Blog

Aug 11, 2026

Claude Text Watermarks in 2026: What Anthropic Announced

Anthropic will watermark Claude's text, but only for models launched on or after August 2, 2026. Older models are in progress. The quotes and the dates.

The version that went around in mid-August is that every word Claude writes is now watermarked, retroactively, everywhere. Anthropic's own support page says something narrower, and the difference matters if you have spent the last year letting an assistant draft your notes and emails.

The page is called "How Claude Marks AI-Generated Content" (support.claude.com, accessed August 11, 2026, every quote from it below re-verified against it on August 19, 2026). Its central sentence is a date, not a blanket claim: "Claude models launched on or after August 2, 2026 support marking at launch." The page states this twice with slightly different scope: a summary bullet says "Claude models launched in the EU on or after August 2, 2026", while the detail section drops the in-the-EU qualifier. The Regions section is unambiguous that the marking itself applies worldwide. For everything released before that, the page says Anthropic is "working to add marking support for those models as well", and describes that work as in progress, within the law's transition period.

Read plainly, that means the draft you generated this morning from a model that shipped in, say, June is not carrying a watermark. It also means no Claude text is watermarked yet. Anthropic's current lineup all predates the cutoff: Claude Fable 5 shipped June 9, 2026, Claude Opus 5 on July 24, 2026, and the Claude Platform release notes through August 18, 2026 announce no new model. Output from the first model launched on or after August 2 will carry a watermark. Nothing is applied backwards to text that already exists.

What Anthropic actually committed to

The commitment is a signature on a specific instrument. In Anthropic's words, "Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content", and the commitment covers both generative AI models and systems.

Two kinds of mark come with it. Generated text gets an embedded watermark. Files, where applicable, get digitally signed provenance metadata.

The coverage is broader than the law that prompted it. "Marking will apply to output from supported models wherever Claude is offered, worldwide", across Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag. The page resolves the per-surface question for text: "Watermarking will be applied at the model level, which means it will be present no matter which Claude product or surface the text comes from", and "Embedded watermarks will apply when supported Claude models are accessed through AWS, Google Cloud, or Microsoft Foundry." The page carries a general platform caveat, that some platforms or features may not support certain marking types, and one specific to files: "Signed provenance metadata may not be supported on every platform, depending on the features each platform offers."

Anthropic has since said more about the commitment, in a longer explainer published on August 14, 2026, "How Claude's text watermark works". It puts the motive in one clause, "We're implementing watermarking to comply with the EU AI Act", places the signature in time, "along with several other major AI model providers and around 190 total signatories, signed the EU Code of Practice on Transparency of AI-Generated Content in July 2026", and settles the worldwide question in its own voice: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region." The European Commission's page on that code dates the final text to June 10, 2026.

How an embedded text watermark behaves

The mechanism is described in one line: "it weaves an imperceptible watermark directly into the text itself." Anthropic says this does not affect readability or meaning.

The consequence is the part people are reacting to. "Because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing."

That sentence is doing careful work. Travel with copy and paste is stated flatly. Survival through editing is hedged to "may persist through some editing", and the page separately admits that marks can be lost through editing, format conversion or platform limitations. So a paragraph pasted straight from a marking model into an email will carry the mark. The same paragraph rewritten twice, run through a formatting converter and pasted into a tool that mangles the text may not. Anthropic is not claiming an unbreakable tag, and neither should anyone quoting it.

The August 14 explainer fills in what the support page left as one line. The watermark is a keyed choice among words that would have read fine either way: "Instead of using an arbitrary random number generator to pick the next word, watermarking uses the key and a few words that come before to settle what word the model should pick." The resulting pattern "is undetectable to the reader, but is detectable to anyone who has a key that encodes it", and Anthropic holds the key. The page is explicit that "Nothing is added to the text and there are no hidden characters", and that watermarking "carries no identifying information and can't be traced to a specific person, organization, or chat". On editing it goes further than the support page's "may": "Light editing probably won't remove the watermark completely; a complete rewrite where every word is replaced will."

Files are marked a different way

For supported file types, which the page gives as examples rather than a closed list, such as .svg, .png and .jpg, the page says "it will attach signed provenance metadata. This metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard." That metadata signals the file was processed by Claude and makes tampering detectable.

The two live in different places. The text watermark is in the words, and the C2PA metadata is in the file wrapper. Metadata is routinely stripped by upload pipelines and screenshots. The two mechanisms fail in different ways.

Why August 2 is the date

The date is not Anthropic's. The European Commission's own guidance states that "Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply with the transparency obligations laid down in that provision."

There is a wrinkle the coverage mostly skipped. The same Commission page describes a limited grace period, and it applies to exactly the obligation at issue here: AI systems placed on the market before 2 August 2026 must comply with the Article 50(2) marking and detection duty only from 2 December 2026. That maps neatly onto the shape of Anthropic's announcement, with new models marking at launch and older ones described as in progress rather than late.

Crypto Briefing, reporting the signature, framed it the same way, noting that Anthropic "signed onto the EU AI Act's Article 50(2) Code of Practice, a voluntary framework that becomes legally enforceable on August 2, 2026." Voluntary code, hard date, worldwide rollout.

So the date is settled. Who the obligations actually fall on is a separate question, and the answer is narrower than the coverage suggests.

Who the rule actually binds

Article 50 assigns its transparency duties by role, and none of the roles is the person reading a document.

The marking duty sits with providers, the companies that build the generative system. In the regulation's own text, Article 50(2) requires that "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated" (Regulation (EU) 2024/1689, read on EUR-Lex August 19, 2026). That is the side of the table Anthropic occupies. The December 2 grace period above scopes that same duty for systems already on the market; whether and how it applies to any given model is not something Anthropic's pages state. A separate provider duty, Article 50(1), covers something else: informing people that they are interacting with an AI system in the first place, unless that is obvious.

The disclosure duty sits with deployers, the organizations that use an AI system, and for text it is narrow. Article 50(4) covers deployers of "an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest", who "shall disclose that the text has been artificially generated or manipulated". The same paragraph exempts text that "has undergone a process of human review or editorial control" where "a natural or legal person holds editorial responsibility for the publication of the content". The European Commission's transparency FAQ (read August 19, 2026) treats that exemption as demanding substance, examination by someone with relevant knowledge of the subject or control by a responsible editor, and states that "Superficial, solely formal, or procedural checks (e.g. spell-checking or grammatical correction) are not considered to be human review or editorial control."

The two duties do not discharge each other. The Act requires the disclosures in paragraphs 1 to 4 to reach people "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" (Article 50(5)), and the Commission's FAQ, in its answer on deepfakes, says it outright: deployers "cannot simply rely on the machine-readable marking embedded in the content by the provider under Article 50(2) of the AI Act to fulfil their disclosure obligation". An invisible watermark in the wording is the provider's instrument. A disclosure people can actually perceive is the deployer's.

None of this reaches the reader. We found nothing in Article 50 or the Commission's FAQ that obliges the person receiving a document to preserve a mark, check for one, or do anything at all. The role that can carry a duty is the deployer's, in the narrow publishing case above.

There is no detector, and no opt-out described

Two absences in the document are as newsworthy as its contents.

The first is detection. Anthropic commits to it without shipping it: the page says it will "support users and other third parties to detect Claude's marks, as the Code requires", and that "we'll share details on detection mechanisms in forthcoming technical documentation." Nothing is published yet, so there is currently no public tool to test a paragraph against. Anyone claiming to have caught a document by its Claude watermark is, for now, working from something other than published Anthropic tooling.

Since this article first ran, Anthropic has named what is coming. The August 14, 2026 explainer says: "We will soon be offering a watermark detection API. We're in the process of working out the details of its implementation." That is an announcement, not a release. No date is attached, and as of August 19, 2026 nothing has shipped, so there is still no public way to check a paragraph for Claude's mark.

The second is control. The support page describes no opt-out. It sets out the products covered, the model cutoff, both mark types and the limits of each, and it never mentions a setting to turn marking off. That may change, and a different page may say otherwise later, but the document announcing the commitment offers no switch.

Anthropic is also honest about how weak a detection result will be in both directions. A detected mark means content "may have been processed by Claude", not that Claude wrote it, because Claude may not be the original author and the content can be modified afterwards. No detected mark proves nothing either, since marks can be lost through editing, format conversion or platform limitations, and since the page notes a very short passage leaves too little text for a reliable signal. Provenance marking is evidence, not proof, and it is much better at answering "was a machine involved somewhere" than "who wrote this".

What this means if an assistant drafts your work

Suppose your week runs on AI drafts. Meeting notes summarized automatically, follow-up emails written from a transcript, a first pass at a document you then rewrite. Three practical consequences:

Everything produced so far is unmarked. There is no archive to worry about, no need to audit last quarter's notes, nothing retroactive in the announcement.

When the tools you use move to a model launched on or after August 2, 2026, provenance starts travelling with the text you paste. A summary pasted into Slack, a paragraph pasted into a proposal, a line dropped into a shared doc. The mark goes where the text goes, at least until something strips it.

Heavily edited text is the ambiguous case. If you take an AI draft and rewrite most of it, "may persist through some editing" is all you have to reason with, and there is no published detector to check the result. Treat authorship of edited work as a question your disclosure answers, not one the watermark will settle for you.

One more consequence applies only if you publish. Text that goes out to inform the public on matters of public interest can carry the deployer duty described in "Who the rule actually binds" above; drafts that stay inside your company, in email, notes and internal documents, are not the case that rule was written for.

Routines, the Mac app we build, also publishes audits of AI vendors written only from each vendor's own published documents, such as the one on Notion AI, and marking puts a receipt of that kind inside the text itself.

Disclosure over evasion

Tools that strip provenance from AI output already exist. Since this article was published, a market for them appeared, and we reported on it on August 14: we still do not link the tools or explain how to use them, and the central claim they sell cannot be verified by anyone while Anthropic has published no detector. Our reason for not using them is practical rather than moral. Stripping a mark buys you deniability about a fact you could have stated in one sentence, and it commits you to maintaining that deniability against detection tooling that has not shipped yet.

The cheap alternative is a line of text. "First draft written with Claude, edited by me" at the top of a document costs nothing, survives every format conversion, and cannot be defeated by a paste into the wrong editor. Most of the anxiety around this is about being caught rather than about doing anything wrong, and the fix for that is disclosure.

Disclosure: the content on this site, this article included, is produced with Claude's help. Under the rules above, none of it published before today is watermarked either, which is exactly why the sentence is here instead of a mark you cannot check.

What is settled, and what is not

Settled, from Anthropic's pages, all of it re-checked against them on August 19, 2026: Claude models launched on or after August 2, 2026 will mark at launch, and none has launched yet; earlier models are in progress; text gets an embedded watermark and supported files get C2PA-signed metadata; coverage is worldwide across Claude, the API, Claude Code, Claude Cowork and Claude Tag, applied globally because Anthropic has no durable way to scope it by region; text watermarking is applied at the model level and so does not vary by surface, while signed provenance metadata may not be supported on every platform; the mechanism, since the August 14 explainer, is on the record as a keyed choice of wording with nothing added to the text. Settled from the law's side: the EU duties sit with providers and deployers, not with readers.

Not settled: when the detection API ships and what it will cover, whether any opt-out will appear, how much editing a watermark actually survives, and whether the EU's enforcement bodies will treat any given implementation as satisfying Article 50(2).

If you want the primary source rather than a screenshot of it, Anthropic's page is short and worth ten minutes.

FAQ

Does Claude watermark text today?

No. Not yet, for anything. Anthropic's support page states that Claude models launched on or after August 2, 2026 support marking at launch, and that for models released before that date it is "working to add marking support for those models as well", which it describes as in progress within the law's transition period. Text written today by a model that shipped before August 2 is not carrying an embedded watermark. Text from the first model launched on or after that date will be.

Can you remove the watermark from Claude's text?

It is built to survive ordinary handling. Anthropic writes that "because the watermark is part of the text, it will travel with the text when it's copied and pasted elsewhere, and may persist through some editing". Note the word may: the page also says marks can be lost through editing, format conversion or platform limitations, so this is not presented as unbreakable. Tools that strip provenance already exist, and we have since reported on the market that grew around them, without linking any of them or explaining how to use them: with no detector published, nobody can verify a removal claim, including the people selling one. If you are worried enough about a mark to hunt for a remover, the cheaper fix is a line at the top of the document saying the draft was AI-assisted.

Will my meeting notes be watermarked?

It depends on which model wrote them and when. Marking applies to output from supported models wherever Claude is offered, worldwide, across Claude Platform (API), Claude, Claude Code, Claude Cowork and Claude Tag, though Anthropic notes some platforms may not support all marking types. Notes summarized by a model that launched before August 2, 2026 are unmarked, and nothing is applied retroactively to notes already written. Once the tool you use moves to a model launched on or after that date, the summary text can carry an embedded watermark.

Is this EU-only?

No. Anthropic states that marking "will apply to output from supported models wherever Claude is offered, worldwide". The date comes from European law even though the coverage does not. Anthropic signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content, and the European Commission states that Article 50 of the AI Act applies from 2 August 2026. One summary bullet does add an in-the-EU qualifier to the model cutoff, which the detail section omits. In its August 14, 2026 explainer Anthropic resolved the ambiguity in its own voice: "We're applying watermarking globally at launch because we don't yet have a durable way to scope it by region."

How can I check whether a piece of text is watermarked?

You cannot yet, at least not with anything Anthropic has published. The support page says only that "we'll share details on detection mechanisms in forthcoming technical documentation". Until that lands there is no public detector to point at a paragraph, which is worth remembering when someone claims to have caught a document out.

Is there an opt-out?

The support page describes none. It lists the products covered, the model cutoff date, the two kinds of mark and the limits of both, and it does not mention a setting that turns marking off. If an opt-out exists somewhere else, it is not in the document announcing the commitment.

Does a detected watermark prove a text came from Claude?

No, and Anthropic says so. Detecting a mark indicates content "may have been processed by Claude", which is weaker than authorship: Claude may not be the original author, and the content can be modified afterwards. The reverse is also weak. No detectable mark does not confirm that content was not AI-generated, because marks can be lost through editing, format conversion or platform limitations, and because the page notes a very short passage leaves too little text for a reliable signal.

What about images and files, not text?

For supported file types, which the page illustrates with .svg, .png and .jpg, Anthropic writes that "it will attach signed provenance metadata. This metadata follows the Coalition for Content Provenance and Authenticity (C2PA) open standard." That metadata signals the file was processed by Claude and allows tampering to be detected. It is a separate mechanism from the text watermark, and it sits in the file's metadata rather than in the words.

Do I have to keep Claude's watermark in text I publish?

We found no such duty. The EU AI Act's transparency rules assign marking to providers, the companies that build the generative system (Article 50(2)), and disclosure to deployers in one narrow publishing case (Article 50(4)). Nothing we could find in the Act or in the European Commission's transparency FAQ, read August 19, 2026, obliges a reader or writer to preserve a watermark. Where the Article 50(4) duty does apply, it asks the deployer to disclose "that the text has been artificially generated or manipulated", which is a label people can see, not a promise to keep the provider's invisible mark intact.

Do I have to label AI-written text I publish?

As we read it, only in a specific case, and with a wide exemption. The second subparagraph of Article 50(4) of the AI Act (the first covers deepfakes) puts the duty on deployers of a system that generates text "which is published with the purpose of informing the public on matters of public interest", and the duty is to disclose that the text was artificially generated or manipulated. The same paragraph exempts text that "has undergone a process of human review or editorial control" where "a natural or legal person holds editorial responsibility for the publication of the content". The Commission's transparency FAQ, read August 19, 2026, reads human review as substantive examination by someone with relevant knowledge of the subject, and says spell-checking and grammatical correction do not count.

Is Claude's watermark EU AI Act compliance?

Anthropic says that is the goal, in its own words: "We're implementing watermarking to comply with the EU AI Act." Its support page adds that "Anthropic has signed the EU AI Act's Article 50(2) Code of Practice on Transparency of AI-Generated Content", and the European Commission counted about 190 signatories to that code by the end of July 2026. Whether the implementation satisfies Article 50(2) is a call for the EU's enforcement bodies, and we found no published verdict from any of them on Claude's marking, either way, as of August 19, 2026.

What happens if someone breaks these rules?

The Commission's transparency FAQ, read August 19, 2026, says fines "can reach up to 15 million euros or 3% of total worldwide turnover for the preceding financial year", with proportionality possible for smaller companies. Those penalties attach to providers and deployers, the two roles Article 50 binds. We found nothing that attaches a penalty to reading, receiving or revising AI-generated text for your own use.

Sources

Related

Related posts

Try it on your Mac.

Routines keeps your notes, transcripts, and routine outputs as markdown and SQLite on your machine, where they stay unless you turn on Cloud Sync.

Download