Blog

Aug 11, 2026

Claude Text Watermarks in 2026: What Anthropic Announced

Anthropic will watermark Claude's text, but only for models launched on or after August 2, 2026. Older models are in progress. The quotes and the dates.

The version going around this week is that every word Claude writes is now watermarked, retroactively, everywhere. Anthropic's own support page says something narrower, and the difference matters if you have spent the last year letting an assistant draft your notes and emails.

The page is called "How Claude Marks AI-Generated Content" (support.claude.com, accessed August 11, 2026). Its central sentence is a date, not a blanket claim: "Claude models launched on or after August 2, 2026 support marking at launch." The page states this twice with slightly different scope: a summary bullet says "Claude models launched in the EU on or after August 2, 2026", while the detail section drops the in-the-EU qualifier. The Regions section is unambiguous that the marking itself applies worldwide. For everything released before that, the page says Anthropic is "working to add marking support for those models as well", and describes that work as in progress, within the law's transition period.

Read plainly, that means the draft you generated this morning from a model that shipped in, say, June is not carrying a watermark. It also means no Claude text is watermarked yet. Anthropic's current lineup all predates the cutoff: Claude Fable 5 shipped June 9, 2026, Claude Opus 5 on July 24, 2026, and the Claude Platform release notes for August 1, 5 and 7 announce no new model. Output from the first model launched on or after August 2 will carry a watermark. Nothing is applied backwards to text that already exists.

What Anthropic actually committed to

The commitment is a signature on a specific instrument. In Anthropic's words, "Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content", and the commitment covers both generative AI models and systems.

Two kinds of mark come with it. Generated text gets an embedded watermark. Files, where applicable, get digitally signed provenance metadata.

The coverage is broader than the law that prompted it. "Marking will apply to output from supported models wherever Claude is offered, worldwide", across Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag. The page resolves the per-surface question for text: "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from", and "Embedded watermarks will apply when supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry." The page carries a general platform caveat, that some platforms or features may not support certain marking types, and one specific to files: "Signed provenance metadata may not be supported on every platform, depending on the features each platform offers."

How an embedded text watermark behaves

The mechanism is described in one line: "it weaves an imperceptible watermark directly into the text itself." Anthropic says this does not affect readability or meaning.

The consequence is the part people are reacting to. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing."

That sentence is doing careful work. Travel with copy and paste is stated flatly. Survival through editing is hedged to "may persist through some editing", and the page separately admits that marks can be lost through editing, format conversion or platform limitations. So a paragraph pasted straight from a marking model into an email will carry the mark. The same paragraph rewritten twice, run through a formatting converter and pasted into a tool that mangles the text may not. Anthropic is not claiming an unbreakable tag, and neither should anyone quoting it.

Files are marked a different way

For supported file types, which the page gives as examples rather than a closed list, such as .svg, .png and .jpg, the page says "it will attach signed provenance metadata. This metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard." That metadata signals the file was processed by Claude and makes tampering detectable.

The two live in different places. The text watermark is in the words, and the C2PA metadata is in the file wrapper. Metadata is routinely stripped by upload pipelines and screenshots. The two mechanisms fail in different ways.

Why August 2 is the date

The date is not Anthropic's. The European Commission's own guidance states that "Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision."

There is a wrinkle the coverage mostly skipped. The same Commission page describes a limited grace period, and it applies to exactly the obligation at issue here: AI systems placed on the market before 2 August 2026 must comply with the Article 50(2) marking and detection duty only from 2 December 2026. That maps neatly onto the shape of Anthropic's announcement, with new models marking at launch and older ones described as in progress rather than late.

Crypto Briefing, reporting the signature, framed it the same way, noting that Anthropic "signed onto the EU AI Act's Article 50(2) Code of Practice, a voluntary framework that becomes legally enforceable on August 2, 2026." Voluntary code, hard date, worldwide rollout.

There is no detector, and no opt-out described

Two absences in the document are as newsworthy as its contents.

The first is detection. Anthropic commits to it without shipping it: the page says it will "support users and other third parties to detect Claude's marks, as the Code requires", and that "we'll share details on detection mechanisms in forthcoming technical documentation." Nothing is published yet, so there is currently no public tool to test a paragraph against. Anyone claiming this week to have caught a document by its Claude watermark is working from something other than published Anthropic tooling.

The second is control. The support page describes no opt-out. It sets out the products covered, the model cutoff, both mark types and the limits of each, and it never mentions a setting to turn marking off. That may change, and a different page may say otherwise later, but the document announcing the commitment offers no switch.

Anthropic is also honest about how weak a detection result will be in both directions. A detected mark means content "may have been processed by Claude", not that Claude wrote it, because Claude may not be the original author and the content can be modified afterwards. No detected mark proves nothing either, since marks can be lost through editing, format conversion or platform limitations, and since the page notes a very short passage leaves too little text for a reliable signal. Provenance marking is evidence, not proof, and it is much better at answering "was a machine involved somewhere" than "who wrote this".

What this means if an assistant drafts your work

Suppose your week runs on AI drafts. Meeting notes summarized automatically, follow-up emails written from a transcript, a first pass at a document you then rewrite. Three practical consequences:

Everything produced so far is unmarked. There is no archive to worry about, no need to audit last quarter's notes, nothing retroactive in the announcement.

When the tools you use move to a model launched on or after August 2, 2026, provenance starts travelling with the text you paste. A summary pasted into Slack, a paragraph pasted into a proposal, a line dropped into a shared doc. The mark goes where the text goes, at least until something strips it.

Heavily edited text is the ambiguous case. If you take an AI draft and rewrite most of it, "may persist through some editing" is all you have to reason with, and there is no published detector to check the result. Treat authorship of edited work as a question your disclosure answers, not one the watermark will settle for you.

Routines, the Mac app we build, also publishes audits of AI vendors written only from each vendor's own published documents, such as the one on Notion AI, and marking puts a receipt of that kind inside the text itself.

Disclosure over evasion

Tools that strip provenance from AI output already exist, and we are not going to name or describe them. The reason is practical rather than moral. Stripping a mark buys you deniability about a fact you could have stated in one sentence, and it commits you to maintaining that deniability against detection tooling that has not shipped yet.

The cheap alternative is a line of text. "First draft written with Claude, edited by me" at the top of a document costs nothing, survives every format conversion, and cannot be defeated by a paste into the wrong editor. Most of the anxiety this week is about being caught rather than about doing anything wrong, and the fix for that is disclosure.

Disclosure: the content on this site, this article included, is produced with Claude's help. Under the rules above, none of it published before today is watermarked either, which is exactly why the sentence is here instead of a mark you cannot check.

What is settled, and what is not

Settled, from the support page as of August 11, 2026: Claude models launched on or after August 2, 2026 will mark at launch, and none has launched yet; earlier models are in progress; text gets an embedded watermark and supported files get C2PA-signed metadata; coverage is worldwide across Claude, the API, Claude Code, Claude Cowork and Claude Tag; text watermarking is applied at the model level and so does not vary by surface, while signed provenance metadata may not be supported on every platform.

Not settled: how detection will work, when the technical documentation lands, whether any opt-out will appear, and how much editing a watermark actually survives.

If you want the primary source rather than a screenshot of it, Anthropic's page is short and worth ten minutes.

FAQ

Does Claude watermark text today?

No. Not yet, for anything. Anthropic's support page states that Claude models launched on or after August 2, 2026 support marking at launch, and that for models released before that date it is "working to add marking support for those models as well", which it describes as in progress within the law's transition period. Text written today by a model that shipped before August 2 is not carrying an embedded watermark. Text from the first model launched on or after that date will be.

Can you remove the watermark from Claude's text?

It is built to survive ordinary handling. Anthropic writes that "because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing". Note the word may: the page also says marks can be lost through editing, format conversion or platform limitations, so this is not presented as unbreakable. Tools that strip provenance already exist and we will not point you at them. If you are worried enough about a mark to hunt for a remover, the cheaper fix is a line at the top of the document saying the draft was AI-assisted.

Will my meeting notes be watermarked?

It depends on which model wrote them and when. Marking applies to output from supported models wherever Claude is offered, worldwide, across Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, though Anthropic notes some platforms may not support all marking types. Notes summarized by a model that launched before August 2, 2026 are unmarked, and nothing is applied retroactively to notes already written. Once the tool you use moves to a model launched on or after that date, the summary text can carry an embedded watermark.

Is this EU-only?

No. Anthropic states that marking "will apply to output from supported models wherever Claude is offered, worldwide". The date comes from European law even though the coverage does not. Anthropic signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and the European Commission states that Article 50 of the AI Act applies from 2 August 2026. One summary bullet does add an in-the-EU qualifier to the model cutoff, which the detail section omits.

How can I check whether a piece of text is watermarked?

You cannot yet, at least not with anything Anthropic has published. The support page says only that "we'll share details on detection mechanisms in forthcoming technical documentation". Until that lands there is no public detector to point at a paragraph, which is worth remembering when someone claims to have caught a document out.

Is there an opt-out?

The support page describes none. It lists the products covered, the model cutoff date, the two kinds of mark and the limits of both, and it does not mention a setting that turns marking off. If an opt-out exists somewhere else, it is not in the document announcing the commitment.

Does a detected watermark prove a text came from Claude?

No, and Anthropic says so. Detecting a mark indicates content "may have been processed by Claude", which is weaker than authorship: Claude may not be the original author, and the content can be modified afterwards. The reverse is also weak. No detectable mark does not confirm that content was not AI-generated, because marks can be lost through editing, format conversion or platform limitations, and because the page notes a very short passage leaves too little text for a reliable signal.

What about images and files, not text?

For supported file types, which the page illustrates with .svg, .png and .jpg, Anthropic writes that "it will attach signed provenance metadata. This metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard." That metadata signals the file was processed by Claude and allows tampering to be detected. It is a separate mechanism from the text watermark, and it sits in the file's metadata rather than in the words.

Sources

Related

Related posts

Try it on your Mac.

Routines keeps your notes, transcripts, and routine outputs as markdown and SQLite on your machine, where they stay unless you turn on Cloud Sync.

Download