Anthropic Watermarks Every Word Claude Writes
Anthropic has started hiding invisible watermarks inside the text Claude produces, and signing generated files with provenance metadata. It applies everywhere, not just in Europe, and it is baked into the models themselves rather than added at the product layer.
The trigger was the EU AI Act. Anthropic signed the Code of Practice on transparency for AI-generated content, and Claude models launching in the EU from August 2, 2026 onward ship with labelling built in.
Two mechanisms, one for text and one for files
Text gets an embedded watermark. Anthropic says it doesn't change the meaning, quality or readability of what Claude writes, and because the mark is applied at the model level it doesn't matter which door you came in through — API, Claude, Claude Code, Claude Cowork, Claude Tag, all the same. Copy the text somewhere else and the mark travels with it. Anthropic's careful phrasing is that it "may persist through some editing".
Files work differently. Images in formats like .svg, .png and .jpg get signed provenance metadata built on C2PA, the open standard from the Coalition for Content Provenance and Authenticity. That signature says Claude touched the file, and it can expose tampering afterward.
Text marks should survive through cloud partners too — AWS, Google Cloud, Microsoft Foundry — though those platforms might not carry the signed metadata.
Worldwide, by choice
The interesting part is the scope. Article 50 of the EU AI Act is a European rule, and Anthropic could have fenced the marks to European users. It didn't. Older models get a transition period under the law, and the company says it's retrofitting them.
Verification tools are promised so people can actually check the labels. No date yet. And if you're building on Claude, Anthropic's position is that working out which Article 50 obligations apply to your product is your job.
What the mark actually proves
Not as much as you'd hope, and Anthropic says so plainly.
Finding a watermark doesn't mean Claude wrote the thing. Plenty of people run their own writing through Claude to tighten it, translate it, or cut it down. The mark ends up on ideas that were entirely theirs.
Not finding one proves less still. Maybe the model predates watermarking. Maybe the text was edited hard or translated. Maybe the passage is too short to read reliably. Maybe someone converted the file format or just took a screenshot, and the metadata went with it.
Everyone else is stuck on the same problem
Google DeepMind open-sourced SynthID, which lives inside Gemini and works by nudging token probabilities during generation. Multilingual, but it struggles once text gets edited. OpenAI has reportedly been sitting on a detector with 99.9 percent accuracy for about two years and still hasn't shipped it — translation and rewriting beat it easily, it risks stigmatising certain groups, and releasing it wouldn't obviously help OpenAI's business.
Schools are where this cuts deepest. Bad detectors have already produced false cheating accusations, and there's research suggesting heavy AI use erodes critical thinking and writing ability. A verifiable watermark beats a statistical hunch. But only if it holds up through the editing and reformatting that real work involves — and that's the open question.
The trade Anthropic is making
Claude is popular for knowledge work, students very much included, in part because it writes naturally. Detection that actually works makes it less appealing to those exact users. Anthropic is taking that hit to be early and explicit about provenance.
Image: Szabó Viktor, via Pexels





