark changes is the cost of not disclosing — it makes an undisclosed use more findable.
It is an industry inflection, not an Anthropic quirk. Every major lab signed the same code, and Google already ships SynthID across text and images. Text provenance is becoming table stakes, the way image content-credentials did over the past two years. The practical consequence for buyers is that “AI-assisted” is quietly becoming a property recorded in the artefact, not just an admission the author may or may not make.
Honest caveats
Anthropic has not published the full spec. There is no public false-positive rate, no broadly available detector at launch, and no precise threshold for how much editing defeats the mark — TechCrunch noted Anthropic did not answer its request to clarify. “Survives some editing” is doing a lot of unspecified work.
A closed detector is an asymmetric tool. Until a public detector exists, the mark is only useful to whoever Anthropic hands the key to — platforms, regulators, perhaps enterprise customers. That is a reasonable rollout, but it means the transparency benefit currently flows to institutions, not to the individual reader deciding whether to trust a page.
Statistical watermarks have a documented history of removal. This is not DRM and Anthropic does not claim it is. A single pass through a competing model erases it. Treat a positive detection as informative and a negative one as meaningless — which is exactly what Anthropic says.
“Claude touched this” is a low bar for a high-stakes label. The gap between “edited by AI” and “written by AI” is enormous, and this mark does not distinguish them. Any downstream policy that ignores that gap will be unfair, and the fairness problem is not Anthropic’s to solve — it lands on the schools, journals and platforms that consume the signal.
The verdict
This is the most consequential transparency move a frontier lab has made this year, and it is genuinely useful — provenance recorded in the artefact beats provenance asserted by whoever happens to be holding it. It is also narrower than the headlines suggest. It marks processing, not authorship; it catches openness, not deception; and it is trivially defeated by the one step a bad actor is most likely to take.
For an AI-tools buyer the takeaways are concrete. If you publish, stop treating light AI polish as invisible — assume Claude output is now detectable, and lean into disclosure rather than around it, because the disclosure norm is hardening regardless of the watermark. If you write for a living, know that a paraphrase defeats the mark, and that the detector cannot tell a proofread from a fabrication — which cuts both ways. And if you were choosing between Claude and ChatGPT or picking among the best AI writing tools on transparency grounds, this narrows the gap rather than opening one: the whole industry signed the same code, and the rest are on the same clock.
Frequently asked questions
Does the Claude watermark mean Anthropic can read what I write?
No — the watermark carries no content. It is a statistical pattern nudged into which words the model picks while it generates, detectable only as a score by someone running a test with the secret key. It does not encode your prompt, your identity or the text's meaning, and it is not a tracking beacon that phones home. The privacy question worth asking is narrower: who holds the detector key, and Anthropic has not published a broadly available public detector yet.
If I only use Claude to polish or translate my own writing, will it flag me as AI?
This is the sharpest fairness problem with the whole scheme. The mark signals that Claude processed the text — not that a machine wrote it from scratch. A journalist using Claude to translate an interview transcript, or a writer tidying one paragraph, can leave the same statistical fingerprint as someone mass-producing filler. A detector returns 'this was generated or edited by Claude,' not a proportion. Until detectors expose nuance, light and heavy AI use look alike.
Can I remove the watermark?
Yes, and easily, if you are determined. Any rewrite that substantially changes which tokens appear defeats it: paraphrasing, translating, or asking a different model to rewrite the passage. Very short passages carry too little signal to detect. What does not remove it: copying and pasting, retyping into a CMS, screenshotting and re-typing, or running it through a plain-text editor. So the mark catches casual and honest use, and misses anyone who cares to erase it.
Do I still have to disclose AI use under the EU AI Act now that Claude marks it?
Yes. The vendor-side marking and your disclosure duty are two separate obligations under Article 50. Anthropic marking its output satisfies the provider's machine-readable-marking requirement; it does nothing for the deployer duty on anyone who publishes AI-generated text to inform the public. If that is you, you still disclose. What changed is that the marking now makes an undisclosed use easier for others to detect.
Do ChatGPT and Gemini watermark text too?
They have committed to. OpenAI, Google, Meta, Microsoft, Black Forest Labs and Synthesia all signed the same EU Code of Practice on transparency of AI-generated content that Anthropic is acting on. Google already ships SynthID for text and images; Anthropic's approach is in the same statistical-watermark family. Anthropic is notable mainly for moving first and loudest on text, and for applying it worldwide rather than only in the EU.
Sources
- TechCrunch — Anthropic says it will watermark text generated by its AI models
- Fortune — Anthropic plans to add an invisible mark to AI text as the industry scrambles to police AI slop
- Gizmodo — Anthropic's Claude Will Start Adding Invisible Watermarks to AI-Generated Text
- Forbes — Claude Will Put Invisible Watermarks On AI Text And Images—And The Internet Isn't Happy
- Interesting Engineering — Anthropic puts invisible watermarks on Claude text under EU rules
- Anthropic — Transparency Hub (voluntary commitments)
Related tool reviews
Questions or corrections? Email Pick Right. Want the full list? See all news.