← All posts / Policy

Claude Now Watermarks Every Word It Writes: Inside Anthropic's Invisible Marking Rollout

Anthropic now embeds invisible, machine-readable watermarks in all Claude-generated text and C2PA provenance metadata in generated files — worldwide, with no opt-out — to comply with the EU AI Act's Article 50 transparency rules that took effect August 2.

Claude Now Watermarks Every Word It Writes: Inside Anthropic's Invisible Marking Rollout

If you’ve used Claude to draft anything since early August 2026, that text now carries a watermark you can’t see. Anthropic confirmed this week that Claude models launched on or after August 2, 2026 embed an invisible, machine-readable watermark in every piece of text they generate — and attach cryptographically signed provenance metadata to generated files. The policy applies globally, across every product surface, with no opt-out. The trigger is a law: the EU AI Act’s Article 50 transparency obligations, which became enforceable on August 2. But Anthropic’s implementation goes further than the regulation strictly demands, and it has ignited one of the most pitched user backlashes the company has faced.

What actually shipped

According to Anthropic’s support documentation, Claude now marks its output using two complementary techniques.

Embedded watermarks in text. When a supported Claude model generates text, it “weaves an imperceptible watermark directly into the text itself.” Anthropic says it doesn’t change the meaning, quality, or readability of the response. Critically, the watermark is part of the text — not metadata attached to it — so it travels when users copy and paste the text elsewhere, and “may persist through some editing.” Watermarking is applied at the model level, meaning it’s present no matter which Claude product or surface the output comes from: the Claude Platform API, the Claude app, Claude Code, Claude Cowork, and Claude Tag. It also applies when supported models are accessed through cloud partners AWS, Google Cloud, and Microsoft Foundry.

Signed provenance metadata for files. When Claude generates a supported file type — .svg, .png, .jpg — it attaches signed provenance metadata following the Coalition for Content Provenance and Authenticity (C2PA) open standard, the same system used by Google and Adobe. If a signed label is present, it signals the file was processed by Claude and lets you detect whether it has been tampered with.

One notable choice: Anthropic is applying the marking worldwide, not just to EU users. And models launched before August 2 are being retrofitted with marking support as well, though no timeline has been given — the law includes a transition period for those older models.

The law behind it

The catalyst is the EU AI Act’s Article 50, whose transparency obligations took effect on August 2, 2026. The rules require providers of generative AI systems to mark AI-generated or synthetic output in machine-readable formats, so that downstream users, platforms, and regulators can identify it. Non-compliance carries fines of up to €15 million or 3% of a company’s total worldwide annual turnover, whichever is higher. (Generative AI systems have until December 2, 2026 to meet the specific machine-readable marking requirement under Article 50(2).)

Anthropic is a signatory to the EU’s Code of Practice on Transparency of AI-generated Content, a voluntary compliance framework finalized in July 2026 that confers a presumption of conformity with Article 50. As of late July, nearly 200 companies had signed, including Microsoft, Google, Meta, OpenAI, Black Forest Labs, and Synthesia. Notably absent: xAI. The Code generally requires providers to implement multilayered machine-readable marking of outputs and deployers to apply visible labels — and it promotes open standards like C2PA and a common EU icon.

How the watermark works

Anthropic hasn’t published full technical documentation yet, but the mechanism it describes matches the statistical watermarking approach long studied in the research literature. The model subtly biases its word choices according to a key held by Anthropic. Any individual word choice looks unremarkable, but across enough text, the pattern becomes statistically detectable by someone holding the verification method.

This is why the watermark survives copy-paste — the signal lives in the choice of words themselves, not in a header or metadata block that gets stripped in transit. It’s also why it degrades gracefully: heavy paraphrasing, translation, or mixing into other writing can wash it out, and very short passages may not contain enough text for a reliable signal.

The C2PA file metadata works differently: a digital signed record of provenance is attached to the file, and the signature can be checked to verify whether the file was modified after Claude generated it. But it can be stripped through re-saving, format conversion, or screenshots — which is precisely why the two systems are designed to complement each other.

Anthropic says it will release detection tools enabling users and third parties to check whether text or a file carries a Claude mark, along with technical documentation — but neither is public yet.

The caveats Anthropic itself flags

The support page is unusually candid about what a detection result does and doesn’t mean. A detected mark signals that content may have been processed by Claude — nothing more. Claude may not be the original author: people routinely use it to proofread, translate, summarize, or convert files, and that output can carry the mark even though the underlying ideas and text originated elsewhere. The mark says Claude touched it, not that Claude wrote it.

Conversely, the absence of a mark doesn’t prove human authorship. Content may carry no detectable mark if it came from a pre-August model, was heavily edited, is very short, or had its metadata stripped. Anthropic also warns developers who deploy Claude in their own products to independently assess what Article 50 requires of them.

The backlash

The rollout has proven genuinely divisive. On X and Reddit, users called the policy “hugely problematic,” and some reported cancelling subscriptions. Several distinct objections have emerged:

  • Misleading accusations. A file a person wrote and lightly polished with Claude could return a positive detection — with no published accuracy thresholds and no dispute procedure for contested results.
  • Attribution and credit. Writers and academics who use Claude to edit substantially their own work now face that work carrying an AI marker they never consented to.
  • Unverifiable claims. Anthropic asserts the watermark doesn’t affect output quality, but hasn’t published implementation details, leaving users unable to verify that independently.
  • Developer concerns. Coders raised pipeline worries about cryptographic signatures and statistical bias interacting with generated code.

There’s also a competitive irony: reporting from the Wall Street Journal suggests OpenAI has had the technical capacity to watermark ChatGPT text for years but held back over concerns including false positives and competitive risk. Anthropic’s move — driven by a regulatory deadline — may force the industry’s hand. Suno began marking AI-generated music tracks last week after legal challenges, and Substack partnered with detection firm Pangram in July to flag AI content.

Why it matters

This is the first time a frontier lab has deployed text watermarking at this scale, globally, with no opt-out. It turns a research-grade technique into production infrastructure, and it makes the EU AI Act’s transparency regime tangible for hundreds of millions of users who will never read the regulation. The unresolved questions — detection tooling, accuracy rates, dispute processes, retrofit timelines for older models — will determine whether this becomes a trusted provenance layer or a persistent flashpoint. For now, every word Claude writes carries a signature most of us can’t see.