Anthropic’s Claude Will Watermark AI Content
Anthropic is preparing to embed invisible watermarks in Claude-generated text and attach signed provenance records to supported files worldwide, responding to new EU rules intended to make synthetic content easier to identify.
EU Rules Drive A Worldwide Change
The change follows Article 50 of the EU AI Act, which became applicable on 2 August 2026. In short, it requires generative AI providers to mark synthetic text, images, audio and video in a machine-readable form so they can be detected as artificial or manipulated.
Anthropic has signed the EU’s voluntary Code of Practice on Transparency of AI-Generated Content, joining Google, Microsoft, Meta and OpenAI. Signing is optional, but the underlying transparency duties are legal requirements for companies offering covered systems in the EU.
Claude models launched in the EU from 2 August will support marking immediately, while Anthropic is adding it to earlier models during the permitted transition period. The company will apply marks wherever supported Claude models are available, not only within Europe.
Coverage includes the Claude website and app, Claude Platform API, Claude Code, Claude Cowork and Claude Tag. Text marks will also apply through AWS, Google Cloud and Microsoft Foundry, although file marking may depend on each platform’s features.
Two Ways To Trace Claude Content
Claude will actually use different methods for text and files. For example, when a supported model generates text, it will weave an imperceptible pattern into its output at model level, meaning the watermark should remain when the words are copied from one Claude product and pasted elsewhere.
Anthropic says: “You won’t see it, and it doesn’t change the meaning, quality, or readability of Claude’s response.” The signal may survive some editing, although the company has not disclosed its technical method or resilience.
Supported files, including PNG, JPG and SVG images, will receive digitally signed provenance metadata based on the Coalition for Content Provenance and Authenticity’s C2PA standard. This can record Claude’s involvement and help reveal later alterations.
How The Text Watermark Works
The invisible text watermark described above takes advantage of how large language models produce text. For example, rather than composing a complete sentence in advance, Claude predicts each next token, usually a word or part of one, and chooses from several plausible continuations.
Anthropic says the watermark subtly influences those choices using a separate source of randomness, creating a statistical signature that can later be detected with a digital key. Crucially, “Watermarking is sparser on factual passages where there are fewer choices that can be made without decreasing the accuracy of the text.”
The company says internal testing found no effect on creativity, readability or quality, while the technique adds no extra tokens and has negligible impact on model speed or cost. It contains no personally identifying information, although extensive rewriting can remove the signal.
A Signal Rather Than Proof
The important limitation is that neither method can provide a definitive answer about authorship. Anthropic’s own wording says detection means content “may have been processed by Claude”, which is very different from proving that Claude conceived or wrote all of it.
A human-written document could acquire a mark after being proofread, translated, summarised or converted by Claude. Equally, Claude-generated material may lose its detectable signal if it is heavily edited, paraphrased, translated, combined with other text or reduced to a short extract.
File metadata can disappear when an image is resaved, converted or captured as a screenshot. C2PA, an industry standard for recording the origins of digital content, acknowledges that provenance metadata can be removed, although watermarking and fingerprinting may help reconnect altered files with stored credentials.
Independent research has found similar weaknesses in text watermarking. For example, paraphrasing can reduce detection, short passages may provide too little evidence, and some techniques can be copied to misattribute content. Anthropic has promised detection tools and fuller guidance, but neither is publicly available.
What The Watermarks Can Achieve
Despite those limitations, consistent marking could give publishers, platforms, researchers and businesses a useful extra source of evidence when tracing large volumes of questionable material. It may become easier to identify coordinated Claude-generated campaigns, investigate disputed content or check whether a file has passed through an AI system.
However, this doesn’t make the watermark an “AI slop” detector in the literal sense. Carefully researched and edited work could carry exactly the same mark as mass-produced nonsense, while misleading human-written content would carry none. Provenance says something about a content-production process, not whether the finished material is accurate, valuable or trustworthy.
Applying the system worldwide also shows how European regulation can influence the design of a global technology product. Running one model-level marking system across every market may be more practical than producing separate EU and non-EU outputs, but it means businesses outside Europe will also receive marked content.
What Does This Mean For Your Business?
Organisations using Claude should identify which models and products support marking, review where AI-generated material enters public communications and decide when visible disclosure is still appropriate. Companies building Claude into their own services must now really assess their own Article 50 duties rather than assuming Anthropic’s watermark completes their compliance work.
Detection results should never be used alone to accuse an employee, student, supplier or author of undisclosed AI use. Businesses should treat a watermark as one piece of evidence, retain original files and provenance records where authorship matters, and continue applying human review, source checking and editorial control.
Anthropic’s plan appears to be a meaningful step towards traceable AI content, particularly because its worldwide reach could create a common provenance signal across numerous products and cloud services. Its real value, though, will be helping people ask better questions about where content has been, not supplying a final verdict on who created it or whether it deserves to be trusted.



