Every piece of text Claude generates now carries an invisible watermark that machines can read but you cannot see. Anthropic, the company behind the Claude AI chatbot, has started embedding imperceptible watermarks into all text output from supported Claude models, along with signed provenance metadata in generated image files.

The move is driven by the EU AI Act’s transparency requirements, but Anthropic is not limiting it to Europe. Watermarking applies worldwide, across every product where Claude is available — the API, Claude’s chat interface, Claude Code, Claude Cowork, and Claude Tag. Cloud partners AWS, Google Cloud, and Microsoft also carry the watermarks in their hosted Claude offerings.
How Claude’s watermarking works
When a supported Claude model generates text, it weaves an imperceptible watermark directly into the text itself. The watermark is baked into the statistical patterns of the output — a digital fingerprint that detection tools can read but that does not change the meaning, quality, or readability of the response. Because it lives in the text, the watermark travels when you copy and paste, and it may survive some editing.
For generated files — currently .svg, .png, and .jpg — Claude attaches digitally signed provenance metadata following the C2PA (Coalition for Content Provenance and Authenticity) open standard. This metadata is designed to let downstream platforms verify that a file originated from an AI system.
Which models are affected
Claude models launched on or after August 2, 2026 carry watermarks natively from day one. Anthropic says it is also working on adding marking support to models released before that date, under what it calls a transition period.
There is no opt-out. Watermarking is mandatory across all supported models and products, and Anthropic’s documentation makes no mention of a way for users — free or paid — to disable it.
What the watermark cannot prove
This is where things get complicated, especially for students, employees, and anyone whose work might be run through an AI detector. Anthropic’s own documentation is explicit about the limits:
- A detected mark is not proof. A watermark provides a signal that content was processed by Claude, but Anthropic says it is not fully conclusive. The text may have originated elsewhere or been edited afterward.
- No mark does not mean no AI. If a watermark is absent, that does not guarantee the content is human-written. Heavy editing, paraphrasing, translation, or mixing AI text into other writing can strip the mark. Very short passages may also lack a detectable signal.
In other words, the watermark can produce both false positives and false negatives — and Anthropic acknowledges this openly. That matters enormously in settings like universities and workplaces that are already using unreliable AI-detection tools to flag students and employees. A watermark from the AI vendor itself carries more authority than a third-party detector, but Anthropic is simultaneously saying that authority is limited.
Detection tools are not ready yet
Anthropic says it is “working to enable users and other third parties to detect Claude’s embedded watermarks and provenance metadata,” with technical documentation forthcoming. As of today, there is no public detection tool. The watermarks are being embedded, but nobody outside Anthropic can check for them yet.
Meanwhile, security researchers have already noted that open-source tools exist for stripping C2PA metadata from files, and that OCR-based workflows could potentially remove text watermarks by converting output to plain text and back.
The gap between marking and detection is worth watching. Anthropic is building a system where content is labelled as AI-generated before the tools to read those labels are publicly available — a transparency measure that is, for now, transparent only to its maker.
Sources: Anthropic (Claude Help Center), The Register
