
Anthropic will watermark all Claude outputs globally starting August 2, 2026, embedding invisible text watermarks and signed file metadata under the EU AI Act Code of Practice.
The watermarks survive copying and pasting and may persist through editing, but the company acknowledges significant limits: a watermark does not confirm Claude wrote the content, since humans use Claude for editing, and absent watermarks may simply indicate older models or heavy post-generation editing.
The real test will be how well the marks hold up against translation and reformatting in the field.
What happened
Anthropic has signed the EU AI Act Code of Practice and will embed invisible watermarks in Claude-generated text and attach digitally signed provenance metadata to files starting August 2, 2026. The watermarks will apply globally across all Claude products—the API, Claude, Claude Code, Claude Cowork, and Claude Tag—not just in the EU. The company is also retrofitting existing models and plans to release verification tools, though no timeline was given.
Why it matters
The watermarks survive copying, pasting, and "may persist through some editing," making AI-generated content more traceable. This addresses pressure to identify AI-generated material in sensitive contexts like education, where unreliable detection has led to false cheating allegations. However, Anthropic itself acknowledges limits: a watermark does not prove Claude wrote the content (humans use Claude for editing), and absence of a watermark does not mean the text is human-written, because older models lack watermarks, text may be heavily edited or translated, or metadata may be stripped.
What to watch
The reliability test will be how well watermarks survive editing, reformatting, and translation. Anthropic's approach differs from OpenAI, which has held a text detector with 99.9 percent accuracy for about two years without releasing it, citing risks of being beaten by translation or rewriting. The open C2PA standard used for file metadata could allow third-party detectors to support the watermark, though cloud partners like AWS, Google Cloud, and Microsoft may not support signed metadata.
Anthropic announced that it has signed the EU AI Act Code of Practice on transparency for AI-generated content and will begin watermarking all Claude outputs globally starting August 2, 2026. The watermarks will apply to all Claude products—the API, Claude, Claude Code, Claude Cowork, and Claude Tag—regardless of geographic location, even though the requirement stems from EU law. Anthropic is also working to retrofit existing models to support watermarking during a transition period the law provides.
The company will deploy two complementary marking methods. Text generated by Claude will carry an embedded, invisible watermark that preserves the text's meaning, quality, and readability and survives copying and pasting; the company states it "may persist through some editing." Because the watermark is applied at the model level, it will work across all Claude products. Files in supported formats—including .svg, .png, and .jpg images—will receive digitally signed provenance metadata based on the open C2PA standard, developed by the Coalition for Content Provenance and Authenticity. This signature proves Claude processed the file and can later reveal if the file has been tampered with. Text watermarks should also work through cloud partners such as AWS, Google Cloud, and Microsoft Foundry, though those platforms may not support the signed metadata layer. Anthropic plans to release verification tools to let users and third parties check the labels, though it has not specified a release date.
Anthropric is transparent about the system's limitations. A detected watermark does not prove Claude wrote the content; humans routinely use Claude for proofreading, translating, or summarizing existing material, so output may carry a watermark even though the underlying ideas came from a human. The absence of a watermark is equally inconclusive: the model may have shipped before watermarking launched, the text may have been heavily edited or translated after generation, the passage may be too short for reliable detection, or metadata may have been stripped through format conversion or screenshots. The real-world effectiveness of the watermarks will ultimately depend on how well they survive editing, reformatting, and translation—a test that has tripped up earlier attempts. Anthropic notes that third-party detectors could add support for its watermark, potentially giving them a more reliable signal than existing tools like Pangram, which use proprietary detection methods that do not reveal what triggered a result.
Anthropric is not alone in the watermarking race. Google DeepMind open-sourced its SynthID watermarking system and built it into Gemini models; SynthID tweaks token probability values during generation to create a watermark without degrading text quality and works across languages, though it struggles with edited text. OpenAI, by contrast, has possessed a text detector with 99.9 percent accuracy for roughly two years but has not released it, citing concerns that users can easily evade it through translation or rewriting, risks of stigmatizing certain groups, and likely worries that a public detector could damage OpenAI's own business. The issue is especially fraught in education, where unreliable detectors have already caused false cheating allegations, even as legitimate reasons exist to track AI use—studies show heavy reliance on AI can weaken critical thinking and writing skills, particularly among students who treat AI as a shortcut rather than a learning aid. Beyond academics, fraud has emerged: scammers are enrolling fake students at US colleges and using AI to complete coursework and collect financial aid. Anthropic's decision to watermark all outputs globally could also reshape its own business, since Claude is popular among students partly because older models produce natural prose; more reliable detection may make Claude less appealing to users seeking to bypass institutional oversight.
Anthropic's watermarking decision sits at the intersection of regulatory pressure, technical capability, and business risk. By signing the EU AI Act Code of Practice, the company has committed to a transparency mechanism that will apply not just to European users but globally—a choice that signals Anthropic's willingness to embed disclosure into its products even where law does not mandate it. This contrasts sharply with OpenAI's two-year silence on a reportedly highly accurate text detector, a gap the article attributes to fears that such a tool could be circumvented by translation or rewriting, and to concerns about harming OpenAI's own business. Anthropic's approach is more optimistic: rather than holding back, it is building watermarks into the model itself and committing to open verification tools, though with notable caveats about what those marks can and cannot prove.
The stakes are highest in education. Unreliable AI detection has already produced false cheating allegations, and schools are actively debating how to integrate AI into coursework. Anthropic's watermarks will not resolve the underlying tension—a detected watermark only shows Claude touched the text, not whether a student used Claude improperly—but more reliable marking could shift the conversation from detecting AI to disclosing its use. At the same time, the article notes that heavy reliance on AI tools can weaken critical thinking and writing skills, and that fraud has already emerged (fake students using AI to breeze through coursework). For Claude's users in schools and knowledge work, stronger watermarking may make the tool less attractive as an undetectable shortcut, and more useful as a tool that must be disclosed.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Tech companies are raising unprecedented sums for AI infrastructure—$194 billion so far in 2026 by just four f…

Nvidia has partnered with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR to raise $500bn in…

Nvidia has signed letters of intent with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs, and KKR to…

Anthropic has agreed to pay $9.1 billion over 20 years to Riot Platforms Inc., a Bitcoin miner turned data cen…

Samsung is accelerating efforts to qualify its Taylor, Texas fabrication plant for 2-nanometer chip production…

Nvidia has partnered with six major investment and financial groups to mobilize more than US$500 billion in th…

The AI news that matters, in one minute each morning.
Sign up free