3 min read
Anthropic has begun embedding an imperceptible watermark in all text its newest Claude models generate. The change took effect for models launched in the EU on August 2, 2026, and Anthropic says it will apply worldwide.
Anthropic laid out the plan in a support article after signing the EU AI Act's Code of Practice on transparency. In other words, it’s not exactly volunteering to do this. The mark reaches every Claude surface, from the chatbot and API to Claude Code and cloud partners such as AWS, Google Cloud, and Microsoft Foundry.
Myriad: When will OpenAI release GPT-6? Click to make your prediction.
“When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. You won't see it, and it doesn't change the meaning, quality, or readability of Claude's response,” Anthropic said. “Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing.”
So it's a bit more complex than the usual methods users tend to think about. When a supported Claude model writes text, it weaves an imperceptible watermark directly into the words, with no visible tag. Because the mark is part of the text, it survives copy-paste and, Anthropic admits, "may persist through some editing." Files get a second layer: signed metadata under the C2PA open standard (think a digital shipping manifest that records who produced a file and whether anyone altered it afterward).
Anthropic hasn't said how the watermark is made. The support article calls it model-level (the model is trained with it) and text-native (it’s not an external tool like metadata generator, for example), but the detection documentation and the exact technique aren't out yet.
Researchers infer it's a statistical signature: The model nudges its word choices toward a faint, detectable bias, the same family of approach Google uses in SynthID Text. That remains a guess until Anthropic publishes the detector.
But that isn’t pushing privacy enthusiasts back, and some experts are already working on methods to break Anthropic’s secret watermarking. mikiane/claude-watermark-cleaner (106 stars on Github) scrubs invisible Unicode, then rewrites text with a non-Claude model to disturb the token pattern.
A larger project, guillaumemeyer/watermarks-remover (4.6k stars on Githum), strips Claude text marks plus C2PA and SynthID-class signals across PNG, JPEG, SVG, PDF, and DOCX. The authors argue a statistical text mark is "not a reliable way to prove origin" and mostly pushes users to spend a second model pass cleaning their own writing. No removal can be guaranteed until Anthropic ships its detector and thresholds.
Anthropic's own history makes the privacy reaction sharper. The company removed a hidden Claude Code tracker in March after researchers found it tagging some users' location and proxy use through undisclosed Unicode markers—the same quiet-marking technique now at the center of the watermark plan.
The mark proves Claude had a hand in text, not that it wrote the whole thing, so it will treat an original writing with a small edit the same as a fully AI-generated text. Ask Claude to proofread or translate your paragraph and the output can still carry the signal. Anthropic is upfront that heavy editing can strip it, and that a missing mark doesn't prove a human wrote something.
A U.S. bill, the COPIED Act, pushes the same idea: a standardized way to watermark AI content so platforms can trace its origin. As Claude's blackmail problem showed, the company's models already draw intense scrutiny over what they do with the text they touch.
Anthropic hasn't said when it will publish the detection tools that would let anyone verify the mark.
Decrypt-a-cookie
This website or its third-party tools use cookies. Cookie policy By clicking the accept button, you agree to the use of cookies.