Starting August 2, everything Claude writes carries an invisible mark. Copy and paste it anywhere, and the mark comes along. But here's the thing — there's currently no way for anyone to actually check for it.
Here's exactly what Anthropic announced
On August 11, 2026, Anthropic made it official: starting with Claude models released after August 2, generated text will carry a watermark invisible to the human eye. The move comes from signing the EU AI Act's Article 50 Transparency Code of Practice — and notably, the rollout isn't limited to Europe, it's going global.
Technically, here's how it works. When Claude generates a response, it weaves an invisible statistical signal into the text itself. Anthropic says "this signal doesn't change the meaning, quality, or readability" of the response. The mark is part of the text, so it travels through copy-paste, and can survive some editing.
Files work differently. Supported formats like SVG, PNG, and JPG get signed metadata based on the C2PA (Coalition for Content Provenance and Authenticity) standard. It's less a watermark woven into the content and more a digital tag attached to the file.
| Category | Text Watermark | File C2PA Metadata |
|---|---|---|
| Applies to | All text Claude generates | Supported files (SVG/PNG/JPG) |
| How it works | Invisible statistical signal embedded | Signed provenance data attached to file |
| Copy/Edit | Can survive moderate editing | Can be lost on format conversion/re-save |
| How to verify | Detection tool not yet released (promised) | Viewable with C2PA-compatible viewers |
Coverage spans the whole product line — not just the Claude chatbot, but Claude Code, Claude Cowork, Claude Tag, and the platform API, plus usage through AWS, Google Cloud, and Microsoft Foundry. Older models will get retroactive support on a rolling basis, Anthropic says.
Key point
Anthropic draws its own line here: "a detected mark is a signal that Claude processed the content — not proof of full authorship." Even a human-written draft that Claude only proofread, translated, or summarized will carry the mark.
Why this doesn't settle the AI-detection question
It's tempting to hear "watermark" and assume AI writing just got easy to catch. In reality, there's currently no way to verify it at all. As South Korean outlet WikiTree points out, Anthropic has only promised "technical documentation" down the road — no detection tool exists yet for users or third parties to actually check a watermark.
And removing it may be easier than you'd think. The Register notes that image watermarking has already been defeated multiple times, and points out that OCR re-extraction or heavy editing can neutralize the text mark. The very design constraint of not degrading meaning or readability limits how robust it can be. Open-source tools for stripping C2PA file metadata already exist, too.
Cuts both ways
Don't assume a watermark means "100% AI-written" — and don't assume no watermark means "a human wrote this." Short passages and heavily edited content can lose the mark entirely.
This isn't a new problem, either. Third-party AI detectors have struggled with reliability for years. A University of Florida study presented at the 2026 IEEE Symposium on Security and Privacy tested five commercial AI text detectors and found false positive rates ranging from 0.05% to 68.6%, and false negatives from 0.3% to 99.6% — wildly inconsistent across tools. Even slightly more sophisticated word choices defeated most of them.
"These are not reliable or robust tools to use to measure the problem. We really can't use them to adjudicate these decisions. People's careers are on the line here."
Professor Patrick Traynor, University of Florida research teamTo be fair, Anthropic's watermark is a different animal — it's embedded at the model level, not bolted on by a third party. But without a detection tool, the catch right now is that there's no way to even confirm the mark is there. The EU's Code requires signatories to have a watermark-detection interoperability solution in place by February 2, 2027 — meaning real verification infrastructure likely won't exist until then.
What to actually prepare for right now
Now that we know the watermark isn't a finished solution, here's what's actually actionable.
- Audit your AI content disclosure policy
Article 50 requires disclosing AI-generated deepfakes and public-interest text that hasn't undergone human review. If you have European customers or partners, check whether your publishing process already meets this bar. - Stop treating the watermark as a final verdict
Don't let a watermark or detector result alone decide hiring, contract, or academic integrity calls. Keep a human cross-check in the loop wherever real stakes are involved. - Build a habit of preserving C2PA metadata
If you handle images or design output as SVG/PNG/JPG, keep original files with intact C2PA metadata — useful evidence if you ever need to prove provenance. - Watch for the detection API
When Anthropic ships the promised technical documentation and detection tooling, test it and decide whether it belongs in your content review workflow. For now, plan around "it doesn't exist yet." - Add AI-use disclosure clauses to vendor contracts
If you outsource or take on content work, spelling out AI usage upfront in contracts heads off disputes later.
Want to go deeper?
Claude's official support doc Anthropic's own explanation of how the watermark works and what it covers. support.claude.com
TechCrunch's original report The first outlet to break down the announcement. techcrunch.com
The Register's skeptical take Why the watermark can be defeated so easily, plus industry reaction. theregister.com
A practical guide to EU AI Act Article 50 The four categories of transparency obligations and their deadlines. artificialintelligenceact.eu
WikiTree: "No verification tool yet" Korean coverage that tackles the detection-infrastructure gap head-on. wikitree.co.kr
University of Florida's AI-detector reliability study Data on why legacy AI detectors are unfit for high-stakes decisions. news.ufl.edu



